A.6.8 People
Information security event reporting
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (15)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- IR-6mostlyaligns with — Both controls require personnel to promptly report security events so that incidents can be contained and investigated.
- IR-6mostlycovers — A.6.8's focus on timely/consistent/effective event reporting by personnel directly accounts for the bulk of IR-6's personnel reporting requirement and organizational routing, but leaves a residual on the second IR-6 clause (external/authority reporting parameters) that sits outside A.6.8's defined scope.
- AT-2partialaligns with — Both emphasize awareness training so users understand their duty to report security events and the correct reporting channels.
- IR-4partialaligns with — The ISO control supports the incident-handling process by ensuring that events are reported quickly enough to enable effective response.
- SI-4partialaligns with — The ISO control complements system monitoring by ensuring human-detected anomalies and suspected vulnerabilities are also reported.
Aligned NIST CSF 2.0 outcomes (17)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- RS.CO-02mostlyaligns with — The ISO control establishes the obligation and mechanism for personnel to report security events promptly, directly supporting the CSF outcome of notifying internal and external stakeholders when incidents occur.
- RS.CO-03mostlyaligns with — By defining accessible reporting channels and points of contact, the ISO control ensures that incident-related information reaches designated stakeholders for coordinated response.
- ID.RA-08partialaligns with — The ISO control requires reporting of vulnerabilities and discourages unauthorized testing, supporting the CSF outcome of receiving and responding to vulnerability disclosures.
- PR.AT-01partialaligns with — The ISO control mandates awareness of reporting responsibilities and procedures, which is a core element of general cybersecurity awareness training.
- RS.MA-02partialaligns with — The ISO control feeds reported events into the incident management process, enabling triage and validation of potential incidents.
- ID.RA-08implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.AT-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- RS.CO-02implements — A.6.8's operational mechanism for timely event reporting directly gives effect to the notification outcome in RS.CO-02 within the response/communications domain, though the CSF outcome does not name reporting as the exclusive means
- RS.CO-03implements — A.6.8 operationalizes timely event reporting which directly supplies the information-sharing required by RS.CO-03 within the response-coordination domain
- RS.MA-02implements — A.6.8 operationalizes timely event reporting which directly supplies the validated incident reports that RS.MA-02 requires within the response domain
Related OWASP ASVS 5.0 requirements (4)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Related weaknesses / CWE (3)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-200finds — Rapid reporting of confidentiality breaches ensures sensitive data exposure is discovered and contained before further leakage occurs.
- CWE-284finds — Prompt disclosure of access violations allows the organization to revoke unauthorized privileges and close the control gap.
- CWE-400finds — Early notification of anomalous resource consumption or system malfunctions enables throttling or isolation before availability is lost.
Mitigated MITRE ATT&CK techniques (787)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, ineffective controls and access violations, which surfaces many T1001 realizations once observed by personnel; it does not itself instrument or guarantee detection of obfuscated C2 traffic.
- T1001.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, and ineffective controls, which would surface steganographic C2 as a reportable event once observed; it does not itself perform detection and leaves most in-flight hidden traffic unreached.
- T1001.003detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behaviour, access violations, suspected malware and breaches that would surface protocol impersonation when observed by personnel, but the control itself only enables reporting of what humans already notice and does not instrument or analyse traffic to discover disguised C2.
- T1003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus suspected malware (both observable indicators of credential dumping in flight or post-execution), but does not itself perform detection, only enabling human-sourced event reports; many stealthy dumps produce no reportable event at all.
- T1003responds — A.6.8's purpose and guidance require personnel to report observed events (including breaches, access violations, malware, anomalous behaviour, and ineffective controls) once they occur, enabling timely incident response that contains and eradicates an in-flight T1003 campaign; the named remainder is stealthy dumps that produce no observable event for personnel to report.
- T1003.001detects — A.6.8 requires personnel to report observed events including access violations, anomalous behaviour, suspected malware, ineffective controls and vulnerabilities; these can surface LSASS dumping when noticed, but most in-memory credential access (especially by privileged/SYSTEM processes) produces no observable event for users to report, so only a minority slice is covered.
