A.5.25 Organizational
Assessment and decision on information security events
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (10)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- IR-4mostlyaligns with — Both controls require a structured process for evaluating reported security events, determining their significance, and deciding on the appropriate response actions.
- AU-6partialaligns with — Assessment of security events in the ISO control aligns with NIST's requirement to review, analyze, and report on audit records to identify security-relevant events.
- IR-5partialaligns with — The ISO control's requirement to assess and decide on events supports the ongoing monitoring and tracking of incidents that NIST addresses through incident monitoring activities.
- SI-4partialaligns with — The ISO control's event assessment and decision process complements NIST's system monitoring requirements by providing the analysis step that follows detection of anomalies.
- IR-4covers — A.5.25's narrow focus on event assessment/categorization/prioritization addresses only the detection-and-analysis slice of IR-4's broader incident handling capability (prep/detection/analysis/containment/eradication/recovery + coordination + lessons learned); a real residual of the target remains uncovered
- IR-5covers — A.5.25's focus on assessment/prioritization of events addresses only a slice of IR-5's broader requirement to track and document the full incident lifecycle
Aligned NIST CSF 2.0 outcomes (17)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- RS.MA-02fullaligns with — Both require a structured assessment of reported events to validate and triage them before further incident handling.
- RS.MA-03fullaligns with — The ISO control’s categorization and prioritization scheme directly supports the CSF outcome of categorizing and prioritizing incidents.
- DE.AE-08mostlyaligns with — Both emphasize applying defined criteria to determine when an event should be declared an incident.
- RS.AN-08mostlyaligns with — The ISO requirement to assess consequences and decide on events aligns with estimating and validating an incident’s magnitude.
- RS.AN-03partialaligns with — Detailed recording of assessment results supports the CSF outcome of performing analysis to understand what occurred and why.
- RS.AN-03implements — A.5.25's assessment/prioritization of events directly operationalizes the incident analysis and root-cause determination required by RS.AN-03 within the response-analysis domain
- RS.AN-08implements — A.5.25's assessment/prioritization of security events directly operationalizes the estimation and validation of incident magnitude within the response-analysis domain named by RS.AN-08
- RS.MA-02implements — A.5.25's assessment/prioritization of security events directly operationalizes the triage-and-validation outcome named in RS.MA-02 within the incident-response domain
- RS.MA-03implements — A.5.25's defined purpose (categorization and prioritization of security events) directly operationalizes exactly what RS.MA-03 requires of incident handling
Related OWASP ASVS 5.0 requirements (5)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Mitigated MITRE ATT&CK techniques (901)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1001detects — A.5.25 requires assessment of events against an agreed incident categorization scheme, which can surface T1001-obfuscated C2 as an information security event once observed, but the control itself supplies no detection instrumentation or discovery mechanism for the hidden traffic.
- T1001.002detects — A.5.25 requires assessment of events against an agreed scheme that decides which ones become incidents; this surfaces knowledge of a steganography C2 event once observed, but the control itself supplies no instrumentation, telemetry, or detection mechanism and stops at the assessment step.
- T1001.003detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify them as security incidents; this surfaces knowledge of T1001.003 traffic once observed and flagged as anomalous, but the control stops at assessment/decision/recording and does not itself perform the monitoring or anomaly detection that would surface the impersonated traffic.
- T1003detects — A.5.25 requires assessment of every security event against an agreed scheme that explicitly includes criteria to categorize events as incidents; credential-dumping TTPs produce observable artifacts (process creation, memory access, LSASS handles, etc.) that fall inside typical event schemes, so the control surfaces and records them as incidents.
- T1003responds — A.5.25 requires assessment/prioritization of security events (including those from credential-dumping TTPs) to drive coordinated incident response, which matches the `responds` verb once the technique is underway.
- T1003.001detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of LSASS dumping when the event is observed and routed to the assessment point, but the control itself performs no monitoring or instrumentation and therefore only reaches events that other mechanisms have already made visible.
- T1003.001responds — A.5.25 requires assessment/prioritization of security events (including those matching T1003.001 activity such as LSASS access or dumps) to decide on incident response, directly enabling the containment/eradication act that `responds` names once the technique is underway.
- T1003.002detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1003.002 when it is recognized as matching those criteria, but the control stops at assessment/decision/recording and does not itself perform detection or monitoring.
- T1003.003detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether it qualifies as an information security incident; this surfaces knowledge of T1003.003 when the event is observed and meets the criteria, but the control stops at assessment/decision/recording and does not itself perform detection instrumentation or monitoring.
- T1003.003responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once an event such as T1003.003 is underway, enabling containment/eradication decisions, with only the already-realized credential theft as named remainder.
- T1003.004detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that decides whether it qualifies as an incident; this surfaces knowledge of credential-dumping events that match the scheme, but the control stops at assessment/prioritization and does not itself instrument or monitor for the technique.
- T1003.005detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of T1003.005 when the extraction is observed as an event, but the control is silent on instrumentation, telemetry or monitoring that would generate the event in the first place.
- T1003.006detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that decides whether it qualifies as an incident; this surfaces knowledge of a DCSync attempt once it is reported as an event, but the control itself performs no monitoring, instrumentation or detection and therefore only reaches the subset of DCSync activity that is already handed to the assessment point.
- T1003.006responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding once an in-progress DCSync technique has produced observable events.
- T1003.007detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface credential-gathering activity from procfs as an incident, but the control itself performs only human-driven post-event triage and recording rather than any automated or continuous detection mechanism.
- T1003.008detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether it qualifies as an information security incident; reading /etc/passwd+shadow is observable as a file-access event that can be assessed and recorded, but the control only supplies the assessment step and does not itself instrument or surface the raw event.
- T1006detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that explicitly includes criteria to identify incidents; this surfaces and records T1006 events (e.g. anomalous volume access or shadow-copy creation) once they are presented as events, but the control itself performs no monitoring or detection and depends on external sources to supply the events.
- T1011detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as security incidents; this surfaces knowledge of the T1011 technique once it produces observable events, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1011.001detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents; this surfaces knowledge of the Bluetooth exfiltration event once it produces observable indicators, but the control itself performs no monitoring, instrumentation or detection and depends on other mechanisms to supply the events being assessed.
- T1016.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface Internet Connection Discovery as an incident indicator when observed, but the control is silent on instrumentation, collection or real-time detection mechanisms and only addresses post-event assessment.
- T1020detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents; this surfaces knowledge of automated exfiltration when it triggers the scheme, but the control stops at assessment/prioritization and does not mandate ongoing monitoring or detection mechanisms.
- T1020responds — A.5.25 requires competent personnel to assess each security event against an agreed scheme that decides whether it is an incident and what priority it receives; this is the exact act of responding once the automated exfiltration technique is already underway, with the named remainder being full incident eradication and recovery that live in separate controls.
- T1020.001detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; traffic-duplication activity (especially when it produces observable anomalies or is paired with sniffing/AiTM) can surface as such an event and therefore be assessed and recorded, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1020.001responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and then decide on and record the outcome; this is the core of incident response once an event is underway, directly matching the `responds` verb for a technique that produces observable network events.
- T1021detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to classify them as incidents; this surfaces knowledge of T1021 executions that meet those criteria (e.g., anomalous remote logons), but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, instrumentation, or detection mechanisms.
- T1021.001detects — A.5.25 requires assessment of events against an agreed scheme that decides which qualify as incidents; this surfaces knowledge of RDP-based lateral movement once it has produced a detectable event, but the control stops at assessment/prioritization and does not mandate instrumentation or monitoring that would catch the technique itself.
- T1021.001responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an RDP-based technique is underway, with the named remainder being full containment/eradication (handled by A.5.26).
- T1021.002detects — A.5.25 requires assessment of events against an agreed scheme to decide if they qualify as security incidents, which can surface SMB/Windows Admin Shares activity when it is observed and reported as an event, but the control itself performs no monitoring, instrumentation or detection and depends entirely on upstream event sources.
- T1021.002responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an event is underway, and T1021.002's use of valid accounts over SMB is a detectable lateral-movement event that would trigger exactly that assessment/decision process.
- T1021.003detects — A.5.25 requires assessment of every security event against an agreed scheme to decide if it qualifies as an incident; this surfaces knowledge of T1021.003 when the DCOM activity is observed as an event, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1021.004detects — A.5.25 requires assessment of security events against an agreed categorization scheme to decide if they qualify as incidents; this surfaces knowledge of SSH-based adversary activity once it has produced an observable event, but only for events that reach the point-of-contact and match the scheme's criteria.
- T1021.004responds — A.5.25 requires assessment/prioritization of events (including those matching T1021.004) to decide on incident response, directly enabling the containment/eradication act that `responds` names once the technique is underway.
- T1021.005detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1021.005 when it triggers those criteria, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, instrumentation, or telemetry that would surface the technique itself.
- T1021.005responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an event is underway, directly matching the `responds` verb for a VNC-abuse technique that has already executed.
- T1021.006detects — A.5.25 requires assessment of events against an agreed scheme to decide if they are incidents (and their priority), which can surface WinRM-based lateral movement when it triggers the scheme, but the control is governance-oriented, applies only to already-raised events, and does not mandate any specific detection instrumentation or coverage of this technique.
- T1021.006responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an event is underway, directly matching the `responds` verb for a WinRM-based technique that has already executed.
- T1021.007detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents, directly enabling detection of T1021.007 activity when it surfaces as an assessable event; partial because the control only acts on already-reported events and does not itself instrument or surface the logins.
- T1021.007responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an event is underway, directly matching the `responds` verb for the T1021.007 technique.
- T1027.005detects — A.5.25 requires assessment of security events using an agreed scheme to decide if they qualify as incidents, which surfaces knowledge of adversary indicator-removal activity once it has produced a detectable event (e.g. AV quarantine or similar curtailment), but the control stops at categorization/prioritization and does not mandate ongoing monitoring or detection mechanisms.
- T1027.006detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify them as information security incidents; this surfaces HTML smuggling when observed as an event, but the control is silent on instrumentation, collection or real-time detection mechanisms that would surface the technique itself.
- T1027.006responds — A.5.25 requires assessment of each security event against an agreed categorization/prioritization scheme to decide if it is an incident and record the outcome; this directly enacts the `responds` verb once an HTML-smuggling event is detected and underway.
- T1027.011detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether it qualifies as an information security incident; this surfaces knowledge of T1027.011 when the event is observable and meets the criteria, but the control itself performs no monitoring or data collection and therefore only detects the subset of fileless-storage activity that reaches the assessment stage.
- T1027.012detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1027.012 when the smuggling produces observable artifacts (e.g. anomalous LNK metadata or download) that match the scheme, but the control stops at assessment/decision/recording and does not mandate instrumentation that would reliably catch the technique itself.
- T1030detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify security incidents; this surfaces and records T1030-style exfiltration (as a network anomaly or data transfer event) once observed, but only within the scope of events that reach the point of contact and match the scheme — it does not instrument or guarantee detection of the technique itself.
- T1036detects — A.5.25 requires assessment of events against an agreed categorization scheme that can tag masquerading artifacts as security incidents once surfaced, but the control itself performs no detection and stops at post-detection triage.
- T1036responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding once a masquerading technique is underway, with only a bounded remainder (e.g., fully automated low-fidelity events) left unreached.
- T1036.001detects — A.5.25 requires assessment of events using an agreed scheme that explicitly includes criteria to categorize them as information security incidents, which can surface T1036.001 when observed as a suspicious event; however, the control is governance-oriented, depends on upstream detection mechanisms to feed it events, and does not itself instrument or guarantee discovery of the technique.
- T1036.001responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to record the decision; this directly enacts the `responds` act of containment/eradication triage once the invalid-signature technique has produced a detectable event.
- T1036.002detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the RTLO technique when it appears in an observed event, but the control stops at assessment/decision/recording and does not itself instrument or scan for the technique.
- T1036.003detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify security incidents; renamed utilities evading monitoring mechanisms can be (and routinely are) surfaced as events for that assessment, but the control stops at assessment/prioritization and does not itself perform the detection instrumentation or monitoring that surfaces the rename.
- T1036.003responds — A.5.25 requires assessment/prioritization of events (including those from renamed utilities evading monitoring) to decide on incident response, directly matching the `responds` verb once the technique is underway.
- T1036.004detects — A.5.25 requires assessment of events against an agreed scheme that decides which qualify as security incidents; this surfaces masquerading when the anomalous naming/description is noticed and escalated, but the control is silent on any instrumentation, telemetry, or automated detection that would surface the technique itself.
- T1036.004responds — A.5.25 requires assessment of each security event against an agreed scheme to decide if it is an incident and to prioritize it; this directly enacts the `responds` verb once the masquerading technique has produced a detectable event (e.g., anomalous task/service), with the named remainder being events that evade initial detection or categorization.
- T1036.007detects — A.5.25 requires assessing every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of a double-extension masquerading event when it is reported or observed, but the control stops at assessment/prioritization and does not itself instrument or scan for the technique.
- T1036.008detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of masquerading activity when it is observed and routed for assessment, but the control itself performs no monitoring, instrumentation or discovery and therefore only reaches the subset of events that are already handed to it.
- T1036.009detects — A.5.25 requires assessment of events against an agreed scheme that explicitly includes criteria to categorize them as information security incidents, which can surface T1036.009 when the scheme treats process-tree anomalies or evasion as qualifying events; the remainder is that the control itself performs no monitoring or instrumentation and depends entirely on whatever upstream collection (if any) feeds it.
- T1036.010detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of masquerading account-name creation when the event is observed and meets the criteria, but the control stops at assessment/decision/recording and does not mandate instrumentation, monitoring coverage, or detection mechanisms that would catch the technique in flight or at creation time across its broad platform scope.
- T1036.010responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to record the decision; this directly enacts the `responds` act of containment/eradication once the masquerading-account technique is already underway as an observable event.
- T1036.011detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether it qualifies as an information security incident; this surfaces knowledge of the masquerading technique when the event is observed and fed into the scheme, but the control itself performs no monitoring, instrumentation or discovery and therefore only reaches the subset of T1036.011 instances that have already been raised as candidate events.
- T1036.012detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1036.012 when its artifacts match those criteria, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring or detection mechanisms.
- T1037detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1037 executions (e.g. anomalous boot/logon script activity) once they have produced observable events, but only for those that fall inside the scheme's chosen criteria and scope.
- T1037.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1037.001 when its execution produces a qualifying event, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, instrumentation, or detection mechanisms that would catch the technique in all cases.
- T1037.002detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether it qualifies as an information security incident; this surfaces knowledge of the login-hook persistence technique once it has produced a detectable event, but the control stops at assessment/decision/recording and does not itself perform detection instrumentation or monitoring.
- T1037.003detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; anomalous network-logon-script execution is an observable event that can be assessed and recorded, but the control does not mandate instrumentation or monitoring to surface the event itself.
- T1037.004detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of RC-script abuse when the modification or its startup execution is already observable as an event, but the control stops at assessment/prioritization and does not itself instrument or observe the technique.
- T1037.005detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the T1037.005 persistence technique once it has produced an observable event, but the control stops at assessment/prioritization/recording and does not itself perform monitoring, alerting or instrumentation that would surface the event in the first place.
- T1039detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify incidents; this surfaces knowledge of T1039 activity when it is recognized as an event, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring or detection mechanisms.
- T1040detects — A.5.25 requires assessment of every information security event against an agreed categorization scheme that explicitly includes criteria to classify events as security incidents; network sniffing (especially when it yields credentials, config details, or occurs via mirroring/CLI) is an observable event that fits those criteria and would be assessed and recorded, satisfying the verb with a bounded remainder for stealthy or sub-threshold sniffing that evades initial event detection.
- T1040responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to record the decision; this is the core of incident response once an event such as network sniffing is detected and reported.
- T1041detects — A.5.25 requires assessment of events against an agreed scheme that decides which become incidents; this surfaces knowledge of an exfiltration-over-C2 event once observed and routed to the point of contact, but the control itself supplies no instrumentation, telemetry, or monitoring to make the event observable in the first place.
- T1041responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding once an exfiltration-over-C2 event is underway, with the named remainder being actual containment/eradication that lives in the separate incident-handling clause.
- T1046detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface network service discovery as an incident when observed, but the control itself performs no monitoring or detection and depends on external observation mechanisms.
- T1047detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify them as security incidents; this surfaces knowledge of T1047 abuse (e.g. via anomalous WMI execution or shadow-copy deletion) once it has produced an observable event, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1047responds — A.5.25's assessment/prioritization of events (including those involving WMI abuse as an incident) directly enables and is performed by the personnel who coordinate and respond, matching the `responds` verb once the technique is underway.
- T1048detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface exfiltration as an incident, but the control itself only records the decision and does not mandate or perform any detection instrumentation or monitoring.
- T1048responds — A.5.25 requires assessment/prioritization of security events (including exfiltration) once underway to enable coordinated response, directly matching the `responds` verb of containing/eradication once the technique has begun.
- T1048.001detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether it qualifies as an information security incident; this surfaces knowledge of the exfiltration technique once it is observed as an event, but only for events that reach the point-of-contact and only to the extent the organization's scheme actually flags symmetric-exfiltration artifacts.