- T1003.001responds — A.6.8 requires personnel to report observed events (including access violations, anomalous behaviour, suspected malware, ineffective controls) as soon as possible so that an incident response process can be triggered; LSASS credential dumping is exactly such an observable event that, once underway, is contained/eradicated by the response the reporting enables.
- T1003.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus suspected malware (both observable during/after SAM extraction), enabling personnel to detect and report the event; it does not itself instrument or surface the technique.
- T1003.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus suspected malware or anomalous behaviour that would surface NTDS-access activity if observed by personnel; this yields detection knowledge but only for the human-observable slice, not automated or stealthy tool use such as Volume Shadow Copy or ntdsutil.exe on a DC.
- T1003.004detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus suspected malware (both observable during/after T1003.004 execution), enabling personnel to detect and report the event; it does not itself instrument or surface the technique.
- T1003.005detects — A.6.8 requires personnel to report observed events including access violations, ineffective controls, anomalous behaviour, suspected malware, and vulnerabilities; an adversary extracting cached credentials (especially with SYSTEM/sudo) can produce observable indicators that fit those categories and would be reported if noticed, but most extractions are stealthy, post-compromise, and unlikely to be spotted without other monitoring layers.
- T1003.006detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour, which would surface a DCSync attempt if noticed and reported by personnel; this is only a slice because the control is purely human-driven, depends on someone observing and choosing to report, and does not itself instrument or monitor for the technique.
- T1003.007detects — A.6.8 requires awareness and easy reporting of events including human errors, access violations, anomalous behaviour, malware, vulnerabilities and ineffective controls; these can surface credential-gathering activity from /proc but only when an observant person notices and reports it, leaving the bulk of stealthy, automated or low-and-slow execution undetected by this personnel-focused mechanism.
- T1003.008detects — A.6.8 explicitly lists access violations, ineffective controls, breaches of confidentiality, and suspected malware as reportable events that personnel must flag; reading /etc/shadow (normally root-only) is exactly such an observable violation or anomalous access, so the control surfaces knowledge of the technique once attempted, but only when a human notices and reports it rather than through automated instrumentation.
- T1005detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, access violations, anomalous behaviour, suspected malware, ineffective controls and vulnerabilities, which would surface many observable signs of a local data collection attempt once it is underway; this is genuine but only a slice because the control is purely about personnel-driven reporting rather than automated or comprehensive detection coverage across all platforms and TTPs.
- T1006detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, access violations, anomalous behaviour, breaches of confidentiality/integrity/availability and suspected malware; this surfaces some T1006 realisations (e.g. anomalous volume access or monitoring bypass) once observed by personnel, but does not instrument or automatically detect the technique itself.
- T1007detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous system behaviour, malware, access violations and vulnerabilities; discovery commands can surface as observable anomalies or events that personnel are trained to report, but this depends on human observation rather than automated detection and leaves most stealthy or non-obvious executions unreported.
- T1008detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations, and ineffective controls, which would surface many fallback-channel C2 attempts once observed by personnel; it does not itself instrument or guarantee detection of the technique.
- T1010detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, ineffective controls, and access violations, which would surface T1010 activity if observed by personnel; however, the control is purely human-driven with no instrumentation, detection logic, or automated coverage, leaving most stealthy or non-obvious executions undetected.
- T1011detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, access violations, ineffective controls, and suspected malware, which can surface T1011 exfiltration when observed by personnel; however, the control is limited to human-reported events and does not itself instrument or monitor for the technique.
- T1014detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'malfunctions or other anomalous system behaviour', 'ineffective information security controls', and 'vulnerabilities' in what must be reported, which surfaces rootkit indicators once observed by personnel; this is only a slice because rootkits are designed to evade exactly the observations a human user or standard monitoring would make, and the control stops at reporting rather than guaranteeing detection occurs.
- T1016.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations and ineffective controls; these surface Internet Connection Discovery when it is treated as an observable event by personnel, but the control stops at reporting knowledge and does not instrument or guarantee detection of the technique itself.
- T1020detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'breaches of information confidentiality' plus 'suspected malware infection' and 'anomalous system behaviour' that would surface many automated exfiltration attempts once noticed by personnel; this is genuine detection coverage but only a slice, as fully automated exfiltration can complete without any human observation or reporting trigger.