- T1048.001responds — A.5.25 requires assessment/prioritization of events (including exfiltration) once they are recognized as incidents, which directly enacts the containment/eradication decision step that `responds` names once the technique is underway.
- T1048.002detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify them as information security incidents, which surfaces knowledge of the exfiltration technique once it produces an observable event.
- T1048.002responds — A.5.25 requires assessment/prioritization of security events (including exfiltration) by the incident response team once they occur, which is the core act named by `responds` (containment/eradication once underway); the named remainder is that it stops short of actual containment steps.
- T1048.003detects — A.5.25 requires assessment of events against an agreed categorization scheme that can surface exfiltration as an information security incident, but the control itself performs no monitoring, instrumentation or detection and stops at human assessment of already-reported events.
- T1048.003responds — A.5.25 requires assessment/prioritization of security events (including exfiltration) to decide on and coordinate incident response, which directly enacts the `responds` verb once the technique is underway.
- T1049detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface T1049 execution as an incident when the discovery command or anomalous network-query pattern is recognized as a security event, but the control stops at assessment/prioritization and does not itself perform detection.
- T1052.001detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents, which can surface T1052.001 exfiltration when the USB activity is observed and routed to the assessment process; the remainder is that the control itself supplies no instrumentation or monitoring and therefore only sees events that other mechanisms have already made visible.
- T1052.001responds — A.5.25 requires assessment/prioritization of events to decide on incident response, which directly enables containment and eradication once an exfiltration event is underway.
- T1053detects — A.5.25 requires assessment of security events against an agreed categorization/prioritization scheme to decide if they are incidents; this can surface T1053 abuse when observed as an anomalous scheduled task but only for events already known to the point of contact, leaving the bulk of stealthy or pre-incident abuse undetected.
- T1053.002detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that decides whether it qualifies as an incident; this surfaces knowledge of T1053.002 when the scheduled-task artifact or its effects become an observable event, but the control stops at assessment/prioritization and does not mandate ongoing monitoring or instrumentation that would catch the technique in flight or at rest.
- T1053.002responds — A.5.25 directly requires assessment/prioritization of security events (including those from T1053.002 abuse) by the incident response team once the event is detected, which is the core act named by `responds`.
- T1053.003detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface anomalous cron/crontab activity as an incident, but the control is silent on instrumentation, monitoring coverage, or detection of the technique itself.
- T1053.005detects — A.5.25 requires assessment of security events against an agreed categorization/prioritization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1053.005 abuse when it triggers observable events that match the scheme, but the control stops at assessment/decision/recording and does not mandate instrumentation, monitoring coverage, or detection of the technique itself.
- T1053.005responds — A.5.25 requires assessment/prioritization of events using an agreed scheme and recording results; this directly engages the detection of a scheduled-task creation or execution (an observable information security event), enabling the incident response process that contains and eradicates the technique once underway, with a bounded remainder for stealth/hidden variants that evade initial categorization.
- T1053.006detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to classify events as information security incidents; this surfaces knowledge of the T1053.006 technique once it has produced an observable event, but only for those events that reach the point-of-contact and match the scheme's criteria.
- T1053.007detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify them as incidents; this surfaces knowledge of the T1053.007 technique once it has produced an observable event, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, instrumentation, or detection mechanisms that would catch the scheduling itself.
- T1053.007responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including explicit criteria for declaring an incident) and to decide on and record the outcome; this is the core act of incident response once an event (such as a suspicious CronJob or container-orchestration scheduling activity) is already underway.
- T1055detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1055 when it is observed and meets the criteria, but the control stops at assessment/decision/recording and does not mandate instrumentation, monitoring coverage, or telemetry that would surface the technique itself.
- T1055responds — A.5.25 requires assessment/prioritization of security events (including those from T1055) by the incident response team once the technique is underway, which is exactly what `responds` names; the remainder is that it stops at decision-making and does not itself perform containment/eradication.
- T1055.001detects — A.5.25 requires assessment of security events against an agreed categorization/prioritization scheme that explicitly includes criteria to classify events as incidents; this surfaces knowledge of T1055.001 once it has produced observable artifacts (e.g., anomalous process behavior), but the control stops at assessment/recording and does not mandate instrumentation or monitoring to make the technique visible.
- T1055.001responds — A.5.25 requires personnel to assess each security event using an agreed categorization/prioritization scheme (including criteria to declare it an incident) and record the decision; this directly enacts the `responds` act of handling a T1055.001 event once underway by deciding its priority and routing it for containment/eradication.
- T1055.002detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as security incidents, which can surface PE injection when it is observed and meets the criteria, but the control itself performs no monitoring, instrumentation or detection and depends entirely on events already being handed to it by other mechanisms.
- T1055.002responds — A.5.25 requires assessment/prioritization of security events (including in-flight process-injection techniques) by the incident-response team to decide on and coordinate an appropriate response, which is exactly what `responds` names.
- T1055.003detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify incidents; this surfaces knowledge of T1055.003 once it is observed as an anomalous event, but the control stops at assessment/prioritization and does not mandate ongoing monitoring or detection instrumentation.
- T1055.003responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding once an in-flight technique such as thread execution hijacking is detected.
- T1055.004detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1055.004 when it triggers observable incident criteria, but the control stops at assessment/prioritization/recording and does not mandate ongoing monitoring, instrumentation, or detection mechanisms.
- T1055.005detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface TLS callback injection as an incident (especially via its evasion and privilege effects), but the control stops at assessment/prioritization and does not itself perform detection
- T1055.008detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1055.008 when the ptrace-based injection is observed and meets the criteria, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring or instrumentation that would surface the technique in the first place.
- T1055.009detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface proc-memory injection as an incident once observed, but the control itself performs no monitoring or detection and depends on external observation mechanisms.
- T1055.011detects — A.5.25 requires assessment of security events against an agreed categorization/prioritization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1055.011 when it triggers observable incident criteria, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, telemetry, or detection mechanisms that would catch the technique in flight.
- T1055.012detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface process-hollowing indicators as incidents, but the control itself performs only after-the-fact human triage and recording rather than continuous or automated detection of the in-flight technique.
- T1055.012responds — A.5.25 requires assessment of security events using an agreed scheme to categorize, prioritize, decide on incidents and record results; this directly enacts the containment/eradication decision step once a hollowing-based incident is underway.
- T1055.013detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of the T1055.013 technique when the event is observed and routed to the assessment point, but the control itself performs no monitoring, instrumentation or detection and therefore only reaches events already handed to it.
- T1055.014detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces and records knowledge of T1055.014 when it triggers those criteria, but the control stops at assessment/prioritization and does not mandate ongoing monitoring, instrumentation, or detection mechanisms that would catch the technique in flight.
- T1055.015detects — A.5.25 requires assessment of security events using an agreed categorization scheme to decide if they qualify as incidents; this can surface ListPlanting when observed as anomalous process behavior or injection-like activity, but the control is governance-oriented, depends on detection having already occurred elsewhere, and does not itself mandate or perform the monitoring/instrumentation needed to catch the technique.
- T1055.015responds — A.5.25 requires competent personnel to assess every security event against an agreed categorization/prioritization scheme and decide whether it is an incident; this is the core of incident response once the technique is underway, with the named remainder being post-decision containment/eradication steps that live in A.5.26.
- T1056.001detects — A.5.25 requires assessment of security events against an agreed scheme that decides whether they qualify as incidents; this can surface keylogging when it produces observable events that match the criteria, but the control stops at assessment/prioritization and does not mandate instrumentation or monitoring to catch the technique itself.
- T1056.002detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1056.002 when its observable artifacts (spoofed credential prompts) meet the scheme, but the control stops at assessment/decision/recording and does not mandate instrumentation, collection or monitoring to make the events visible in the first place.
- T1056.003detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1056.003 when its observable artifacts (e.g., anomalous login-page behavior or credential exfiltration) match the scheme, but the control stops at assessment/decision/recording and does not mandate instrumentation, monitoring coverage, or detection of the technique itself.
- T1056.003responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an event is underway, and directly matches the containment/eradication act that `responds` names for a post-compromise web-portal credential-capture technique.
- T1056.004detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents; this surfaces knowledge of credential API hooking when it is observed and reported as an event, but the control itself performs no monitoring, instrumentation or discovery and therefore only reaches the subset of hooking that has already been noticed and escalated.
- T1057detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface process-discovery activity when it is recognized as an information security event, but the control only acts after the event is already reported to the point of contact and does not itself instrument or monitor for the technique.
- T1059detects — A.5.25 requires assessment of each security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of T1059 abuse when the event is observed and routed for triage, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1059responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding once an interpreter-abuse event is underway, with the named remainder being full incident containment/eradication that lives in A.5.26.
- T1059.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface PowerShell abuse as an incident, but the control itself performs only human assessment/prioritization after the event and does not mandate any detection instrumentation or automated discovery of the technique.
- T1059.001responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once the technique is already underway.
- T1059.004detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents, which surfaces knowledge of T1059.004 abuse when it produces observable events meeting the criteria, but the control stops at assessment/prioritization and does not mandate ongoing monitoring or detection instrumentation.
- T1059.004responds — A.5.25 requires assessment/prioritization of security events (including those from T1059.004 execution) to decide on incident response, directly enabling the containment/eradication act that `responds` names once the technique is underway.
- T1059.005detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of VB-based execution when the event is observed and routed to the point of contact, but the control itself performs no instrumentation, monitoring or detection and therefore only reaches the subset of events that other mechanisms have already made visible.
- T1059.006detects — A.5.25 requires assessment of events using an agreed scheme to decide if they qualify as security incidents, which can surface Python-based execution when it produces observable indicators matching the criteria, but the control is limited to post-event triage rather than proactive or broad detection of the technique itself.
- T1059.006responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding once an in-flight technique such as Python-based execution is detected.
- T1059.007detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents; this surfaces knowledge of malicious JavaScript execution when it is observed and routed for assessment, but the control itself performs no detection instrumentation or monitoring and depends on events already being noticed by other means.
- T1059.008detects — A.5.25 requires assessment of security events against an agreed categorization scheme to decide if they qualify as incidents; this surfaces knowledge of T1059.008 when it produces observable events that match the scheme, but the control stops at assessment/decision and does not mandate ongoing monitoring or instrumentation that would catch the technique in flight.
- T1059.009detects — A.5.25 requires assessment of each security event against an agreed categorization scheme to decide if it qualifies as an incident; this surfaces knowledge of malicious cloud API abuse when it is reported or observed as an event, but the control itself performs no monitoring, instrumentation or discovery and therefore only reaches the subset of events that are already handed to the incident team.
- T1059.009responds — A.5.25's assessment/prioritization of events (including deciding they are incidents) directly feeds and triggers the incident response process once an API-abuse event is underway, containing/eradication steps follow per the event-lane definition of responds; mostly because the control stops at assessment/decision/recording and does not itself perform containment.
- T1059.011detects — A.5.25 requires assessment of events against an agreed incident-categorization scheme and recording of decisions; this surfaces knowledge that a Lua-abuse event qualifies as an incident but only after the technique has already executed, and only for events routed to the defined point of contact.
- T1059.013detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1059.013 when its indicators match those criteria, but the control stops at assessment/prioritization/recording and does not mandate ongoing monitoring, instrumentation, or detection mechanisms.
- T1068detects — A.5.25 requires assessing every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of privilege-escalation exploitation when the event is observable and reaches the point of contact, but the control itself sets no instrumentation, telemetry, or detection mechanism and therefore sees only the subset of T1068 that produces recognizable events.
- T1068responds — A.5.25 requires assessment/prioritization of security events (including those from exploitation) by the incident response team once they occur, which is the core act named by `responds`.
- T1069.003detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to classify events as information security incidents; enumeration of cloud groups/permissions (T1069.003) is observable as a security event that can trigger such assessment, but the control only records the decision and does not itself perform detection instrumentation or monitoring.
- T1070.003detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether an event qualifies as an information security incident; command-history clearing is a recognizable post-compromise concealment action that would be assessed and potentially categorized as an incident, but the control only surfaces this after the technique has already run and does not mandate continuous monitoring or automated detection mechanisms.
- T1070.004detects — A.5.25 requires assessment of every information security event against an agreed scheme that decides whether it qualifies as an incident; file-deletion artifacts (especially post-intrusion cleanup) are observable events that can be assessed and therefore detected as potential incidents, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1070.004responds — A.5.25 requires assessment/prioritization of security events (including those from post-intrusion file deletion) to decide on and coordinate incident response, which directly enacts the `responds` verb once the technique is underway.
- T1070.006detects — A.5.25 requires assessment of security events against an agreed categorization/prioritization scheme that explicitly includes criteria to identify which events qualify as information security incidents; timestomping is an anti-forensic technique whose artifacts (timestamp anomalies) can be one observable input to such assessment when the scheme treats it as an incident indicator, but the control stops at assessment/decision/recording and does not itself perform detection.
- T1070.007detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether it qualifies as an information security incident; this surfaces knowledge of the T1070.007 clearing activity when the event reaches the point-of-contact, but the control stops at assessment/decision/recording and does not itself instrument or monitor for the artifacts.
- T1070.007responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding once an event (such as an adversary clearing network connection artifacts) is already underway.
- T1070.008responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once an event is underway, directly addressing T1070.008's post-impact evidence-removal technique (e.g. deleting mailbox export requests or suspicious metadata that would otherwise trigger detection).
- T1070.009detects — A.5.25 requires assessment of events against an agreed scheme to decide if they are security incidents, which can surface T1070.009 cleanup activity when it is observed and fed into the process, but the control itself performs no detection and only acts on already-known events.
- T1070.009responds — A.5.25 requires assessment/prioritization of security events (including those from T1070.009 cleanup) by the incident response team once the technique has run, which is the core act named by `responds`.
- T1070.010detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1070.010 when it meets those criteria, but the control stops at assessment/decision/recording and does not mandate instrumentation or monitoring that would catch the technique itself.
- T1070.010responds — A.5.25 requires assessment of security events (including those involving evasion like T1070.010) using an agreed scheme to categorize, prioritize, decide on incident status, and record results, which is the core of `responds` once the technique is underway.
- T1071.001detects — A.5.25 requires assessment of events against an agreed scheme that decides which qualify as security incidents; this surfaces knowledge of T1071.001 C2 traffic when it is already flagged as an event, but the control itself performs no detection and stops at assessment/prioritization of what others have already observed.
- T1071.002detects — A.5.25 requires assessment of events against an agreed scheme that decides which qualify as security incidents; this surfaces knowledge of T1071.002 when its traffic triggers the scheme, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1071.003detects — A.5.25 requires assessment of events against an agreed scheme that decides which qualify as security incidents, which can surface T1071.003 C2 when anomalous mail-protocol traffic is flagged as an event; this is genuine but limited to the post-event triage slice rather than continuous monitoring or detection instrumentation.
- T1071.004detects — A.5.25's assessment scheme and point-of-contact evaluation of events can surface DNS-tunneling/beaconing once it has produced a recognizable incident indicator, but the control itself supplies no instrumentation, monitoring or detection mechanism and stops at post-event categorization.
- T1071.004responds — A.5.25 requires assessment/prioritization of security events (including those from anomalous DNS traffic) once detected and the decision whether they constitute an incident, which is the core of `responds` (containment/eradication pathway once the technique is underway); extent is mostly because it stops at assessment/decision/recording and does not itself perform the subsequent containment steps.
- T1071.005detects — A.5.25 requires assessment of events against an agreed scheme to decide if they qualify as security incidents, which can surface pub/sub C2 blending in with normal traffic when the event reaches the point of contact, but the control is silent on instrumentation, collection or automated detection of the technique itself.
- T1072detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that decides whether it qualifies as an incident; this surfaces knowledge of T1072 abuse when the event is observed and fed into the process, but the control itself performs no monitoring or detection and depends on external observation of the event.
- T1072responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including explicit criteria for declaring an incident) and to decide on and record the outcome; this is the core act of incident response once an event is underway, directly matching the `responds` verb against T1072 abuse of deployment tools.
- T1074detects — A.5.25 requires assessment of events against an agreed incident categorization scheme, which can surface staging activity once it is treated as an information security event, but the control itself supplies no instrumentation, monitoring or detection mechanism and stops at human assessment of already-reported events.
- T1074responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once an event such as data staging is underway, enabling containment/eradication decisions.
- T1074.001detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as security incidents; this surfaces knowledge of T1074.001 when the staging activity is recognized as an event, but the control itself performs no monitoring or detection and depends on external observation to even receive the event.
- T1074.002detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1074.002 activity when it meets those criteria, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, telemetry, or detection mechanisms that would catch the staging technique itself.
- T1078detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1078 abuse when anomalous use of valid accounts triggers the scheme, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring or detection instrumentation.
- T1078responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once an event is underway, directly addressing T1078 abuse that is already in progress and harder to detect because it uses legitimate credentials.
- T1078.001detects — A.5.25 requires assessing every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of default-account abuse when it produces observable events that meet the criteria, but the control stops at assessment/prioritization and does not mandate instrumentation or monitoring to generate the events themselves.
- T1078.002detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of a domain-account abuse event once it has produced observable indicators, but the control stops at assessment/prioritization/recording and does not mandate ongoing monitoring, telemetry collection, or automated detection mechanisms.