- T1020.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective information security controls', 'breaches of confidentiality/integrity/availability', 'access violations', 'suspected malware', and 'anomalous system behaviour' that would surface many instances of traffic mirroring or duplication as reportable events, but this is limited to what personnel notice and choose to report rather than any automated or guaranteed detection.
- T1021detects — A.6.8 requires personnel to report observed events including access violations, ineffective controls, anomalous behavior, suspected malware, and vulnerabilities; this surfaces some T1021 executions (e.g., anomalous RDP/SSH logins or post-login anomalies noticed by users) but does not instrument or guarantee detection of the technique itself, especially stealthy or automated uses.
- T1021.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour, which surfaces RDP logons that deviate from baseline (e.g. off-hours, unexpected source, or post-credential-access); this is genuine detection of the technique in flight but only a slice, as the clause sets scope by what personnel notice and choose to report rather than mandating instrumentation that catches all RDP use.
- T1021.002detects — A.6.8 requires awareness and easy reporting of events including access violations, ineffective controls, anomalous behaviour, and suspected malware, which would surface many (but not all) realisations of SMB admin share abuse once they occur and are observable by personnel.
- T1021.003detects — A.6.8 requires awareness and easy reporting of events including access violations, anomalous behaviour, malware, ineffective controls and suspected vulnerabilities, which would surface many observable signs of DCOM lateral movement once it occurs; it does not instrument or guarantee detection of the technique itself.
- T1021.004detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour, which surfaces SSH logins (especially unauthorized or post-compromise) when reported; it does not itself instrument or monitor for the technique.
- T1021.005detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour, which would surface VNC-based remote control when noticed by personnel; it does not instrument or guarantee automated detection of the technique itself.
- T1021.006detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour, which surfaces WinRM-based lateral movement when observed and reported by personnel; it does not instrument or guarantee automated detection of the technique itself.
- T1021.007detects — A.6.8 requires awareness, easy mechanisms, and explicit inclusion of access violations plus anomalous behaviour in the list of reportable events, which surfaces T1021.007 use after the fact when noticed by personnel; it does not instrument or guarantee detection of the technique itself.
- T1021.008detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour as reportable events, which can surface T1021.008 post-facto when observed by personnel; it does not itself instrument or monitor for the technique.
- T1027.003detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, breaches and vulnerabilities; this surfaces steganography use once observed by personnel but does not instrument or guarantee discovery of the hidden payload itself.
- T1027.006detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, breaches, anomalous behaviour, malware and vulnerabilities; HTML smuggling (as an obfuscated delivery that evades filters and later deobfuscates) can surface as one of those observable events if noticed by personnel, but the control itself only enables reporting and does not perform or guarantee detection.
- T1027.007detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behavior, and ineffective controls, which can surface dynamic API resolution once observed as suspicious activity, but does not itself instrument or analyze binaries for the obfuscation technique.
- T1027.010detects — A.6.8 requires personnel to report observed events including anomalous system behaviour, suspected malware, ineffective controls, and access violations; obfuscated commands can produce observable anomalies that fit these categories and are therefore surfaced via human reporting, but this is limited to what users notice and choose to report rather than systematic or automated detection of the technique itself.
- T1027.011detects — A.6.8 requires personnel to report observed events including anomalous system behaviour, suspected malware, ineffective controls, and access violations; these can surface fileless storage artifacts when noticed, but the control relies on human observation rather than any automated or systematic detection mechanism and leaves the bulk of stealthy fileless activity unseen.
- T1027.012detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, malware, anomalous behavior, and breaches so that personnel can surface LNK-smuggling events when observed; this provides detection coverage for post-compromise or user-visible cases but leaves pre-compromise phishing, content-filter evasion, and non-human-triggered executions outside the personnel-reporting scope.
- T1027.017detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, breaches and vulnerabilities; SVG smuggling (malicious script inside an image-like file) can be surfaced if spotted by personnel as one of those event types, but the control itself supplies no mechanism or instrumentation to detect the technique automatically.