- T1078.002responds — A.5.25 requires assessment/prioritization of security events (including those from credential abuse like T1078.002) by the incident response team once underway, enabling containment decisions; it does not itself perform eradication.
- T1078.003detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1078.003 abuse when the event meets those criteria, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, instrumentation, or detection mechanisms that would catch the technique in flight or at scale.
- T1078.003responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding once an event is underway, with a bounded remainder that the control stops at assessment/decision rather than performing full containment/eradication.
- T1078.004detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that decides whether it qualifies as an information security incident; this surfaces knowledge of malicious use of valid cloud accounts once the event is already reported or observed, but the control itself performs no monitoring, instrumentation, or discovery and therefore only reaches the subset of T1078.004 events that have already reached the assessment stage.
- T1078.004responds — A.5.25 requires assessment/prioritization of security events (including those from valid cloud account abuse) by the incident response team once underway, enabling containment decisions; the named remainder is that it stops at assessment/decision and does not itself perform containment/eradication.
- T1080detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1080 activity (tainted shared content, directory-share pivots, binary infections) once it is reported as an event, but the control stops at assessment/prioritization/recording and does not itself perform detection instrumentation or monitoring.
- T1083detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface T1083 as an incident when observed and reported, but the control itself performs no monitoring or detection and stops at post-detection assessment/prioritization.
- T1087.002detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface domain-account enumeration as an incident when observed, but the control only acts on already-reported events and does not itself instrument or monitor for the technique.
- T1087.003detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether it qualifies as an information security incident; this surfaces knowledge of T1087.003 when the enumeration is recognized as an event, but the control stops at assessment/decision and does not itself instrument or monitor for the technique.
- T1087.004detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to decide whether an event qualifies as an information security incident; this surfaces knowledge of the T1087.004 enumeration once it is treated as an observable event, but the control stops at assessment/decision/recording and does not itself perform detection or monitoring.
- T1090.001detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents; this can surface internal-proxy C2 traffic when the event is observable and meets the criteria, but the control itself performs no monitoring, detection engineering, or instrumentation and therefore only reaches the subset of events that other mechanisms have already flagged.
- T1090.002detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface proxy-based C2 as an incident, but the control itself performs only human assessment after the event is already reported rather than any automated or continuous detection mechanism.
- T1090.003detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as security incidents; this can surface multi-hop proxy traffic when it is already observable as an anomalous event, but the control itself supplies no instrumentation, monitoring, or discovery capability and stops at the governance layer of categorization/prioritization.
- T1092detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; removable-media C2 leaves observable artifacts (USB insertion, file staging/transfer) that fall inside the event-assessment scope, but the control itself performs only after-the-fact human categorization rather than continuous or automated detection of the technique.
- T1095detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1095-style non-application-layer C2 (e.g., ICMP, VMCI) when the event reaches the point-of-contact, but the control itself performs no monitoring, instrumentation, or detection and stops at post-event assessment.
- T1098detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface account manipulation as an incident, but only once the event reaches the point of contact and is recorded; it does not instrument or monitor for the technique itself.
- T1098responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once an event is underway, and account manipulation is a detectable post-compromise event that would trigger exactly that assessment/decision workflow.
- T1098.001detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of the T1098.001 technique once it has produced a detectable event, but only for events that reach the point-of-contact and match the scheme's criteria.
- T1098.002detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1098.002 when it is recognized as an incident (e.g., in persistent-threat or BEC cases), but the control stops at assessment/prioritization/recording and does not mandate instrumentation, monitoring, or detection mechanisms that would surface the technique in flight or at scale.
- T1098.003detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces and categorizes the T1098.003 technique when it is observed and reported as an event, but only reaches the subset of cases that cross the detection threshold into the event pipeline (most stealthy or external-role additions remain unseen).
- T1098.003responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once an event is underway, directly matching the `responds` verb for a persistence/privilege-escalation technique that has already executed.
- T1098.004detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the T1098.004 technique when it is reported or observed as an event, but the control stops at assessment/prioritization/recording and does not itself perform monitoring, alerting or discovery of the modification.
- T1098.005detects — A.5.25 requires assessing every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of the device-registration technique when it is observed as an event, but the control stops at assessment/prioritization and does not mandate instrumentation, telemetry collection, or monitoring that would actually surface the technique.
- T1098.005responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide/record the outcome; this directly enacts the containment/eradication decision once an adversary device-registration technique is already underway as an event.
- T1098.006detects — A.5.25 requires assessment of every security event against an agreed categorization/prioritization scheme that explicitly includes criteria to classify events as incidents; this surfaces malicious role/permission additions (T1098.006) when they are reported as events, but only reaches the subset of technique executions that generate observable events inside the organization's defined scope.
- T1102detects — A.5.25 requires assessment of events against an agreed scheme that decides which qualify as security incidents; this surfaces knowledge of T1102 use when the event is observed and routed to the assessment process, but the control itself performs no detection and the scheme's criteria are left entirely to the organization.
- T1102.001detects — A.5.25 requires assessment of events against an agreed scheme that decides which qualify as security incidents; this surfaces knowledge of the dead-drop technique when the resolver communication is already flagged as an event, but the control itself supplies neither the initial detection instrumentation nor coverage of all instances (e.g., those hidden in expected web noise).
- T1102.001responds — A.5.25's core act is to assess each security event using an agreed scheme, decide its categorization/priority as an incident, record the outcome, and hand off to personnel who coordinate and respond; this directly engages the detection-to-response handoff once a dead-drop resolver event is underway on the estate, with the named remainder being fully stealthy or pre-compromise uses that never surface as observable events.
- T1102.002detects — A.5.25 requires assessment of events against an agreed scheme that decides which qualify as security incidents; this surfaces knowledge of T1102.002 once the bidirectional Web-service C2 traffic is already treated as an observable event, but the control itself supplies neither the monitoring that would surface the traffic nor any guarantee the scheme will flag it amid legitimate noise.
- T1102.002responds — A.5.25 requires competent personnel to assess every security event against an agreed categorization/prioritization scheme (including explicit criteria for declaring an incident) and to decide on and record the outcome; this is the core act of incident response once an event is underway, and T1102.002's C2 channel produces observable events (outbound connections, posts, updates) that the scheme would classify and act upon.
- T1102.003detects — A.5.25 requires assessment of events against an agreed scheme to decide if they are security incidents; this surfaces knowledge of potential T1102.003 C2 (e.g. anomalous web flows) but only after the technique has already run and only for events that reach the point of contact, leaving the bulk of stealthy one-way uses undetected.
- T1104detects — A.5.25 requires assessment of events against an agreed scheme to decide if they qualify as security incidents, which can surface multi-stage C2 when the observable behaviors (callbacks, tool updates, redirects) match the criteria, but the control stops at categorization/prioritization and does not mandate or perform detection instrumentation itself.
- T1105detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of T1105 when the transfer is observed and categorized, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1110detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of brute-force activity (e.g. repeated failed logins) once it is reported or observed as an event, but the control itself performs no monitoring, instrumentation or discovery and therefore only reaches the subset of T1110 activity that has already been flagged as an event.
- T1110responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this directly enacts the `responds` act of handling an in-flight brute-force technique once observed.
- T1110.001detects — A.5.25 requires assessment of events against an agreed scheme that decides which ones become incidents; this surfaces knowledge of password-guessing attempts that produce observable authentication failures, but the technique's stealth variants (e.g., LDAP/Kerberos, low-and-slow, or non-triggering ports) fall outside what the control necessarily sees.
- T1110.001responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once the guessing technique has produced observable authentication failures or lockouts.
- T1110.002detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify events as information security incidents; this surfaces knowledge of T1110.002 activity when it is reported or observed as an event, but the control stops at assessment/prioritization/recording and does not mandate ongoing monitoring or detection instrumentation.
- T1110.002responds — A.5.25 requires assessment/prioritization of security events (including those from observed cracking attempts) by the incident response team to decide on handling, which is the core of `responds` once the technique is underway.
- T1110.003detects — A.5.25 requires assessment of events against an agreed scheme that decides which ones become incidents; this surfaces knowledge of password-spraying attempts that cross the scheme's threshold but does not mandate instrumentation or monitoring that would catch the low-and-slow, throttled, or non-4625 variants described in the technique.
- T1110.003responds — A.5.25 requires assessment/prioritization of security events (including those from password spraying attempts) by the incident response team once underway, enabling a decision on whether to treat as an incident and record results for coordinated response.
- T1110.004detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents; this surfaces and categorizes credential-stuffing attempts that produce observable authentication failures or anomalies, but only after they have already been generated and only for those that meet the organization's chosen criteria.
- T1110.004responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding to an in-flight credential-stuffing event once it is detected as an information security event.
- T1111detects — A.5.25 requires assessment of every security event against an agreed categorization/prioritization scheme that explicitly includes criteria to classify events as incidents; this surfaces and records MFA-interception events once they are observed and fed in, but the control itself performs no detection instrumentation or generation of the initial events.
- T1111responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to record the decision; this is the core act of responding to an MFA-interception event once it is detected and underway.
- T1112detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether it qualifies as an information security incident; registry-modification activity (especially when tied to defense evasion or persistence) can be one observable event that is assessed and potentially categorized as an incident, but the control itself supplies no detection mechanism, sensor, or monitoring and therefore only reaches the subset of T1112 activity that surfaces through other means.
- T1114detects — A.5.25 requires assessment of events against an agreed scheme to decide if they qualify as security incidents, which can surface email-collection activity once it is reported or observed as an event, but does not itself instrument, monitor or discover the technique.
- T1114responds — A.5.25 requires assessment/prioritization of security events (including those revealing T1114 email collection, e.g. via IR details in stolen mail) to drive coordinated response, which matches the `responds` verb once the technique is underway; mostly because it stops at assessment/decision/recording and does not itself perform containment or eradication.
- T1114.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1114.001 when it triggers those criteria, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, telemetry, or instrumentation that would catch the technique in flight.
- T1114.002detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify them as information security incidents, which surfaces knowledge of the T1114.002 technique once it has produced observable events
- T1114.002responds — A.5.25 requires assessment/prioritization of events to decide if they are incidents and trigger coordinated response, which directly enacts the `responds` verb once the T1114.002 collection technique is underway.
- T1114.003detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1114.003 when its artifacts (e.g., anomalous forwarding rules) are reported as events, but the control stops at assessment/prioritization and does not itself perform monitoring, collection, or discovery of the technique.
- T1114.003responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an event is underway, directly matching the `responds` verb for a technique that produces detectable forwarding-rule events.
- T1115detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface clipboard collection as an incident when observed and reported, but the control itself performs no monitoring or detection and depends entirely on external observation mechanisms.
- T1123detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents; this surfaces knowledge of T1123 once it produces observable events, but the control stops at assessment/prioritization and does not itself perform monitoring or detection instrumentation.
- T1127detects — A.5.25 requires assessment of events against an agreed incident categorization scheme and recording of decisions; this surfaces and categorizes T1127 activity once observed as an event but does not mandate or guarantee instrumentation that would observe the technique itself.
- T1127.001detects — A.5.25 requires assessment of events against an agreed incident categorization scheme and recording of decisions; this surfaces knowledge of an MSBuild abuse event once it is reported or observed as a security event, but the control itself performs no monitoring, telemetry collection, or proactive detection and the scheme's criteria are organization-defined.
- T1127.002detects — A.5.25 requires assessment of events against an agreed scheme to decide if they qualify as security incidents, which can surface ClickOnce abuse as an anomalous or suspicious event once observed, but only reaches the subset of events that reach the point-of-contact for triage rather than reliably detecting the technique itself.
- T1127.003detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that explicitly includes criteria to identify events as information security incidents; this surfaces knowledge of the JamPlus abuse when it is reported or observed as an event, but the control stops at assessment/prioritization/recording and does not mandate ongoing monitoring, telemetry, or automated detection mechanisms that would catch the technique in flight or at execution.
- T1129detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface loading of shared modules as an incident when observed, but the control itself performs no detection and only acts on events already handed to it.
- T1132.001detects — A.5.25 requires assessment of events against an agreed scheme that decides which qualify as security incidents; this surfaces knowledge of encoded C2 (once observed as an event) but only for the subset that meets the scheme's criteria, leaving the bulk of stealthy encoding undetected at the traffic level.
- T1132.002detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents, which can surface non-standard encoding in C2 traffic when it is observed and fed into the scheme, but the control itself performs no monitoring, instrumentation or detection and stops at human assessment of already-reported events.
- T1134.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1134.001 when the scheme's criteria match its observable artifacts (e.g., anomalous token duplication or impersonation calls), but the control stops at assessment/decision/recording and does not mandate instrumentation, monitoring coverage, or detection mechanisms themselves.
- T1134.001responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once the technique is underway, with the named remainder being full containment/eradication (owned by A.5.26).
- T1134.002detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that explicitly includes criteria to identify incidents; this surfaces knowledge of T1134.002 when its artifacts match those criteria, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, instrumentation, or detection mechanisms.
- T1134.003detects — A.5.25 requires assessment of security events against an agreed scheme that decides whether they qualify as incidents; this surfaces knowledge of T1134.003 when the scheme's criteria match its observable artifacts (e.g., anomalous LogonUser/SetThreadToken use), but the control itself sets no instrumentation or detection requirements and leaves most technique executions outside the assessed events.
- T1134.004detects — A.5.25 requires assessment of security events against an agreed categorization/prioritization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of PPID-spoofing events when they match those criteria, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, telemetry collection, or automated detection mechanisms that would catch the technique in flight.
- T1134.005detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of SID-History Injection when the event reaches the point-of-contact, but the control stops at assessment/prioritization and does not itself instrument or observe the technique.
- T1136detects — A.5.25 requires assessment of security events against an agreed scheme that decides whether they qualify as incidents; this surfaces knowledge of the T1136 account-creation technique when it is observed and routed as an event, but the control stops at assessment/prioritization and does not itself instrument or monitor to catch the creation act.
- T1136responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (explicitly including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding once an event (account creation) is underway, with the named remainder being full incident containment/eradication that lives in A.5.26.
- T1136.001detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; creation of a local account is observable (command execution, new account artifacts) and would be assessed when surfaced by monitoring, but the control itself performs only the assessment/prioritization step and does not mandate or perform the initial detection instrumentation.
- T1136.002detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents, which can surface the creation of a domain account when it is observed and fed into that process, but the control itself performs no monitoring, instrumentation or discovery and therefore only reaches the subset of events that are already handed to it.
- T1136.003detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the T1136.003 account-creation event when it meets those criteria, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, telemetry collection, or automated detection mechanisms that would catch the technique in flight or at scale.
- T1136.003responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an event is underway, directly matching the `responds` verb for a persistence technique that has already succeeded in creating the account.
- T1137detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1137-based persistence when it triggers an observable event that meets the scheme, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, telemetry, or detection mechanisms that would catch the technique itself.
- T1137.001detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that decides whether it qualifies as an information security incident; this surfaces knowledge of T1137.001 when the macro-based persistence produces a detectable event, but the control stops at assessment/prioritization and does not mandate ongoing monitoring or instrumentation that would catch the technique itself.
- T1137.002detects — A.5.25 requires assessment of events against an agreed categorization scheme that can surface Office Test registry abuse as an information security incident, but the control itself performs no detection and depends on some other mechanism first surfacing the event.
- T1137.003detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents; this surfaces knowledge of the T1137.003 technique once it has produced a detectable event (e.g. suspicious form loading or crafted email), but the control's scope is limited to post-event triage rather than continuous monitoring or broad detection coverage.
- T1137.003responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once the T1137.003 persistence technique has executed and produced observable events.
- T1137.004detects — A.5.25 requires assessment of each security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of the T1137.004 persistence technique once it has produced observable activity, but the control stops at assessment/decision and does not mandate ongoing monitoring or instrumentation that would catch the initial mailbox change or HTML load.
- T1137.004responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding once an event is underway, with the named remainder being full containment/eradication that lives in A.5.26.
- T1137.005detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that decides whether it qualifies as an incident; this surfaces knowledge of the T1137.005 technique once the triggering email arrives and is processed as an observable event, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring or detection instrumentation.
- T1137.005responds — A.5.25's assessment/prioritization of events (including deciding they are incidents) directly feeds and initiates the incident response process once the malicious rule has executed on a crafted email, with the named remainder being full containment/eradication handled by separate response procedures.
- T1137.006detects — A.5.25 requires assessment of events against an agreed scheme to decide if they qualify as security incidents, which can surface add-in-based persistence when the event is observed and routed for triage, but the control itself performs no detection and stops at assessment of already-identified events.
- T1137.006responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into declared incidents) and to decide on and record the outcome; this is the core act of responding once the add-in persistence technique has produced a detectable event.
- T1176detects — A.5.25 requires assessment of events against an agreed incident categorization scheme and recording of decisions; this surfaces some T1176 events once they are already flagged as security events, but the control does not itself perform or require any detection instrumentation, monitoring, or discovery of the extension-installation technique.
- T1176.001detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1176.001 when its indicators appear in logged events, but the control stops at assessment/prioritization/recording and does not itself perform detection collection or monitoring.
- T1176.002detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the T1176.002 technique once it produces observable events, but the control stops at assessment/prioritization/recording and does not mandate ongoing monitoring, telemetry collection, or detection mechanisms that would catch the technique in flight or at installation.
- T1185detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1185 when it triggers those criteria, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, instrumentation, or detection mechanisms that would catch the technique in flight.
- T1185responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an event is underway, and T1185's browser-injection/pivoting actions are observable events that would trigger exactly that assessment/decision process.
- T1187detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; forced-authentication activity (SMB/WebDAV hash capture) is observable as anomalous network or file-access behaviour and can therefore be assessed and recorded, but the control only supplies the assessment step and does not itself perform detection instrumentation or monitoring.
- T1189detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to decide whether an event qualifies as an information security incident; a successful drive-by compromise produces observable events (e.g., anomalous browser behavior, unexpected code execution) that can be assessed this way, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1189responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding to an event already underway, with the named remainder being full incident containment/eradication that lives in A.5.26.
- T1190detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of T1190 exploitation attempts that manifest as observable events, but only after they have occurred and only for those that reach the point-of-contact assessment step.
- T1190responds — A.5.25 requires assessment/prioritization of security events (including those from T1190 exploitation) by the incident response team once the event has occurred and is underway, enabling containment decisions; this matches the `responds` verb but leaves a named remainder for full eradication/recovery handled by other controls.
- T1197detects — A.5.25 requires assessment of events against an agreed categorization scheme that can surface BITS abuse as an information security incident (e.g. via anomalous background job behavior), but the control stops at assessment/prioritization and does not itself perform or mandate the monitoring that would generate the events to assess.
- T1199detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of a T1199 event once it has produced observable indicators, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring or detection mechanisms.
- T1203detects — A.5.25 requires assessment of security events against an agreed scheme that decides whether they qualify as incidents; this surfaces knowledge of exploitation events that manifest observable consequences, but the control is silent on instrumentation, telemetry, or detection of the technique itself before or during execution.
- T1203responds — A.5.25 requires personnel to assess each security event against an agreed scheme, decide whether it qualifies as an incident, and record the outcome; this is the core act of responding once the exploitation technique has produced observable events.
- T1204detects — A.5.25 requires assessing every security event against an agreed scheme to decide if it qualifies as (and how to prioritize) an information security incident; this surfaces knowledge of user-execution events that meet the criteria but does not mandate instrumentation or monitoring to catch the technique itself, leaving most instances outside the assessment window.
- T1204responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once the user-execution technique has produced observable follow-on behavior.
- T1204.001detects — A.5.25 requires assessing each security event against an agreed categorization scheme that decides whether it qualifies as an information security incident; this surfaces and records knowledge of T1204.001 when the click is observed as an event, but the control stops at assessment/prioritization and does not mandate ongoing monitoring or detection instrumentation.
- T1204.001responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding to an in-flight incident whose follow-on behavior is the T1204.001 user click.
- T1204.002detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1204.002 when the user-action event is observed and meets the criteria, but the control stops at assessment/decision/recording and does not mandate instrumentation, monitoring coverage, or detection of the technique itself.
- T1204.002responds — A.5.25 requires assessment/prioritization of security events (including those from T1204.002 user execution) by the incident response team to decide on handling, which is the core of `responds` once the technique is underway; mostly because it stops at categorization/decision and does not itself perform containment/eradication.
- T1204.003detects — A.5.25 requires assessing every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of malicious-image execution when the resulting anomaly or artifact is reported as an event, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1204.004detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether it qualifies as an information security incident; this surfaces and records knowledge of T1204.004 events once they are reported, but only for those that reach the point-of-contact and match the scheme's criteria, leaving the bulk of stealthy or unreported instances untouched.
- T1204.004responds — A.5.25 requires assessment, categorization, prioritization, and recorded decision on security events (including those from social-engineering-driven user actions like ClickFix), which directly enacts the containment/eradication steps of `responds` once the technique is underway; the named remainder is that it stops short of full incident-handling actions such as eradication or recovery.
- T1204.005detects — A.5.25 requires assessment of security events against an agreed scheme that decides whether they qualify as incidents; this surfaces knowledge of malicious-library installation events once they are reported or observed as candidate events, but the control itself performs no monitoring, instrumentation or discovery and therefore only reaches the subset of events that have already been handed to the assessment process.
- T1204.005responds — A.5.25 requires assessment/prioritization of security events (including those from malicious library execution) by the incident response team once underway, which is exactly what `responds` names.
- T1205detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify events as security incidents; traffic signaling packets or sequences are observable network anomalies that can be assessed and recorded this way, but the control only surfaces them once they occur as events and does not mandate any specific detection mechanism or coverage of all variants (e.g. raw sockets, WoL, embedded device signaling).
- T1205.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface port-knocking patterns as incidents, but the control itself performs only after-the-fact human assessment and recording rather than continuous or automated detection of the technique.
- T1205.002detects — A.5.25 requires assessment of events against an agreed categorization scheme that can surface a socket-filter activation as an information security incident, but the technique's passive/low-activity nature (no active socket until trigger packet) leaves substantial detection gaps that the control does not close.
- T1207detects — A.5.25 requires assessment of every security event against an agreed categorization/prioritization scheme that explicitly includes criteria to classify events as incidents; this surfaces and decides on T1207 activity when it is recognized as an event, but the technique's explicit design to bypass SIEM/logging means many instances never become visible events for the scheme to act on.
- T1207responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this directly enacts the containment/eradication decision once a T1207 rogue-DC registration event is underway and detected.
- T1210detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1210 exploitation attempts when they manifest as observable events, but only after they have occurred and only for those that meet the scheme's criteria.
- T1210responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this directly enacts the `responds` verb once T1210 exploitation is underway as an observable event, with the named remainder being events that evade initial detection or fall outside the agreed scheme.
- T1212detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of exploitation attempts that manifest as observable events, but many T1212 instances (e.g. silent credential forgery or replay that does not trigger an event) stay outside any event stream the scheme can assess.
- T1213detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1213 when repository-access or exfiltration events are observed and meet the criteria, but the control stops at assessment/decision/recording and does not itself perform detection instrumentation or monitoring.
- T1213.005detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of adversary use of messaging apps when the event is observable, but the control stops at assessment/prioritization and does not mandate instrumentation that would catch the technique itself.
- T1213.005responds — A.5.25 requires assessment/prioritization of events (including those involving messaging apps leaking IR discussions or credentials) to drive coordinated response, directly matching the `responds` verb once the technique is underway.
- T1216detects — A.5.25 requires assessment of events against an agreed incident categorization scheme, which can surface T1216 proxy execution as a security event if observed and reported, but the control itself performs no monitoring, instrumentation, or detection and stops at human assessment of already-known events.
- T1216.001detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1216.001 abuse when the event is observed and assessed, but the control stops at assessment/decision/recording and does not itself perform detection instrumentation or monitoring.
- T1216.002detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether it qualifies as an information security incident; this surfaces knowledge of the T1216.002 technique once it has produced observable artifacts that reach the point of contact, but the control stops at assessment/decision/recording and supplies no instrumentation, telemetry, or monitoring capability itself.
- T1218detects — A.5.25 requires assessment of events using an agreed categorization scheme that can surface proxy-execution anomalies as security incidents once they are reported or observed, but the control itself performs no detection or monitoring and depends on external sources for the events it assesses.
- T1218.001detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents; this surfaces knowledge of T1218.001 when it is recognized as an incident but does not instrument or observe the technique itself.
- T1218.002detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that decides whether it qualifies as an incident; this surfaces knowledge of T1218.002 executions that manifest as observable events, but the control stops at assessment/prioritization and does not mandate ongoing monitoring, telemetry collection, or detection mechanisms that would catch stealthy or non-incident-classified abuse.
- T1218.003detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify incidents; this surfaces knowledge of T1218.003 when its observable artifacts (suspicious CMSTP.exe invocation with INF/SCT) are reported as an event, but the control stops at assessment/prioritization and does not itself perform detection collection or monitoring.
- T1218.003responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria to declare it an incident) and record the decision; this is the core of incident response once the CMSTP abuse event is underway, with the bounded remainder being full eradication/containment actions that live in A.5.26.
- T1218.004detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1218.004 when it triggers the scheme, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, instrumentation, or telemetry that would surface the technique itself.
- T1218.005detects — A.5.25 requires assessment of each security event against an agreed categorization scheme to decide if it qualifies as an incident; this surfaces knowledge of T1218.005 when it is observed and reported as an event, but the control stops at assessment/prioritization and does not mandate ongoing monitoring or detection mechanisms.
- T1218.005responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to record the decision; this is the core of incident response once the mshta abuse event is underway, with the named remainder being the subsequent containment/eradication steps that live in A.5.26.
- T1218.007detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that explicitly includes criteria to identify events as information security incidents; this surfaces knowledge of the T1218.007 technique when it triggers an observable event, but the control stops at assessment/prioritization/recording and does not mandate ongoing monitoring, instrumentation, or detection mechanisms.
- T1218.008detects — A.5.25 requires assessment of events using an agreed categorization scheme that can surface anomalous use of signed binaries like odbcconf.exe as security incidents, but the control is governance-oriented (defining criteria and recording decisions) and does not itself perform or instrument detection.
- T1218.009detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the T1218.009 technique when its observable artifacts (e.g. anomalous Regsvcs/Regasm invocation) meet the scheme's criteria, but the control stops at assessment/decision/recording and does not mandate instrumentation, collection or monitoring that would guarantee the event is even visible.
- T1218.010detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents; this surfaces knowledge of T1218.010 when the proxy-execution or Squiblydoo pattern is recognized as an event, but the control stops at categorization/prioritization and does not itself perform monitoring or detection instrumentation.
- T1218.010responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an event is underway, directly matching the `responds` verb for a technique already in flight.
- T1218.011detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1218.011 when its artifacts (rundll32.exe proxying, anomalous DLL/script execution, masquerading) are presented as an event, but the control stops at assessment/prioritization/recording and does not itself perform detection or monitoring.
- T1218.012detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that decides whether it qualifies as an incident; this surfaces knowledge of the T1218.012 technique once it has produced observable evidence that reaches the point of contact, but the control stops at assessment/prioritization and does not mandate ongoing monitoring or specific detection instrumentation.
- T1218.013detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the mavinject abuse when the event is observed and meets the criteria, but the control stops at assessment/decision/recording and does not mandate instrumentation, telemetry, or monitoring that would surface the technique itself.
- T1218.013responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once the technique is underway.
- T1218.014detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1218.014 executions that meet those criteria, but the clause stops at assessment/prioritization/recording and does not mandate instrumentation, telemetry, or automated detection mechanisms that would catch the technique in flight or at scale.
- T1218.014responds — A.5.25 requires assessment of each security event against an agreed categorization/prioritization scheme to decide if it is an incident and to record the outcome; this directly enacts the `responds` verb (act on an event once underway via containment/eradication workflow) for T1218.014 MMC abuse when it is surfaced as an event.
- T1218.015detects — A.5.25 requires assessment of events against an agreed incident-categorization scheme and recording of decisions; this surfaces knowledge that a given event is (or is not) an information-security incident, which can include Electron-abuse artifacts when they trigger the scheme, but the control itself supplies no instrumentation, telemetry, or scanning and therefore only detects what is handed to it by other mechanisms.
- T1219detects — A.5.25 requires assessment of events against an agreed scheme that decides which ones become incidents; this surfaces knowledge of RAT usage when it triggers the scheme but does not mandate instrumentation or monitoring that would catch the technique itself.
- T1219responds — A.5.25's assessment/prioritization of events (including those involving RAT C2) directly feeds and enables the incident response process once the technique is underway, satisfying the verb even though the control itself stops at assessment rather than performing containment.
- T1219.001detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of the IDE-tunneling C2/persistence technique when the event is observed and routed to the assessment point, but the control itself performs no monitoring, instrumentation or detection and therefore only reaches the subset of events that other mechanisms have already made visible.
- T1219.002detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1219.002 when the remote-desktop C2 activity is recognized as matching those criteria, but the control stops at assessment/decision/recording and does not itself perform detection instrumentation or monitoring.
- T1219.002responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including explicit criteria to declare it an incident) and to decide on and record the outcome; this is the core act of responding to an in-flight technique that has already produced observable events.
- T1219.003detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly decides whether it qualifies as an incident; hardware-based C2 via KVM is observable as an anomalous or unauthorized peripheral/comms channel and would therefore be assessed and potentially flagged as an incident, but the control stops at assessment/decision/recording and does not itself perform detection instrumentation or monitoring.
- T1220detects — A.5.25 requires assessing events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1220 executions (e.g. anomalous msxsl.exe or wmic /FORMAT usage) once they have occurred and are reported as events, but only for those that meet the scheme's criteria and only after the fact.
- T1221detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1221 when the resulting document/template fetch or forced-authentication behavior is observed and routed for assessment, but the control stops at assessment/prioritization/recording and does not itself perform detection instrumentation or monitoring.
- T1222.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface permission-modification activity as an incident, but the control is silent on instrumentation, telemetry, or automated detection of the technique itself.
- T1222.002detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface permission-modification activity as an incident, but the control is governance-oriented (assessment/prioritization after the fact) and does not itself mandate or perform detection instrumentation.
- T1484detects — A.5.25 requires assessment of each security event against an agreed categorization/prioritization scheme that explicitly includes criteria to classify events as incidents; this surfaces and records knowledge of T1484 when the modification (or its downstream effects) is observed as an event, but the control stops at assessment/decision and does not mandate instrumentation, monitoring coverage, or detection of the technique itself.
- T1484.001detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of a T1484.001 execution once it is reported as an event, but the control itself performs no monitoring, instrumentation or discovery and therefore only covers the subset of cases that reach the point-of-contact.
- T1484.001responds — A.5.25 requires assessment, categorization, prioritization, and recorded decision on security events (including those from GPO modification), which directly enacts the containment/eradication decision step once the technique is underway.
- T1484.002detects — A.5.25 requires assessment of every security event against an agreed categorization/prioritization scheme that explicitly includes criteria to classify events as incidents; this surfaces malicious trust modifications once they are reported or observed as events, but only within the scope of events that reach the point of contact and only for the classification act itself.
- T1484.002responds — A.5.25 requires assessment of each security event against an agreed categorization/prioritization scheme (including criteria to declare it an incident) plus recording the decision; this directly enacts the containment/eradication decision point once a trust-modification technique is already underway, with the named remainder being full incident response workflow beyond mere assessment.
- T1485detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of a data-destruction event once reported to the point of contact, but the control itself supplies no instrumentation, monitoring or discovery mechanism and therefore only detects the subset of T1485 events that are already handed to it.
- T1485responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into declared incidents) and to record the decision; this is the exact act of responding once an incident is underway, with the named remainder that it stops at assessment/prioritization rather than performing containment or eradication.
- T1485.001detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify incidents; this surfaces knowledge of the lifecycle-policy modification (or its immediate effects) once it is reported as an event, but the control stops at assessment/prioritization and does not itself instrument or monitor for the technique.
- T1486detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an information security incident; this surfaces knowledge of T1486 ransomware events once they produce observable impact, but the control stops at assessment/prioritization and does not require ongoing monitoring or detection instrumentation.
- T1486responds — A.5.25 requires assessment/prioritization of events using an agreed scheme plus recording results, which directly enables and is the first step of incident response once the ransomware encryption event is underway (containment/eradication follow from that decision).
- T1489detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify incidents; stopping critical services (especially those that inhibit incident response) is an observable event that would be assessed and potentially categorized as an incident, but the control stops at assessment/decision/recording and does not itself perform detection instrumentation or monitoring.
- T1489responds — A.5.25's assessment/prioritization of events (including those that stop services to inhibit incident response) directly enables the coordinated response once the technique is underway, matching the event-lane definition of responds; mostly because the control stops at assessment/decision/recording and does not itself perform containment or eradication.
- T1490detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces and records T1490 activity (deletion of recovery mechanisms) once it has occurred, but only for events that reach the point-of-contact and match the scheme's criteria.
- T1490responds — A.5.25 requires assessment/prioritization of security events (including those that have already executed T1490) by the incident response team and records the decision, which is the core of `responds` once the technique is underway.
- T1491detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; a realized T1491 defacement is an observable event that would be assessed and therefore surfaced as an incident, but the control itself supplies no instrumentation, monitoring, or discovery mechanism and only grades events that have already reached the point-of-contact.
- T1491responds — A.5.25 requires assessment/prioritization of security events (including those from defacement) by the incident response team and recording of decisions, which is the core of responding once the technique is underway.
- T1491.001detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; internal defacement (visible changes to internal assets) is an observable event that would be assessed and therefore detected as an incident when the scheme includes integrity or availability impacts, but the control does not mandate instrumentation or monitoring to surface the event itself.
- T1491.001responds — A.5.25 requires competent personnel to assess every security event against an agreed scheme that decides whether it is an incident and what priority it receives, which is the core of incident response once the defacement technique has run and is underway.
- T1491.002detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; external defacement is an observable event that can be assessed this way, but the control only surfaces/records it once reported to the point of contact and does not itself instrument or discover the defacement.