- T1030detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behaviour, breaches of expectations, and suspected malware; this surfaces some T1030 usage (e.g. via anomaly or threshold alerts that personnel notice) but does not instrument or guarantee detection of the stealthy chunked exfiltration itself.
- T1033detects — A.6.8 requires awareness and easy reporting of events including human errors, access violations, anomalous behaviour, and suspected malware that could surface T1033 execution; this provides detection only where personnel notice and choose to report rather than automated coverage.
- T1036.001detects — A.6.8 requires personnel to report observed events including ineffective controls, anomalous behaviour, suspected malware, access violations and vulnerabilities; an invalid code signature may surface as one of those observable anomalies and be reported, but the control itself only gathers human-reported knowledge and does not instrument or guarantee detection of the technique.
- T1036.002detects — A.6.8 explicitly lists suspected malware infection, anomalous system behaviour, and ineffective controls among the events personnel must report, which would surface many (but not all) RTLO-based disguises once noticed; the control is awareness-driven rather than automated tooling, so coverage is a chosen slice rather than a bounded remainder.
- T1036.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'malfunctions or other anomalous system behaviour' plus 'ineffective information security controls' and 'access violations' in the list of reportable events; renamed utilities are a classic anomalous/masquerading indicator that monitoring or personnel can surface via the mandated reporting channel, but the control itself only enables reporting of what is noticed and reaches none of the stealthier rename+execute cases that evade all observation.
- T1036.004detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, malware, access violations and ineffective controls, which can surface a masquerading task/service once it produces observable anomalies; this is genuine but only a slice because the control is purely about personnel-driven reporting and does not mandate any automated detection mechanism that would reliably surface the naming manipulation itself.
- T1036.006detects — A.6.8 requires personnel to be aware of and report anomalous system behaviour, suspected malware, ineffective controls, and other observable events that would surface a suspicious space-after-filename file when encountered by a user; this is genuine but only a slice because the control is limited to human-reported events and does not instrument or automatically surface the technique itself.
- T1036.007detects — A.6.8 explicitly lists human errors, non-compliance, access violations, suspected malware, and anomalous behaviour as reportable events that personnel are trained to recognise and report, which surfaces many (but not all) realisations of double-extension masquerading when a user notices or is suspicious before opening
- T1036.008detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, ineffective controls, breaches and vulnerabilities; this surfaces masquerading when observed by personnel but does not instrument or guarantee detection of the technique itself.
- T1036.010detects — A.6.8 requires awareness and easy reporting of events including access violations, ineffective controls, anomalous behaviour, suspected malware, and vulnerabilities; this can surface a masquerading account after creation (e.g. via anomaly or violation report) but does not instrument or guarantee detection of the name-matching act itself.
- T1036.011detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, suspected malware, access violations and ineffective controls; these can surface the in-memory argument overwrite when observed, but the control itself only enables human reporting and does not instrument or guarantee discovery of the stealth technique.
- T1036.012detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behaviour, access violations and suspected malware; these can surface browser fingerprinting when observed as anomalous traffic or system behaviour, but the control is personnel-driven awareness rather than automated detection and does not reach most stealthy spoofing cases.
- T1037detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, malware, access violations and ineffective controls — all of which surface T1037 when a user or admin notices the script's side-effects; this is genuine but only a slice because most script-based persistence is silent until later activity and the control stops at reporting rather than automated detection.
- T1037.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, non-compliance, access violations, anomalous behaviour, and suspected malware as reportable events; these surface many (but not all) observable indicators of a T1037.001 logon-script persistence implant once it has executed at logon.
- T1037.002detects — A.6.8 requires awareness and easy reporting of events including human errors, non-compliance, access violations, anomalous behaviour, malware and vulnerabilities; a Login Hook modification or its anomalous execution can be observed and reported by personnel, but the control only surfaces knowledge without mandating any detection mechanism and leaves most technical realizations (especially post-deprecation) unreached.
- T1037.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, non-compliance, anomalous behaviour, access violations, and suspected malware as reportable events; these surface T1037.003 when the anomalous logon-script execution is noticed by personnel, but the control itself only enables reporting of what is already observed and does not instrument or guarantee discovery of the technique.