- T1491.002responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including whether it qualifies as an incident) and record the decision; external defacement is a visible, high-visibility event that would be assessed and decided upon as part of incident response once it has occurred.
- T1495detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of a T1495 event once it has produced observable consequences, but the control stops at assessment/prioritization/recording and does not mandate ongoing monitoring, specific detection mechanisms, or coverage of stealthy firmware writes.
- T1496detects — A.5.25 requires assessment of events against an agreed scheme that decides which ones qualify as security incidents, which surfaces knowledge of resource-hijacking activity once it has produced a detectable event; the remainder is that the control itself supplies no instrumentation, detection logic, or telemetry and therefore sees only the subset of hijacking that triggers an already-monitored event.
- T1496responds — A.5.25 requires competent personnel to assess each security event against an agreed scheme, decide if it is an incident, and record the outcome; this directly enacts the assessment/prioritization step that begins incident response once resource hijacking (T1496) is underway.
- T1496.001detects — A.5.25 requires assessment of events against an agreed scheme to decide if they qualify as security incidents, which can surface compute hijacking when it produces observable anomalous resource consumption or competing-process behavior, but the control stops at categorization/prioritization and does not mandate instrumentation or monitoring to generate the events in the first place.
- T1496.001responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (explicitly including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an event is underway, directly matching the `responds` verb for a compute-hijacking technique that manifests as observable resource-impact events.
- T1496.002detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents; bandwidth hijacking produces observable anomalies (availability impact, unexpected traffic, financial metering spikes) that can be assessed and recorded as incidents, but the control itself supplies no instrumentation, monitoring, or detection mechanism and depends on events already reaching the assessment point.
- T1496.002responds — A.5.25 requires assessment/prioritization of events (including those matching T1496.002 symptoms like anomalous bandwidth use) to decide on incident response, directly enabling the containment/eradication act that `responds` names once the technique is underway.
- T1496.003detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that explicitly includes criteria to identify events as information security incidents; this surfaces and records SMS-pumping events (as availability/cost-impact incidents) once they reach the point of contact, but the control itself performs no monitoring, instrumentation or automated detection and therefore only covers the assessment slice of the full detection surface.
- T1496.003responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding once an SMS-pumping event is underway, with the named remainder being full incident containment/eradication that lives in A.5.26.
- T1496.004detects — A.5.25 requires assessment of each security event against an agreed categorization/prioritization scheme that explicitly includes criteria to classify events as incidents; this surfaces knowledge of the T1496.004 technique once it has produced observable events (e.g. anomalous SaaS usage, quota exhaustion, or billing spikes), but the control stops at assessment/recording and does not mandate instrumentation, monitoring coverage, or detection of the technique itself.
- T1496.004responds — A.5.25 requires assessment/prioritization of events (including those matching T1496.004) by the incident response team once they are recognized, which directly enacts the containment/eradication decision step that `responds` names
- T1498detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces and categorizes a realized Network DoS (once traffic volume or impact is observed and reported) but only for events that reach the point-of-contact, leaving many stealthy or low-and-slow DoS attempts outside the scheme's practical scope.
- T1498responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once a Network DoS event is underway, with the bounded remainder being actual containment/eradication actions that live in A.5.26.
- T1498.001detects — A.5.25 requires assessment of events against an agreed scheme that decides which become incidents; this surfaces and categorizes a realized network flood (an observable event with impact) but only where the flood is already inside the organization's monitored scope and the scheme includes volumetric DoS criteria — it does not instrument detection itself.
- T1498.001responds — A.5.25 requires assessment/prioritization of security events (including floods) by the incident response team once they occur, which is the core of `responds` (containment/eradication once underway); mostly because it stops at assessment/decision without mandating full eradication steps.
- T1498.002detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify them as incidents; this surfaces and records reflection-amplification DoS events once observed, but the control itself supplies no instrumentation, monitoring, or detection mechanism and therefore only grades the assessment slice.
- T1498.002responds — A.5.25 requires assessment, categorization, prioritization, and recorded decision on security events (including network DoS like reflection amplification), which is the core of incident response once the event is underway.
- T1499detects — A.5.25 requires assessment of security events against an agreed scheme to decide if they qualify as incidents (and to prioritize them); this surfaces knowledge of an in-progress or realized Endpoint DoS but only for those events that reach the point-of-contact and match the scheme's criteria, leaving the bulk of stealthy/low-and-slow or pre-incident DoS activity outside its scope.
- T1499responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on them, which is the core of incident response once an Endpoint DoS is underway; recording supports that process, though the control stops short of mandating full containment/eradication actions.
- T1499.001detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to designate them as information security incidents; this surfaces knowledge of the OS-exhaustion flood once it is observed as an event, but the control stops at assessment/prioritization/recording and does not mandate any monitoring, instrumentation or detection capability itself.
- T1499.001responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding to an in-flight DoS event once it is detected.
- T1499.002detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents, which can surface a service-exhaustion flood once it is already observable as an event, but the control itself performs no monitoring, instrumentation, or detection and stops at human categorization/prioritization of whatever is handed to it.
- T1499.002responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once the DoS flood is underway, with the named remainder being full containment/eradication (owned by A.5.26).
- T1499.003detects — A.5.25 requires assessment of events using an agreed scheme to decide if they qualify as security incidents, which can surface application-exhaustion floods as incidents when they match the criteria, but the control itself performs no monitoring, instrumentation, or automated detection and depends on events already being observed by other means.
- T1499.003responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once the exhaustion flood is underway, with the bounded remainder being full eradication/containment that lives in the paired A.5.26 clause.
- T1499.004detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of exploitation-induced crashes/DOS when they are reported or observed as events, but the control itself performs no instrumentation, monitoring or automated detection and stops at human triage of already-known events.
- T1499.004responds — A.5.25 requires assessment/prioritization of events using an agreed scheme plus recording results, which directly engages the core of incident response once an exploitation event is underway (triage to decide handling, escalation, and recording for eradication/follow-up).
- T1505detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify them as information security incidents, which surfaces knowledge of T1505 when it triggers such an event; the remainder is that the control is silent on instrumentation or monitoring that would surface the technique before or without an event being raised.
- T1505responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once an event is underway, and T1505's installed malicious server component would surface as such an event.
- T1505.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface a malicious/persistent stored-procedure creation as an incident, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1505.002detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the malicious transport agent when its email-triggered behavior is observed and meets the criteria, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring or instrumentation that would catch the registration or stealthy persistence itself.
- T1505.003detects — A.5.25 requires assessment of events against an agreed scheme that decides which qualify as security incidents; this surfaces knowledge of a web shell once it triggers an observable event, but the control is silent on instrumentation, collection or real-time detection of the technique itself.
- T1505.003responds — A.5.25 requires assessment/prioritization of security events (including those from web shell deployment) by the incident response team once the event is underway, which is exactly what `responds` names.
- T1505.004detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of malicious IIS component installation when the event is observed and routed to the point of contact, but the control itself supplies no instrumentation, telemetry, or discovery mechanism to generate the events in the first place.
- T1505.004responds — A.5.25 requires assessment, categorization, prioritization, and recorded decision on security events (including those from installed malicious IIS components), which is the core of incident response once the persistence technique is underway.
- T1505.005detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that explicitly includes criteria to identify incidents; this surfaces knowledge of the T1505.005 technique once it has produced observable artifacts (e.g. anomalous RDP behavior or service modification), but the control stops at assessment/decision/recording and does not mandate ongoing monitoring or detection instrumentation.
- T1505.006detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of malicious VIB installation/persistence activity when it is reported or observed as an event, but the control stops at assessment/decision/recording and does not itself perform detection collection or monitoring.
- T1518detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1518 when the enumeration activity is observed and meets the incident criteria, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring or instrumentation that would catch the technique in the first place.
- T1518.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface discovery activity as an incident, but the control is silent on instrumentation, telemetry, or real-time detection of the technique itself.
- T1518.002detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface discovery activity as an incident precursor, but the control is silent on instrumentation, telemetry collection, or automated detection of the specific commands or artifacts named in T1518.002.
- T1525detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; an image-implant event is observable (e.g., via registry or instance logs) and can be assessed and recorded, but the control itself supplies no instrumentation, monitoring, or scanning and therefore only detects those events that are already surfaced by other means.
- T1528detects — A.5.25 requires assessing every security event against an agreed scheme that decides whether it qualifies as an incident; token-theft events (esp. via OAuth phishing, container compromise, or IMDS abuse) can be observed as anomalous events and thereby assessed and categorized, but the control stops at assessment/prioritization and does not itself instrument or surface the theft.
- T1528responds — A.5.25 requires assessment/prioritization of security events (including those from token theft) by the incident response team once they have occurred, which is exactly what `responds` names; the remainder is that it stops at decision-making and does not itself perform containment/eradication.
- T1529detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; shutdown/reboot events that visibly impede response/recovery or follow other destructive TTPs can be categorized and prioritized this way, but many standalone or stealthy instances produce no observable event for the point-of-contact to assess.
- T1529responds — A.5.25 requires assessment/prioritization of security events (including those from T1529 shutdowns that impede response/recovery) by the incident team once underway, directly enabling the containment/eradication acts that `responds` names.
- T1530detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether it qualifies as an information security incident; this surfaces knowledge of T1530 events (e.g., anomalous cloud-storage access) once reported, but only for events that reach the point-of-contact and only to the extent the scheme's criteria cover them.
- T1530responds — A.5.25 requires assessment/prioritization of security events (including data-access incidents) by the incident-response team once they are identified, which directly enacts the `responds` verb on T1530 once the technique is underway.
- T1531detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of T1531 when the account-access-removal event is observed and routed to the point of contact, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1531responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once an Impact technique like T1531 is underway, enabling containment/eradication decisions, with the named remainder being that the control stops at assessment/decision rather than executing full containment.
- T1534detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents, which surfaces and records internal spearphishing events once they are observed and reported but does not mandate ongoing monitoring or instrumentation that would catch the technique in flight.
- T1534responds — A.5.25 requires assessment/prioritization of security events (including those matching internal spearphishing) by the incident response team to decide on handling, which is the core of `responds` once the technique is underway; mostly because it stops at categorization/decision and does not itself perform containment or eradication.
- T1535detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the T1535-created resources (or their downstream effects) when they meet those criteria, but the control stops at assessment/prioritization and does not itself perform monitoring, alerting, or discovery of events in unused regions.
- T1537detects — A.5.25 requires assessment of events against an agreed scheme that decides which become incidents; this surfaces and categorizes T1537 events that reach the PoC but does not instrument or guarantee detection of the stealthy internal/cloud-native transfers themselves.
- T1537responds — A.5.25's assessment/prioritization of events (including recorded decisions on whether they qualify as incidents) directly enables and is the first step of coordinated response once the exfiltration technique is underway, with the named remainder being full eradication/recovery actions that sit in separate controls.
- T1538detects — A.5.25 requires assessment of each security event against an agreed categorization scheme to decide if it qualifies as an incident; this can surface T1538 when the dashboard access is treated as a detectable event, but the control is silent on instrumentation, telemetry, or automated detection of the technique itself.
- T1539detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1539 when its indicators (e.g. anomalous cookie access, malicious JS injection, or proxy behavior) trigger the scheme, but the control stops at assessment/decision and does not mandate ongoing monitoring or instrumentation that would catch the technique in all its forms or platforms.
- T1539responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an event is underway, and directly matches the containment/eradication boundary in the event-lane anchors for responds (e.g., A.5.26 vs T1486).
- T1542.001detects — A.5.25 requires assessment of security events using an agreed scheme to categorize and prioritize them as incidents, which can surface firmware modification as an event if observed and reported, but the control itself performs no detection and depends on external observation of a low-visibility technique.
- T1542.002detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface firmware-modification incidents once reported, but does not itself instrument, monitor or discover the technique
- T1542.003detects — A.5.25's assessment scheme and point-of-contact evaluation of events can surface a suspected bootkit once an event reaches the incident pipeline (e.g., via anomalous boot behavior or remediation difficulty), but the control itself supplies no instrumentation, telemetry, or scanning to discover the low-level persistence before or during execution.
- T1542.003responds — A.5.25's assessment/prioritization scheme and recording directly enable the incident response team to decide and act on a suspected bootkit event once it is underway, which is the core of `responds`; the named remainder is that the control itself performs only the assessment step, not the full containment/eradication that follows from the decision.
- T1542.004detects — A.5.25 requires assessment of events against an agreed scheme to decide if they are security incidents (and to record the outcome), which can surface ROMMONkit activity if it triggers observable events meeting the criteria, but the technique's low observability and firmware/boot nature mean most instances go unseen.
- T1542.005detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; a TFTP-boot configuration change or unauthorized netboot is an observable event that can be assessed and recorded, but the control only surfaces the fact of the event and does not guarantee instrumentation or telemetry will make the netboot itself visible.
- T1543detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface T1543 as an incident (e.g., via anomalous service creation/modification), but the control itself performs only post-event assessment and recording rather than continuous or proactive detection of the technique.
- T1543.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface a persistence technique (e.g. anomalous LaunchAgent plist) as an incident, but the control is silent on instrumentation, collection or real-time detection mechanisms and only acts once an event is already known.
- T1543.002detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the T1543.002 technique once it has produced a detectable event (e.g. anomalous service creation/modification), but the control stops at assessment/prioritization/recording and does not mandate ongoing monitoring, specific detection mechanisms, or coverage of all possible technique manifestations.
- T1543.002responds — A.5.25 requires personnel to assess each security event using an agreed categorization/prioritization scheme (including criteria to declare it an incident) and record the decision; this directly enacts the `responds` verb once the persistence technique has produced a detectable event.
- T1543.003detects — A.5.25 requires assessment of security events against an agreed categorization/prioritization scheme to decide if they qualify as incidents; this surfaces knowledge of T1543.003 when the service creation/modification is observed and routed as an event, but the control stops at assessment/decision/recording and does not itself perform the detection instrumentation or monitoring that would surface the technique.
- T1543.003responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to record the decision; this is the core act of `responds` (containment/eradication once the technique is underway) for a persistence technique that surfaces as a detectable service modification or creation event.
- T1543.004detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the T1543.004 technique once it has produced observable artifacts (e.g. anomalous plist or daemon behavior) that reach the point of contact, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, instrumentation depth, or coverage of all possible macOS Launch Daemon artifacts.
- T1543.004responds — A.5.25 requires assessment, categorization, prioritization, and recorded decision on security events (including those from persistence techniques like T1543.004 once underway), which directly enacts the containment/eradication decision step of `responds` with only a bounded remainder for events that evade initial detection
- T1543.005detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface anomalous container-service creation/modification as an incident, but the control only acts after the event has already occurred and depends on an organization-specific scheme that may or may not include this technique.
- T1546detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1546 abuse when the triggered execution produces a detectable event matching the scheme, but the control stops at assessment/prioritization/recording and does not mandate instrumentation or monitoring to catch the events themselves.
- T1546responds — A.5.25 requires competent personnel to assess every security event against an agreed categorization/prioritization scheme and decide on it (including recording the outcome), which is the core of incident response once an event is underway; the T1546 technique (creating or abusing event triggers for persistence/escalation) is observable as a security event that would trigger this assessment/decision process, with the named remainder being events that evade initial detection or categorization.
- T1546.001detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of the T1546.001 persistence technique once it has produced observable consequences (e.g. anomalous file-type behavior), but the control stops at assessment/prioritization and does not mandate ongoing monitoring or instrumentation that would catch the registry change itself.
- T1546.002detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface a screensaver-based persistence technique once it has executed and is observable as an event, but the control stops at assessment/prioritization and does not mandate instrumentation or monitoring to generate the events in the first place.
- T1546.003detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents, which surfaces knowledge of the T1546.003 technique when it triggers a subscribed event that meets those criteria.
- T1546.003responds — A.5.25 requires assessment/prioritization of security events (including those from malicious WMI subscriptions) by the incident response team once they have occurred, which is the core act named by `responds`.
- T1546.004detects — A.5.25 requires assessing every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces T1546.004 when its indicators (e.g. anomalous shell config changes) trigger an event that meets the criteria, but the control stops at assessment/decision/recording and does not mandate instrumentation or collection that would surface the technique itself.
- T1546.005detects — A.5.25 requires assessment of security events against an agreed scheme to decide if they qualify as incidents, which can surface T1546.005 trap-based persistence when it triggers an observable interrupt or anomalous shell behavior that meets the criteria, but the control is silent on instrumentation, telemetry, or proactive detection of the registration itself.
- T1546.006detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface anomalous binary modifications as incidents, but the control itself performs only human-driven post-event triage and recording rather than any automated or continuous detection mechanism that would catch the technique in flight or at the point of binary tampering.
- T1546.007detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface and record a Netsh Helper DLL persistence technique as an incident once observed, but the control itself performs no detection and depends on external observation mechanisms.
- T1546.007responds — A.5.25 requires assessment/prioritization of security events (including those from persistence techniques like Netsh Helper DLL registration/execution) to decide on incident response, directly matching the `responds` verb once the event is underway.
- T1546.008detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether it qualifies as an information security incident; this surfaces knowledge of the T1546.008 technique when it produces observable events (e.g. anomalous process execution or login-screen behavior) that meet those criteria, but the control stops at assessment/decision/recording and does not mandate instrumentation that would reliably surface the technique itself.
- T1546.009detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface AppCert DLL abuse as an incident when observed, but the control itself performs no detection and stops at post-detection assessment/prioritization.
- T1546.009responds — A.5.25 requires competent personnel to assess every security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of `responds` once the technique is underway, with only the bounded remainder of events that evade initial detection falling outside.
- T1546.010detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface AppInit DLL abuse as an incident (e.g., via anomalous DLL loads or registry changes), but the control stops at assessment/prioritization and does not itself perform or mandate the monitoring that would generate the events to assess.
- T1546.011detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1546.011 when its artifacts or effects match those criteria, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, specific detection mechanisms, or coverage of all possible shim abuse indicators.
- T1546.012detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces and records IFEO-injection events when they match those criteria, but the control stops at assessment/prioritization and does not itself perform the monitoring or data collection that would surface the events.
- T1546.013detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the T1546.013 technique once it has produced observable malicious profile content or anomalous PowerShell execution, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring or instrumentation that would catch the modification or execution itself.
- T1546.014detects — A.5.25 requires assessment of every information security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as security incidents; emond-triggered rules (startup, auth, command execution) are observable events that would be assessed and potentially flagged as incidents once they occur.
- T1546.014responds — A.5.25's assessment/prioritization scheme and recorded decision directly feed the incident response workflow once an emond persistence event is surfaced, enabling containment/eradication of the rule and service abuse (with the bounded remainder being pre-compromise rule installation that has not yet triggered).
- T1546.015detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the COM hijacking (once it has produced observable Registry or execution artifacts) but only for the subset of events that reach the point-of-contact and match the scheme, leaving the stealthy or low-impact variants described in the technique outside that slice.
- T1546.015responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to record the decision; this directly enacts the `responds` verb once the persistence technique has produced a detectable event.
- T1546.016detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the T1546.016 technique when its indicators appear in an event, but the control stops at assessment/prioritization/recording and does not mandate ongoing monitoring, telemetry, or automated detection mechanisms.
- T1546.016responds — A.5.25 requires assessment of each security event against an agreed categorization/prioritization scheme (including criteria to declare it an incident) plus recording the decision; this directly enacts the `responds` verb once the installer technique has produced observable malicious content or persistence.
- T1546.017detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the udev-rule persistence technique when it triggers a detectable event, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, instrumentation, or coverage of all possible udev triggers.
- T1546.018detects — A.5.25 requires assessment of events using an agreed categorization scheme that can surface a Python startup-hook persistence artifact as an information security incident once it is observed (e.g., via log or monitoring data), but the control itself supplies no instrumentation, telemetry, or discovery mechanism and therefore only partially detects the technique.
- T1547.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface persistence activity (including anomalous registry/run-key changes) as an incident; this is genuine but only a slice because the control is post-event triage performed by the incident team and does not itself instrument or monitor for the technique.
- T1547.002detects — A.5.25 requires assessment of events against an agreed incident-categorization scheme and recording of decisions; this surfaces malicious LSA authentication-package autostart activity once it has produced a recognizable security event, but only for those events that reach the point-of-contact and match the scheme's criteria.
- T1547.003detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces the registration of a malicious time-provider DLL (a persistence technique) once it is observed as an event, but only for events that reach the point-of-contact and only if the scheme's criteria treat it as an incident.
- T1547.004detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the T1547.004 persistence technique once it has produced a detectable logon-related event, but the control stops at assessment/decision/recording and does not itself perform detection instrumentation or monitoring.
- T1547.005detects — A.5.25 requires assessment of events against an agreed scheme to decide if they are security incidents; this surfaces SSP abuse (a detectable boot-time or registry event) when observed, but the control is scoped only to post-event assessment rather than continuous monitoring or specific detection mechanisms for this technique.
- T1547.006detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface kernel-module activity as an incident (especially when it produces observable effects such as log tampering or anomalous boot behavior), but the control itself performs only human-driven post-event triage and does not mandate any instrumentation or monitoring that would actually observe the LKM/kext loading.
- T1547.007detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the T1547.007 persistence technique once it has produced a detectable event, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, telemetry, or specific detection mechanisms for plist modifications.
- T1547.008detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface LSASS-driver anomalies as incidents, but the control itself performs only human-driven triage after the event and does not mandate any specific detection instrumentation or telemetry that would surface the technique.
- T1547.009detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces T1547.009 when the shortcut modification produces observable consequences that match those criteria, but the control stops at assessment/decision/recording and does not itself perform detection instrumentation or monitoring.
- T1547.010detects — A.5.25 requires assessing events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces qualifying port-monitor persistence events once they are observed and reported, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1547.012detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface a print-processor abuse as an incident (once the boot-time DLL load or registry change is observed as an event), but the control itself performs no detection and stops at post-detection triage.
- T1547.013detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the T1547.013 persistence technique once it has produced an observable event at login, but the control stops at assessment/prioritization/recording and does not itself perform detection instrumentation or monitoring.
- T1547.014detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the T1547.014 persistence technique once it has produced a detectable login-triggered execution event, but the control stops at assessment/prioritization/recording and does not itself perform detection instrumentation or monitoring.
- T1547.014responds — A.5.25 requires assessment, categorization, prioritization, and recorded decision on security events (including those revealing persistence like T1547.014), which is the core of `responds` once the technique has run and an event is raised.
- T1547.015detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces malicious login-item additions when they are reported or observed as events, but the control itself performs no monitoring, telemetry collection, or proactive discovery of the technique.
- T1548.002detects — A.5.25 requires assessing every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of a UAC-bypass technique once it has produced observable evidence that meets the scheme's criteria, but the control stops at assessment/prioritization and does not mandate instrumentation that would catch the bypass itself.
- T1548.002responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (explicitly including criteria to declare it an incident) and to record the decision, which is the core of responding once the UAC-bypass technique has executed and produced a detectable event.
- T1548.003detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; sudo-caching or sudoers abuse that produces observable artifacts (e.g. unexpected sudo executions, file modifications to /etc/sudoers, or anomalous privilege-use logs) can be assessed and categorized as an incident, but the control is silent on instrumentation or collection that would surface the technique when no prior event is already known.
- T1548.004detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of the T1548.004 technique when it triggers an observable event, but the control stops at assessment/prioritization and does not mandate ongoing monitoring or detection instrumentation.
- T1548.005detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of T1548.005 when the abuse produces a detectable event, but the control stops at assessment/prioritization and does not mandate instrumentation that would reliably surface the technique itself.
- T1548.005responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including deciding whether it qualifies as an incident) and record the outcome; this is the core of incident response once an event is underway, though it stops short of containment/eradication actions named in other response controls.
- T1548.006detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that decides whether it qualifies as an incident; TCC manipulation is observable as a privilege-escalation or anomalous-permission event that would be assessed and potentially categorized, but the control stops at assessment/prioritization and does not itself instrument or surface the technique.
- T1550.001detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces some token-abuse events that produce observable anomalies fitting the scheme, but the technique's stealth (API use that mimics legitimate workflows, immunity to password changes, and provider-side detection difficulty) leaves most instances outside what the assessment will reliably flag.
- T1550.003detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of PtT (a lateral-movement technique that produces observable events such as anomalous Kerberos ticket use) once those events reach the point of contact, but the control stops at assessment/prioritization/recording and does not itself perform monitoring, alerting, or data collection.
- T1550.003responds — A.5.25 requires assessment, categorization, prioritization, and recorded decision on security events (including those from PtT lateral movement), which is the core of incident response once the technique is underway.
- T1550.004detects — A.5.25 requires assessment of security events against an agreed scheme to decide if they qualify as incidents; this surfaces knowledge of T1550.004 when the cookie theft or reuse produces an observable event that fits the criteria, but the control stops at assessment/prioritization and does not mandate ongoing monitoring or detection mechanisms.
- T1550.004responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including deciding whether it qualifies as an incident) and record the outcome; this is the core act of responding once an event (such as cookie theft or reuse) is underway, with the named remainder being full containment/eradication that lives in separate IR controls.
- T1552.001detects — A.5.25 requires assessment of events against an agreed scheme to decide if they qualify as incidents, which can surface T1552.001 when the search or credential exposure is observed as an event, but the control is silent on instrumentation, monitoring coverage, or proactive detection of the technique itself.
- T1552.003detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface command-history credential searches when they are reported or observed as events, but the control itself performs no monitoring, instrumentation or automated detection of the technique.
- T1552.004detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; discovering private-key material on a compromised system is an observable event that would be assessed and potentially escalated, but the control only acts after the search has already succeeded and does not mandate instrumentation that would surface the file-search activity itself.
- T1552.005detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of T1552.005 when the metadata-access event is observed and routed to the assessment process, but the control itself performs no monitoring or instrumentation and therefore only detects those events that other mechanisms have already surfaced.
- T1552.006detects — A.5.25 requires assessment of events against an agreed categorization scheme that can surface GPP credential exposure as an information security incident, but the control is silent on automated or continuous detection mechanisms and stops at human assessment of already-reported events.
- T1552.007detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1552.007 when it triggers detectable logging or API-access events, but the control stops at assessment/prioritization and does not mandate instrumentation or monitoring to catch the technique itself.
- T1552.008detects — A.5.25 requires assessment of events against an agreed scheme that decides which qualify as security incidents, which surfaces knowledge of credential-harvesting events once they are reported or observed as candidate events; this is genuine but only a slice because the control is silent on instrumentation, telemetry, or proactive discovery of the technique itself.
- T1553detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces and categorizes T1553 when it produces observable events, but many subversions (e.g., silent registry changes or stolen certificates) produce no detectable event until later misuse, so only a minority slice is reached.
- T1553.003detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether an event qualifies as an information security incident; this surfaces knowledge of the SIP/trust-provider tampering when the event is observed and routed to the assessment point, but the control stops at recording the decision and does not itself perform detection instrumentation or monitoring.
- T1553.004detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; an adversary's root-certificate installation (T1553.004) is observable as a security event on Linux/macOS/Windows and can be categorized when the scheme includes certificate or trust-store changes, but the control stops at assessment/prioritization and does not itself perform detection instrumentation.
- T1553.005detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether it qualifies as an information security incident; this surfaces and records knowledge of a MOTW-bypass attempt once it is reported as an event, but the control stops at assessment/prioritization and does not itself instrument or monitor for the technique.
- T1554detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to classify events as incidents; this surfaces knowledge of T1554 activity once it has produced a detectable event, but the control stops at assessment/prioritization/recording and does not mandate instrumentation, monitoring coverage, or detection mechanisms themselves.
- T1554responds — A.5.25 requires assessment/prioritization of security events (including those from binary compromise/persistence) by the incident response team once underway, enabling coordinated response.
- T1555detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface credential-access activity as an incident, but the control is silent on any instrumentation, monitoring or discovery mechanism that would actually generate the events for assessment.
- T1555.001detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether it qualifies as an information security incident; this surfaces knowledge of credential-acquisition activity from Keychain when the event is observed and routed to the assessment point, but only for events that reach that point and only to the extent the organization's scheme actually flags Keychain access as an incident indicator.
- T1555.002detects — A.5.25 requires assessment of each security event against an agreed categorization/prioritization scheme that explicitly includes criteria to identify events as information security incidents; this surfaces knowledge of the T1555.002 technique once it is observed as an event, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring or instrumentation that would catch the in-memory read itself.
- T1555.003detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1555.003 when it is recognized as an incident, but the control stops at assessment/prioritization and does not mandate ongoing monitoring or detection mechanisms.
- T1555.004detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether it qualifies as an information security incident; this surfaces knowledge of T1555.004 when the technique produces observable events that match those criteria, but the control stops at assessment/prioritization and does not mandate instrumentation or monitoring that would reliably surface the technique itself.
- T1555.005detects — A.5.25 requires assessment of security events against an agreed categorization/prioritization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1555.005 when it triggers observable events meeting those criteria, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, instrumentation, or detection mechanisms.
- T1555.006detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether it qualifies as an information security incident; this surfaces knowledge of T1555.006 when the event is observed and meets the criteria, but the control stops at assessment/decision/recording and does not itself perform detection instrumentation or monitoring.
- T1555.006responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once an event is underway, and directly applies to T1555.006 events (credential theft from a secrets manager).
- T1556detects — A.5.25 requires assessment of events against an agreed scheme to decide if they qualify as security incidents, which can surface T1556 once it has produced observable authentication anomalies or related events, but the control stops at categorization/prioritization and does not mandate instrumentation or monitoring to catch the modification itself.
- T1556.001detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as security incidents; this surfaces knowledge of the T1556.001 technique once it has produced observable indicators (e.g., anomalous LSASS behavior or authentication anomalies), but the control itself performs no monitoring or instrumentation and therefore only detects the subset of events that reach the point-of-contact assessor.
- T1556.002detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; a malicious password-filter DLL registering itself or subsequently receiving plaintext credentials is an observable event that can be categorized and escalated as an incident, but the control stops at assessment/decision/recording and does not itself perform detection instrumentation.
- T1556.003detects — A.5.25 requires assessment of events against an agreed scheme that decides which become incidents; this surfaces some malicious PAM modifications once they trigger observable events, but the control is silent on instrumentation, telemetry or detection mechanisms for the technique itself.
- T1556.003responds — A.5.25 requires assessment/prioritization of security events (including those from PAM modifications) by the incident response team once they are identified, which is the core of `responds` (containment/eradication once underway); mostly because it stops at assessment/decision/recording without mandating full eradication steps.
- T1556.005detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; an adversary enabling reversible encryption (or the observable effects of that change) can be assessed and categorized as a security event/incident, but this is governance-level detection after the fact and does not instrument or surface the technique itself.
- T1556.006detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1556.006 when it is recognized as an incident but does not mandate instrumentation or monitoring that would catch the technique in all cases or environments.
- T1556.007detects — A.5.25 requires assessment of each security event against an agreed categorization/prioritization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the T1556.007 technique once it has produced observable events (e.g. anomalous auth or backdoor activity), but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, instrumentation, or detection mechanisms that would catch the backdooring itself.
- T1556.008detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that decides whether it qualifies as an incident; this surfaces knowledge of the T1556.008 technique when the associated logon or credential-capture event is observed and assessed, but the control stops at assessment/decision and does not itself perform detection instrumentation.
- T1556.008responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide/record the outcome; this directly enacts the containment/eradication decision once the T1556.008 technique has run and produced observable logon-related events, with the named remainder being post-decision eradication actions that live in a separate clause.
- T1556.009detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that explicitly includes criteria to identify events as security incidents; this surfaces knowledge of conditional-access tampering when the event meets those criteria, but the control stops at assessment/prioritization/recording and does not mandate instrumentation, telemetry, or automated detection mechanisms that would catch the technique in flight or at scale.
- T1557detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of AiTM positioning (and many of its follow-on behaviors) once the event is observed and routed to the point of contact, but the control itself performs no monitoring, instrumentation, or discovery and stops at human assessment of already-reported events.
- T1557responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to record the decision; this directly enacts the `responds` verb once an AiTM technique is detected as an event underway, with the named remainder that the control stops at assessment/decision and does not itself perform containment or eradication.
- T1557.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces name-resolution poisoning/relay activity when observed and routed to the point of contact, but only for events that reach the assessment stage and match the scheme's criteria.
- T1557.002detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface ARP poisoning as an incident (e.g., via anomalous traffic or MITM indicators), but the control itself performs only post-event assessment/prioritization rather than continuous or proactive detection.
- T1557.002responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an ARP-poisoning event is underway, with only the bounded remainder of fully automated or pre-assessment containment outside its scope.
- T1557.003detects — A.5.25 requires assessment of security events against an agreed categorization/prioritization scheme that explicitly includes criteria to identify which events qualify as information security incidents; rogue DHCP server traffic or anomalous DHCP responses are observable network events that can be assessed this way, but the control stops at assessment/decision/recording and does not itself perform detection instrumentation or monitoring.
- T1557.003responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to record the decision; this directly enacts the `responds` act of handling an in-flight technique once detected, with the named remainder being post-assessment containment/eradication steps that live in A.5.26.
- T1557.004detects — A.5.25 requires assessment of every information security event against an agreed categorization scheme that explicitly includes criteria to decide whether it qualifies as an information security incident; an evil-twin Wi-Fi event is observable (rogue AP, anomalous SSID/signal, probe-response behavior) and would be assessed and recorded once it reaches the point-of-contact, but the control itself supplies no instrumentation, monitoring, or discovery mechanism and therefore only performs the detection verb on events already surfaced by other means.
- T1557.004responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to record the decision; this directly enacts the `responds` verb once an evil-twin event is underway, with the bounded remainder being the post-assessment containment/eradication steps that live in A.5.26.
- T1558detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface a Kerberos-ticket theft as an incident, but the control itself performs only human assessment after the fact and does not mandate any instrumentation or automated detection capability.
- T1558responds — A.5.25 requires assessment/prioritization of security events (including those matching T1558) by the incident response team once underway, enabling a decision on whether and how to respond, which is the core of the `responds` verb.
- T1558.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the golden-ticket technique once it has produced observable events, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, telemetry collection, or specific detection mechanisms for the technique itself.