- T1037.004detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behavior, access violations, ineffective controls and non-compliance; this surfaces RC script abuse once observed by personnel but does not instrument or guarantee discovery of the modification itself.
- T1037.005detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'malfunctions or other anomalous system behaviour', 'access violations', and 'ineffective information security controls' that would surface a new StartupItems persistence artifact at boot or via monitoring; this is a genuine but minority slice of the technique's full lifecycle (creation, persistence, and root execution) rather than broad detection coverage.
- T1040detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behaviour, access violations, suspected malware, and vulnerabilities; this surfaces some sniffing (e.g. via observed anomalies or post-capture indicators) but does not instrument or guarantee detection of passive sniffing itself, especially stealthy or cloud-based instances.
- T1041detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective controls', 'breaches of confidentiality/integrity/availability', 'anomalous system behaviour', 'access violations' and 'suspected malware' as reportable events, which would surface many observable signs of C2-based exfiltration once it is underway; it does not itself instrument or analyse traffic, so coverage is a chosen slice rather than a bounded remainder.
- T1046detects — A.6.8 requires personnel to report observed events including vulnerabilities, ineffective controls, anomalous behaviour, and suspected malware; this surfaces T1046 when a user or admin notices the scanning activity, but most network service discovery is automated/silent and evades human observation, so only a minority slice is caught.
- T1047detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations, and ineffective controls — all of which can surface WMI abuse when observed by personnel; this is genuine but only a slice because the control is purely human-driven, depends on someone noticing and choosing to report, and has no instrumentation, alerting, or automated detection component.
- T1047responds — A.6.8's purpose and guidance require timely reporting of events (including malware, anomalous behaviour, access violations, ineffective controls) once they occur so that response actions can begin, which is exactly what `responds` names on the event lane.
- T1048detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective controls', 'breaches of confidentiality/integrity/availability', 'access violations', 'suspected malware', and 'anomalous system behaviour' that would surface many observable signs of T1048 exfiltration; however, it is a personnel-driven reporting process with no mandated monitoring, detection tooling, or automated coverage of stealthy/obfuscated protocol use across all platforms.
- T1048.001detects — A.6.8 requires awareness and easy reporting of events including breaches of confidentiality, anomalous behaviour, access violations and suspected malware, which can surface exfiltration; this is genuine but only a slice because the control is purely about personnel reporting (no monitoring, no automated detection, and many stealthy exfiltrations produce no observable event for a person to report).
- T1048.002detects — A.6.8 requires awareness and easy reporting of events including breaches of confidentiality, anomalous behavior, access violations and suspected malware, which would surface many (but not all) observable signs of asymmetric exfiltration over non-C2 channels such as HTTPS/TLS.
- T1048.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'breaches of information confidentiality' plus 'malfunctions or other anomalous system behaviour' in the list of reportable events, which can surface exfiltration; however, it is a personnel-driven reporting process with no instrumentation, monitoring, or automated detection, so only a slice of realisations (those noticed and reported by people) is covered.
- T1049detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, access violations, and suspected malware as reportable events; discovery commands like netstat/lsof can surface as observable anomalies or violations once run, but this depends on personnel noticing and reporting rather than automated detection, leaving most stealthy or non-obvious executions unreached.
- T1052detects — A.6.8 explicitly lists human errors, breaches of physical security measures, access violations, and suspected malware as reportable events that personnel are trained to recognize and report, which surfaces many (but not all) instances of physical-medium exfiltration once a user introduces or observes the removable device.
- T1052.001detects — A.6.8 requires awareness and easy reporting of events including breaches of confidentiality, physical security breaches, access violations, anomalous behaviour, and suspected malware, which would surface many observable signs of USB exfiltration (especially user-introduced device use in air-gapped settings); it does not itself instrument or monitor for the technique.
- T1053detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations, ineffective controls and suspected vulnerabilities, which surfaces many (but not all) observable indicators of scheduled-task abuse for persistence or privilege escalation
- T1053.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'anomalous system behaviour', and 'ineffective controls' among reportable events, which would surface many observable signs of at-based scheduling/persistence/execution; it stops short of mandating automated detection or covering all stealthy or non-user-visible invocations, leaving a genuine slice unreached.