- T1558.001responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once an event is underway, and golden-ticket use (forged TGTs enabling domain-wide access) is a detectable information-security event that would trigger exactly this assessment/decision process.
- T1558.002detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as security incidents, which can surface silver-ticket activity once it is observed and reported as an event; this is genuine but only a minority slice because the control itself performs no monitoring, instrumentation, or proactive discovery of the technique.
- T1558.002responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (explicitly including criteria to declare it an incident) and to record the decision, which is the core of incident response once an event is underway; the silver-ticket technique produces detectable events (forged TGS without KDC interaction) that this assessment directly acts on, with only a bounded remainder for events that evade initial detection.
- T1558.003detects — A.5.25 requires assessment of security events against an agreed categorization/prioritization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces and records knowledge of Kerberoasting activity (a detectable network or DC request pattern) once observed, but the control stops at assessment/decision and does not mandate instrumentation, monitoring coverage, or specific detection of the TGS-request or offline-crack technique itself.
- T1558.004detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of AS-REP Roasting activity (e.g. anomalous AS-REQ/AS-REP traffic or pre-auth-disabled account enumeration) once it has occurred, but only for events that fall inside the scheme's chosen criteria and scope.
- T1558.005detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of T1558.005 when the ccache theft is noticed and routed for assessment, but the control stops at assessment/prioritization and does not itself perform the detection that produces the event.
- T1559detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of T1559 abuse when the IPC technique produces observable events that match the scheme, but the control is silent on instrumentation, telemetry generation, or coverage of the many platform-specific IPC surfaces, leaving most executions undetected.
- T1559.001detects — A.5.25 requires assessment of events against an incident categorization scheme and recording of decisions, which can surface COM-based code execution if it triggers an observable event meeting the criteria, but the control is silent on instrumentation, telemetry, or detection mechanisms and only acts once an event is already reported.
- T1559.001responds — A.5.25 requires assessment/prioritization of security events (including those from COM abuse) by the incident response team and recording of decisions, which is the core of `responds` once the technique is underway; the named remainder is that it stops short of containment/eradication actions themselves.
- T1559.002detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents; this surfaces knowledge of T1559.002 when the DDE-based execution is observed and categorized, but the control stops at assessment/prioritization and does not itself perform monitoring or instrumentation.
- T1559.002responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to record the decision; this is the core of incident response once the DDE-based technique is underway, with the named remainder being full containment/eradication actions that live in A.5.26.
- T1559.003detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that explicitly includes criteria to identify events as information security incidents; this surfaces knowledge of T1559.003 abuse when it triggers an observable event, but the control stops at assessment/prioritization/recording and does not mandate ongoing monitoring or instrumentation that would catch the technique in flight.
- T1560detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces T1560 when the compression/encryption artifact is observed as part of an already-collected-data event, but the control stops at categorization/prioritization and does not itself instrument or monitor for the technique.
- T1560.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface and record an archiving utility as an incident indicator, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1560.003detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface custom archival as an incident indicator (especially when recorded in logs or monitoring data), but the control itself performs no detection and stops at human assessment of already-reported events.
- T1561detects — A.5.25 requires assessment of security events against an agreed scheme to decide if they qualify as incidents (and to prioritize them); this surfaces knowledge of a disk-wipe event once it is observed and reported as an event, but the control itself performs no detection or instrumentation and stops at the assessment step.
- T1561responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including explicit criteria for declaring an incident) and to decide on and record the outcome; this is the core of incident response once the disk-wipe technique is underway, with only the post-decision containment/eradication steps lying outside this control.
- T1561.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1561.001 (a destructive availability event) once observed, but the control stops at assessment/prioritization/recording and does not mandate ongoing monitoring, instrumentation, or detection mechanisms.
- T1561.001responds — A.5.25 requires assessment/prioritization of security events (including destructive incidents like disk wipes) by the incident response team once they occur, which directly enacts the `responds` verb of containment/eradication once underway.
- T1561.002detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of T1561.002 when the wipe is observed and reported as an event, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1561.002responds — A.5.25 requires assessment/prioritization of security events (including destructive incidents like disk-structure wipe) by the incident-response team once they are reported, which is the core act named by `responds`.
- T1563detects — A.5.25 requires assessment of security events against an agreed scheme that decides whether they qualify as incidents; this surfaces knowledge of a hijacking when it is reported or observed as an event, but the control itself performs no monitoring, instrumentation or automated detection and the scheme's criteria are left entirely to the implementer.
- T1563responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding to an in-flight T1563 hijacking once detected, with the named remainder being full eradication and recovery steps that live in separate clauses.
- T1563.001detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents, which can surface SSH hijacking once it is observed and reported as an event, but the control itself performs no monitoring, instrumentation or discovery and therefore only reaches the subset of events that are already handed to personnel for triage.
- T1563.001responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once an event is underway, and SSH session hijacking (a detectable lateral-movement technique) is a clear information-security event that would trigger exactly this assessment/decision workflow.
- T1563.002detects — A.5.25 requires assessment of events against an agreed scheme to decide if they qualify as security incidents, which can surface RDP hijacking when observed and categorized, but the control itself performs no monitoring, instrumentation or detection and depends entirely on events already being handed to it.
- T1563.002responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an RDP hijacking event is underway, with the named remainder being full containment/eradication actions that live in A.5.26.
- T1564.002detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to decide whether an event qualifies as an information security incident; this surfaces knowledge of hidden-user creation/modification when the event reaches the point-of-contact, but the control stops at assessment/prioritization/recording and does not itself instrument or observe the technique.
- T1564.006detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces and records knowledge of T1564.006 when its artifacts or behaviors are observed and match the scheme, but the control itself performs no monitoring, instrumentation or discovery and therefore only grades the assessment slice of detection.
- T1564.007detects — A.5.25 requires assessment of events using an agreed categorization scheme that can surface anomalous VBA-stomped documents as security incidents once observed, but the control itself supplies no instrumentation, scanning, or detection mechanism and stops at human assessment of already-reported events.
- T1564.008detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as incidents; this surfaces the abuse of email-hiding rules when the rule itself (or its effects) is reported as an event, but the control stops at assessment/prioritization and does not mandate ongoing monitoring or detection mechanisms that would catch the rule creation or hidden-mail condition in the first place.
- T1564.008responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to record the decision; this directly matches the responding act of triaging and deciding on alerts that the T1564.008 technique is designed to suppress or delay.
- T1564.009detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1564.009 when its indicators (e.g., anomalous resource-fork usage on macOS) are presented as an event, but the control stops at assessment/prioritization and does not itself perform detection collection or monitoring.
- T1564.010detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as security incidents, which can surface T1564.010 when the PEB-spoofing produces observable anomalies or is combined with other detectable activity, but the control stops at categorization/prioritization and does not itself instrument or monitor for the in-memory overwrite technique.
- T1564.011detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of T1564.011 when the nohup/silentlyContinue behavior is observed as part of an event, but the control stops at categorization/prioritization and does not mandate instrumentation that would reliably surface the technique itself.
- T1564.012detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces and categorizes the use of an exclusion when the dropped artifact itself triggers a detectable event, but many placements produce no observable event at all and the control stops at assessment without mandating ongoing detection mechanisms.
- T1564.014detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the xattr technique when the event is observed and meets the criteria, but the control stops at assessment/decision/recording and supplies no instrumentation, monitoring or detection mechanism itself.
- T1565detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces and records data-manipulation events that meet those criteria, but the control stops at assessment/prioritization and does not itself instrument or monitor to discover the events.
- T1565responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once an event is underway, directly addressing T1565 data-manipulation events that threaten integrity and affect decisions.
- T1565.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1565.001 when its data-manipulation artifacts are recognized as an incident, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, telemetry, or automated detection mechanisms that would catch the technique in flight or at rest.
- T1565.001responds — A.5.25 requires assessment/prioritization of security events (including those from stored data manipulation) by the incident response team once the event is underway, which is exactly what `responds` names; the remainder is that it stops short of full containment/eradication addressed in paired IR controls.
- T1565.002detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1565.002 when its data-manipulation artifacts match those criteria, but the control stops at assessment/decision/recording and does not itself perform detection instrumentation or monitoring.
- T1565.002responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding once the T1565.002 technique has produced observable transmitted-data manipulation.
- T1565.003detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; runtime data manipulation (T1565.003) is an integrity-threatening technique that would qualify under such criteria when observed, but the control stops at assessment/decision/recording and does not itself perform detection or monitoring.
- T1566detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of a phishing event once reported or observed, but the control itself performs no monitoring, alerting or discovery and therefore reaches only the subset of events that have already been handed to the incident team.
- T1566responds — A.5.25 requires assessment/prioritization of events using an agreed scheme and recording results to drive coordinated response, which directly enacts the `responds` verb once a phishing event is underway; the named remainder is that it stops at decision-making and does not itself perform containment/eradication.
- T1566.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces and records knowledge of T1566.001 events once they have reached the point-of-contact, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1566.001responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding once the spearphishing event is underway, with the named remainder being full incident handling/containment/eradication addressed by A.5.26.
- T1566.002detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of a spearphishing-link event once reported, but the control is silent on instrumentation, collection or automated discovery of the emails/links themselves.
- T1566.002responds — A.5.25 requires assessment/prioritization of events (including those from spearphishing links) by the incident response team to decide on handling, which directly enacts the `responds` verb once the technique is underway; the named remainder is that it stops at categorization/decision rather than performing full containment/eradication.
- T1566.003detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces and records spearphishing-via-service events once they reach the PoC, but only for those that meet the scheme's criteria and only after delivery/arrival.
- T1566.003responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on them; this is the core of incident response once the spearphishing event is underway, with recording for verification.
- T1566.004detects — A.5.25 requires assessment of events against an agreed scheme that decides which ones become incidents; this surfaces knowledge of a vishing event once reported but does not instrument or observe the technique itself, leaving the dominant pre-reporting slice (e.g. the phone call and any resulting execution) unreached.
- T1566.004responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once the vishing technique has begun (assess, categorize, prioritize, decide), with the named remainder being full containment/eradication actions that live in A.5.26.
- T1567detects — A.5.25 requires assessment of events against an agreed categorization scheme that can surface exfiltration-over-web-service as an information security incident, but the control itself performs only human assessment after the fact and does not mandate any instrumentation or detection mechanism that would surface the technique while it is occurring.
- T1567responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding once an exfiltration-over-web-service event is underway, with the named remainder being full incident containment/eradication that lives in A.5.26.
- T1567.001detects — A.5.25 requires assessment of events against an agreed incident-categorization scheme that explicitly includes criteria to classify events as information security incidents; this surfaces and records knowledge of the T1567.001 exfiltration event once it is observed, satisfying `detects` for the subset of events that reach the point-of-contact assessment step, but the control itself supplies no instrumentation, telemetry, or monitoring that would surface the technique in the first place.
- T1567.001responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding once the exfiltration technique is underway, with the named remainder being full incident containment/eradication that lives in A.5.26.
- T1567.002detects — A.5.25 requires assessment of events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the exfiltration technique when it triggers those criteria, satisfying `detects` for a scoped slice of observable events rather than all instances.
- T1567.002responds — A.5.25 requires assessment/prioritization of security events (including exfiltration) by the incident response team once they are identified, which directly enacts the `responds` verb of containment/eradication once the technique is underway.
- T1567.003detects — A.5.25 requires assessment of events against an agreed incident categorization scheme and recording of decisions; this surfaces some exfiltration-to-text-storage events once they are flagged as potential incidents, but the control itself supplies no instrumentation, telemetry, or detection mechanism and depends on other controls to first generate the events it assesses.
- T1567.003responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once an exfiltration technique is underway, with the named remainder being full containment/eradication that lives in A.5.26.
- T1567.004detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1567.004 when the webhook exfiltration produces observable events that match those criteria, but the control stops at assessment/prioritization/recording and does not mandate instrumentation, monitoring coverage, or detection of the technique itself.
- T1567.004responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to record the decision, which is exactly the initial assessment step that launches incident response once an exfiltration technique like T1567.004 is underway.
- T1568detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents, which can surface dynamic-resolution C2 behavior once observed as an anomalous event, but the control itself performs no monitoring, instrumentation or detection and stops at human assessment of already-reported events.
- T1568.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface Fast Flux DNS as an incident indicator when observed, but the control itself performs no monitoring, detection instrumentation or automated discovery of the technique.
- T1568.002detects — A.5.25 requires assessment of events against an agreed incident categorization scheme that explicitly includes criteria to classify events as information security incidents; this surfaces knowledge of DGA-driven C2 events once observed, but the control itself performs no detection instrumentation or discovery and stops at human assessment of already-reported events.
- T1568.003detects — A.5.25's assessment of events using an agreed categorization scheme (including criteria to identify security incidents) can surface DNS-calculation C2 as an anomalous event once observed, but the control is silent on any instrumentation, telemetry, or monitoring that would actually make the technique observable.
- T1569detects — A.5.25 requires assessment of events against an incident categorization scheme, which can surface T1569 abuse when it manifests as a recognizable security event, but the control is governance-oriented, depends on upstream detection to feed it events, and does not itself instrument or monitor for the technique.
- T1569responds — A.5.25 requires assessment/prioritization of security events (including those from T1569 abuse of services) by the incident response team once the event is underway, which is exactly what `responds` names.
- T1569.001detects — A.5.25 requires assessment of events against an agreed scheme to decide if they qualify as security incidents, which can surface T1569.001 abuse when it triggers the scheme's criteria, but the control itself performs no monitoring, instrumentation or detection and depends entirely on upstream event sources.
- T1569.001responds — A.5.25 requires assessment/prioritization of events (including those matching T1569.001 execution) to decide on incident response, directly enabling the containment/eradication act that `responds` names once the technique is underway.
- T1569.002detects — A.5.25 requires assessment of events against an incident categorization scheme and recording of decisions, which can surface T1569.002 once it has produced observable security events, but the control itself performs no monitoring, detection tooling, or proactive identification and stops at human assessment of already-reported events.
- T1569.002responds — A.5.25 requires assessment/prioritization of security events (including those from service execution) by the incident response team and recording of decisions, which directly enacts the containment/eradication decision step once the technique is underway.
- T1569.003detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of the T1569.003 technique when it triggers a logged or reported event, but the control itself performs no monitoring, instrumentation or detection and therefore only reaches the subset of technique executions that are already handed to it as events.
- T1569.003responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an abuse-of-systemctl event is underway.
- T1570detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface lateral tool transfer as an incident when observed, but the control itself performs no monitoring or detection and depends on events already being handed to it.
- T1570responds — A.5.25 requires assessment/prioritization of security events (including those involving lateral tool transfer) by the incident response team once underway, enabling a decision on whether and how to respond, with recording for verification.
- T1571detects — A.5.25 requires assessment of events against an agreed categorization scheme that can surface non-standard port usage as an information security incident, but the control itself performs only human assessment after the fact and does not mandate any detection mechanism or instrumentation.
- T1571responds — A.5.25's assessment/prioritization of events (including recording for response coordination) directly enacts the `responds` verb once T1571 is detected as an underway security event, with the named remainder being full incident eradication steps that live in A.5.26.
- T1572detects — A.5.25 requires assessment of security events against an agreed categorization/prioritization scheme that explicitly includes criteria to identify events as incidents; this surfaces knowledge of tunneling when observed events match those criteria, but the control itself performs no monitoring, detection engineering, or instrumentation and therefore only reaches the subset of tunneling events that have already been flagged by other means.
- T1573detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as information security incidents; this surfaces knowledge of T1573 once observed as an event, but the control itself performs no detection and only acts on events already handed to it.
- T1574.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface DLL-abuse incidents once reported, but the control itself performs no monitoring, instrumentation or discovery and therefore only grades the assessment slice of detection.
- T1574.004detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface dylib-hijacking artifacts (e.g., anomalous library loads or unexpected process behavior) once they occur, but the control itself performs only human-driven triage after the fact and does not mandate any specific detection instrumentation or automated discovery mechanism.
- T1574.004responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to record the decision; this is the core of incident response once the hijacking event is underway, with only the bounded remainder of non-incident-classified events left unaddressed.
- T1574.005detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface installer-permission anomalies as incidents, but only once they have already been observed or reported; it does not itself instrument or discover the underlying permission weakness or technique execution.
- T1574.006detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces and records knowledge of T1574.006 when it triggers observable consequences matching those criteria, but the control stops at assessment/prioritization and does not itself perform monitoring or detection instrumentation.
- T1574.007detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1574.007 when it is observed and meets the criteria, but the control stops at assessment/prioritization/recording and does not mandate ongoing monitoring, instrumentation, or telemetry that would surface the technique in flight.
- T1574.008detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface search-order hijacking as an incident, but the control stops at event triage and does not itself perform detection instrumentation or monitoring.
- T1574.009detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface path interception when it is recognized and reported as an event, but the control itself performs no monitoring, instrumentation or automated detection of the technique.
- T1574.010detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1574.010 when its artifacts (e.g., anomalous service binary replacement) are reported as an event, but the control stops at assessment/prioritization and does not itself perform monitoring, logging, or discovery of the technique.
- T1574.011detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface Registry-permission anomalies as incidents, but the control itself only records decisions after the fact and does not mandate instrumentation or monitoring that would actively detect the technique.
- T1574.012detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the COR_PROFILER abuse when it is observed and meets those criteria, but the control stops at assessment/decision/recording and does not mandate instrumentation, telemetry, or monitoring that would surface the technique itself.
- T1574.013detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to classify events as incidents; this surfaces knowledge of the T1574.013 technique once it has produced observable evidence that meets those criteria, satisfying `detects` for the subset of executions that trigger the scheme, but the control itself performs no monitoring, instrumentation or anomaly detection and therefore cannot surface the stealthy or masked cases the technique is designed to evade.
- T1574.014detects — A.5.25 requires assessment of events using an agreed scheme to categorize them as incidents (with recording), which can surface AppDomainManager injection as an information security event once observed, but the control itself supplies no instrumentation, telemetry, or detection mechanism and depends entirely on whatever upstream observation feeds it.
- T1578detects — A.5.25 requires assessment of each security event against an agreed categorization scheme to decide if it qualifies as an incident; this surfaces knowledge of T1578 when the modification is treated as an event, but the control stops at assessment/prioritization and does not mandate ongoing monitoring or detection mechanisms.
- T1578responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an event is underway, directly addressing T1578 modifications that are already occurring to evade defenses or remove evidence.
- T1578.001detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the T1578.001 snapshot-creation event when it meets those criteria, but the control stops at assessment/decision/recording and does not mandate ongoing monitoring, telemetry, or automated detection mechanisms.
- T1578.002detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of the T1578.002 technique when it is observed and routed as an event, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or collection.
- T1578.002responds — A.5.25 requires assessment/prioritization of security events (including this technique once detected) plus recording for response coordination, which directly enacts the `responds` verb once the event is underway.
- T1578.003detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents, directly enabling detection of the T1578.003 technique when it surfaces as an observable event.
- T1578.003responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an event is underway, directly addressing the deletion technique in flight or immediately after to contain/eradicate and decide next actions.
- T1578.004detects — A.5.25 requires assessment of events against an agreed scheme to decide if they qualify as incidents (and to record that), which surfaces knowledge of the revert activity when it is observed and fed in as an event; this is genuine but bounded by the scheme's criteria, event visibility, and the fact that successful reversion often erases the very artifacts that would trigger assessment.
- T1578.004responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once an event is underway, directly addressing T1578.004's post-activity reversion that attempts to erase evidence.
- T1578.005detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that decides whether it qualifies as an incident; this surfaces knowledge of the T1578.005 modification when it is reported or observed as an event, but the control stops at assessment/prioritization and does not itself instrument or monitor for the technique.
- T1595detects — A.5.25 requires assessment of security events against an agreed scheme that decides whether they qualify as incidents; active scanning (T1595) can be observed as anomalous network traffic and assessed as a security event, but the control only surfaces this after the fact for a chosen subset of events and does not mandate instrumentation to catch reconnaissance itself.
- T1595.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface scanning activity as an information security event (especially when it reveals reconnaissance intent), but the control is scoped to post-event assessment rather than proactive or real-time detection of the technique itself.
- T1595.002detects — A.5.25 requires assessment of security events against an agreed scheme that decides whether they qualify as incidents; this can surface vulnerability scanning when the scan is treated as a detectable event (e.g., anomalous network traffic), but the control is silent on proactive detection mechanisms and most pre-compromise reconnaissance occurs outside monitored incident-response scopes.
- T1595.003detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface reconnaissance activity like wordlist scanning as an information security event, but the control is silent on instrumentation, monitoring coverage, or detection mechanisms and only acts once an event reaches the point of contact.
- T1598.002detects — A.5.25 requires assessing every security event against an agreed scheme that decides whether it qualifies as an information security incident; this surfaces knowledge of a spearphishing event once reported or observed, but the control is silent on instrumentation, monitoring, or proactive discovery of the technique itself.
- T1598.003detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces spearphishing-link events when they are reported or observed, but the control is silent on proactive collection mechanisms that would catch the technique before or without human reporting.
- T1598.003responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to record the decision; this directly enacts the `responds` verb of containment/eradication once the spearphishing event is underway, with the named remainder being events that evade initial detection entirely.
- T1598.004detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; vishing events are observable human-reported or log-detectable events that can be assessed this way, but the control only surfaces them after they have already reached the victim and does not instrument or guarantee detection of the technique itself.
- T1599detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; a boundary-bridging compromise of a network device is observable as an anomalous event (unauthorized config change, unexpected traffic, etc.) that the point-of-contact would assess, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1599.001detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of the NAT-traversal technique once it has produced observable events, but only for those that meet the scheme's criteria and only after they have already occurred.
- T1601.001detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of the T1601.001 technique when it produces observable indicators that reach the point of contact, but the control stops at assessment/prioritization and does not mandate instrumentation, monitoring coverage, or detection of stealthy in-memory patches that leave no event.
- T1601.002detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; an observed downgrade of a network-device image (or its enabling artifacts) can be categorized and prioritized as a security event, but the control itself supplies only the assessment process and does not mandate instrumentation that surfaces the downgrade in the first place.
- T1602detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface configuration-repository exfiltration as an information security incident, but the control stops at assessment/prioritization and does not itself perform detection or monitoring.
- T1602.001detects — A.5.25 requires assessment of events using an agreed scheme that decides whether they qualify as incidents; this surfaces knowledge of the SNMP MIB dump when it is recognized as an event, but the control's mechanism is human assessment of already-reported events rather than instrumentation that would catch the technique in flight across the broad network-device surface.
- T1602.002detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface a configuration-dump event as an information security incident, but only once the event has already been identified and reported to the point of contact; it does not itself provide detection mechanisms.
- T1606detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface forged-credential activity as an incident (once observed), but the control itself performs no detection and stops at post-detection triage
- T1606.001detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; forged-cookie activity that produces observable artifacts (e.g. anomalous auth, unusual SaaS access) can therefore be surfaced and categorized, but the control stops at assessment/prioritization and does not itself instrument or guarantee detection of the technique.
- T1606.002detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of forged-SAML activity when it is reported or observed as an event, but the control stops at assessment/prioritization/recording and does not itself instrument or monitor for the technique.
- T1606.002responds — A.5.25 requires competent personnel to assess every security event against an agreed categorization/prioritization scheme (explicitly including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an event is underway, and the SAML-token-forgery technique is an observable information-security event that would trigger exactly this assessment/decision step.
- T1609detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface container admin command abuse as an incident, but the control itself performs only human-driven post-event triage and recording rather than any automated or continuous detection mechanism.
- T1610detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; container deployment is observable as a system change or anomalous workload and can therefore be assessed, but the control only surfaces the subset judged to be security-relevant and does nothing for stealthy or policy-compliant-looking deployments.
- T1611detects — A.5.25 requires assessment of security events against an agreed categorization/prioritization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1611 when it is recognized as such an event, but the control stops at assessment/decision/recording and does not itself perform detection or monitoring.
- T1612detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1612 activity when the build request or resulting image is treated as an event, but the control stops at assessment/prioritization/recording and does not itself perform detection instrumentation or monitoring.
- T1613detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface anomalous container-discovery activity as an incident, but the control is silent on instrumentation, monitoring coverage, or automated detection and only addresses post-event human assessment.
- T1615detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface anomalous Group Policy discovery activity as an incident, but only once the technique has already produced observable artifacts and only for events routed to the assessment point.
- T1620detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface reflective loading as an incident (especially when it produces observable anomalies), but the control itself performs only human-driven post-event triage and recording rather than any automated or continuous detection mechanism.
- T1621detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces and records MFA-fatigue or push-bombardment attempts once they are observed as events, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1621responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of responding to an MFA-fatigue or push-bombardment event once it is underway, with a named remainder that the control stops at assessment/decision and does not itself perform containment or eradication.
- T1649detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an information security incident; this surfaces knowledge of T1649 when the theft/forgery produces observable events that match the scheme, but many stealthy certificate abuses (e.g. golden-ticket-style forgeries or direct store access) produce no detectable event at all.
- T1649responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to record the decision; this is the core of incident response once an event is underway, and T1649's certificate theft/forgery is a detectable event that would trigger exactly this assessment and decision process.
- T1651detects — A.5.25 requires assessment of events against an agreed scheme to decide if they qualify as security incidents, which can surface T1651 abuse when it produces observable events that match the criteria, but the control stops at assessment/prioritization and does not mandate ongoing monitoring, telemetry collection, or specific detection mechanisms for cloud admin command execution.
- T1653detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface anomalous power-setting changes or shutdown-file deletions as incidents, but the control stops at assessment/prioritization and does not itself perform detection instrumentation or monitoring.
- T1654detects — A.5.25 requires assessment of security events (including those that surface log-enumeration activity) using an agreed scheme to decide if they qualify as incidents, which directly supplies detection of the technique when it produces observable events.
- T1654responds — A.5.25 requires assessment/prioritization of security events (including real-time log monitoring by defenders that can reveal the T1654 technique in flight) plus recording results to drive coordinated incident response, which matches the `responds` verb once the technique is underway.
- T1657detects — A.5.25 requires assessment of every security event against an agreed scheme to decide if it qualifies as (and how to prioritize) an information security incident; this surfaces knowledge that a financial-theft technique has produced an incident but only for events already routed to the point of contact, leaving the initial event detection outside its scope.
- T1657responds — A.5.25 requires assessment/prioritization of security events (including those involving financial theft via ransomware, BEC, etc.) to decide on and coordinate incident response, directly matching the `responds` verb once the technique is underway.
- T1659detects — A.5.25 requires assessment of security events against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of T1659 activity when observed events match those criteria, but the control stops at assessment/decision/recording and does not itself perform detection or monitoring.
- T1659responds — A.5.25 requires personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to record the decision; this is the core act of responding to an in-flight technique once it has produced observable events.
- T1665detects — A.5.25 requires assessment of events against an agreed scheme that decides which ones become incidents; this surfaces some T1665 activity once observed (e.g., anomalous traffic patterns or filtering attempts that reach the point of contact), but the control stops at categorization/prioritization and does not itself perform detection, nor reach the bulk of stealthy pre-incident hiding techniques that never trigger an observable event.
- T1665responds — A.5.25's assessment/prioritization of events (including those revealing hidden C2 via traffic anomalies or responder probes) directly enables the incident response act once the technique is detected and underway, with the named remainder being pre-assessment containment steps outside this clause.
- T1666detects — A.5.25 requires assessment of every security event against an agreed categorization/prioritization scheme that explicitly includes criteria to classify events as incidents; this surfaces and records the T1666 hierarchy-modification technique when it is observed and reported as an event, but the control itself performs no monitoring, logging, or discovery and therefore only detects the subset of cases that reach the assessment stage.
- T1667detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces and records email-bombing events that meet those criteria (e.g., as disruptive or harassing), but the control is silent on automated detection mechanisms and only acts once an event has already been noticed and handed off for assessment.
- T1667responds — A.5.25 requires assessment/prioritization of security events (including the flooding/disruption from T1667) to decide on incident response, directly matching the `responds` verb once the technique is underway.
- T1669detects — A.5.25 requires assessment of events against an agreed scheme to decide if they qualify as security incidents, which would surface a realized Wi-Fi connection attempt (especially anomalous ones) as part of incident handling; it does not instrument or monitor for the technique itself.
- T1671detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces malicious OAuth integrations when they produce observable events meeting those criteria, but the control stops at assessment/prioritization/recording and does not mandate instrumentation, telemetry, or coverage of the silent creation/consent steps that realize T1671.
- T1673detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface anomalous VM enumeration as an incident, but the control is scoped only to events already presented to the point of contact and does not itself instrument or monitor for the technique.
- T1677detects — A.5.25 requires assessing every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces knowledge of a pipeline-poisoning event once it has been raised as an event, but the control stops at assessment/prioritization/recording and supplies no instrumentation, monitoring, or discovery mechanism to generate the initial event from T1677 activity.
- T1679detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify incidents; this surfaces and records selective-exclusion behavior when it is observed as part of a ransomware or payload event, but only after the technique has already executed and only for events routed to the assessment point.
- T1684detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as information security incidents; this surfaces and records social-engineering events once reported, but only within the bounded slice of events that reach the point of contact (most social engineering succeeds without ever generating a detectable event).
- T1684.001detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces impersonation attempts once reported as an event but does not instrument or observe the technique itself.
- T1684.001responds — A.5.25 requires assessment/prioritization of security events (including social-engineering impersonation campaigns once detected) to drive coordinated response, directly matching the `responds` verb of containing/eradication once underway; mostly because it stops at assessment/decision and does not itself perform containment.
- T1684.002detects — A.5.25 requires assessment of every security event against an agreed categorization scheme that explicitly includes criteria to classify events as incidents; this surfaces and records spoofing events that reach the PoC, but only those that are first observed and routed to the assessment process (most spoofed emails are filtered or never surface as events).
- T1685detects — A.5.25 requires assessment of security events (including those that could be T1685) using an agreed scheme to categorize and prioritize them as incidents, which surfaces knowledge of the technique in flight but only for events that reach the point of contact and fit the scheme's criteria.
- T1685responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core act of incident response once an event (such as tool tampering) is underway.
- T1685.001detects — A.5.25 requires assessment of every security event against an agreed categorization/prioritization scheme that explicitly includes criteria for deciding whether an event qualifies as an information security incident; disabling the Event Log itself is an observable event that can be assessed and recorded as such, but the control only surfaces the fact after the technique has already succeeded in limiting logging data and does not guarantee detection of every variant or instance.
- T1685.002detects — A.5.25 requires assessment of each security event against an agreed categorization scheme that explicitly includes criteria to identify which events qualify as incidents; this surfaces knowledge of the logging-disabling technique when it is observed and reported as an event, but the control stops at assessment/prioritization and does not itself perform or mandate the monitoring that would surface the event in the first place.
- T1685.003detects — A.5.25 requires assessment of events against an agreed categorization scheme to decide if they are incidents; this surfaces and prioritizes the spoofed-UI technique once observed as an anomalous event, but the control itself supplies no instrumentation or monitoring and stops at human assessment of already-reported events.
- T1685.004detects — A.5.25 requires assessment of security events against an agreed categorization scheme to decide if they are incidents; this surfaces some malicious auditd tampering as an event but only after other detection has already occurred and does not itself instrument or observe the technique.
- T1685.005detects — A.5.25 requires assessment of each security event against an agreed categorization/prioritization scheme that explicitly includes criteria to identify which events qualify as incidents; this surfaces (i.e., detects) the T1685.005 technique when it produces a recognizable anomalous-clearing event, but only for events that reach the point-of-contact assessor and only within the scheme's chosen criteria, leaving substantial remainder outside that scope.
- T1685.005responds — A.5.25 requires competent personnel to assess each security event against an agreed categorization/prioritization scheme (including criteria that turn events into incidents) and to decide on and record the outcome; this is the core of incident response once an event is underway, and clearing Windows event logs is a detectable technique that would trigger exactly such assessment and decision-making.
- T1685.006responds — A.5.25 requires assessment/prioritization of security events (including log-clearing as an indicator) by the incident response team and records the decision, which directly enacts the `responds` verb once the technique is underway.
- T1686detects — A.5.25 requires assessment of each security event against an agreed categorization/prioritization scheme that explicitly includes criteria to identify events as incidents; firewall tampering is a detectable anomalous event that can be assessed and recorded this way, but the control stops at assessment/decision and does not itself perform detection instrumentation or monitoring.
- T1686responds — A.5.25 requires assessment/prioritization of security events (including those matching T1686 behaviors) by the incident response team to decide on and record the incident response path, which is the core of `responds` once the technique is underway.
- T1686.001detects — A.5.25 requires assessment of events against an agreed scheme that decides whether they qualify as security incidents, which can surface T1686.001 once the firewall change is treated as an observable event, but the control itself supplies no instrumentation, monitoring or detection mechanism and stops at human categorization of already-reported events.
- T1686.001responds — A.5.25 requires assessment/prioritization of security events (including those matching T1686.001) once they have occurred and are underway, which directly enacts the `responds` verb of containment/eradication once the technique is in flight.
- T1686.002detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; this surfaces knowledge of T1686.002 once the modification is treated as an event, but the control stops at assessment/prioritization and does not itself instrument or observe the technique.
- T1688detects — A.5.25 requires assessment of security events against an agreed categorization scheme that can surface safe-mode abuse as a high-priority incident when observed, but the control itself performs no monitoring or detection and depends on other mechanisms to first surface the event.
- T1689detects — A.5.25 requires assessment of every security event against an agreed scheme that decides whether it qualifies as an incident; a downgrade that impairs logging, Secure Boot, or encryption is observable as an anomalous security-relevant event and would be assessed and recorded, but many downgrade variants (especially those that only enable a later technique without triggering a visible event) sit outside any realistic categorization scheme.
Prevented OWASP Web Top 10 (2025) risks (4)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A09mitigates — A.5.25's assessment/prioritization scheme and recording of events directly bounds the consequence of undetected incidents by enabling faster, better-coordinated response once an event reaches the point of contact, but does not address the core weakness of events not being logged or alerts not firing in the first place.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.