- T1053.002responds — A.6.8 makes personnel aware of the duty and easy mechanism to report security events (including malware, anomalous behaviour, access violations, ineffective controls), which directly enables the containment/eradication steps of incident response once the scheduled-at technique is recognised as an event; it does not itself perform the response actions.
- T1053.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations, anomalous system behaviour, malware, and ineffective controls — all of which surface cron-based persistence when observed by personnel; it does not itself instrument or monitor for the technique.
- T1053.005detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, malware, access violations, ineffective controls and breaches; this surfaces some observable signs of scheduled-task abuse (e.g. unexpected tasks, hidden-task anomalies, malware indicators) once created or running, but does not instrument or guarantee discovery of the technique itself.
- T1053.006detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, malfunctions, access violations, ineffective controls and suspected malware, which would surface systemd timer abuse once observed; the control itself stops at reporting and does not mandate monitoring or detection mechanisms, leaving most of the technique unobserved.
- T1053.007detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations and ineffective controls — all of which can surface a container-orchestration job once it is running, but only when observed and voluntarily reported by personnel; the control itself supplies no instrumentation, monitoring or automated detection.
- T1055detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'anomalous system behaviour', 'access violations' and 'ineffective controls' as reportable events; these surface some observable indicators of process injection once it has occurred, but the control is personnel-driven rather than automated monitoring and does not reach stealthy or non-obvious injections.
- T1055.001detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations and ineffective controls; these can surface DLL injection in flight when observed by personnel, but the control itself only enables reporting and does not mandate or perform detection instrumentation.
- T1055.001responds — A.6.8 makes personnel the detection surface for anomalous system behaviour, suspected malware, access violations and ineffective controls (all observable during or after T1055.001 execution) and requires timely reporting that feeds directly into incident response; the control does not itself contain or eradicate but its output enables the response that does, matching the verb's definition on the event lane.
- T1055.002detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations and ineffective controls; this surfaces some observable signs of PE injection once it has occurred, but the clause itself only organises human reporting and does not mandate any automated detection capability.
- T1055.003detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations and ineffective controls; these can surface Thread Execution Hijacking once it produces observable symptoms, but the control itself supplies no instrumentation, monitoring or automated detection and stops at human reporting of already-evident events.
- T1055.003responds — A.6.8 requires timely reporting of events including malware, anomalous behaviour, access violations and ineffective controls; once T1055.003 is underway these map directly to reportable events that trigger the incident-response process the control feeds.
- T1055.004detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations and ineffective controls; personnel observing APC injection symptoms (suspicious process behaviour, unexpected DLL loads, anomalous threads) can report them, but the control itself supplies no instrumentation, monitoring or automated detection and reaches only what observant humans notice.
- T1055.008detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations and ineffective controls; ptrace injection produces observable anomalies that personnel could report, but the control only surfaces knowledge via human reporting and does not instrument or guarantee detection of the technique itself.
- T1055.009detects — A.6.8 requires personnel to report observed events including anomalous system behaviour, suspected malware, access violations, ineffective controls and vulnerabilities; this surfaces some in-flight or post-injection artifacts when noticed by users or admins, but the technique is designed to evade process-based defenses and runs silently without obvious symptoms in most cases.
- T1055.011detects — A.6.8 requires personnel to report observed events including malware, anomalous behavior, access violations and ineffective controls; this surfaces some EWM injection attempts when noticed by users or admins, but most in-process technique executions are not human-observable and fall outside the clause's personnel-focused mechanism.
- T1055.012detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations and ineffective controls; personnel observing hollowing artefacts (suspended processes, anomalous memory writes, unexpected ResumeThread behaviour) can report them, but the control itself supplies no instrumentation, telemetry or automated detection and reaches only the human-observable slice.
- T1055.013detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'anomalous system behaviour', 'access violations' and 'ineffective controls' as reportable events; these surface some observable symptoms of process doppelganging once it has executed, but the technique's file-less, TxF-based stealth (avoiding monitored APIs and masking under a legitimate process) leaves the bulk of its in-memory execution outside what personnel are positioned to notice or report.
- T1055.014detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'anomalous system behaviour', and 'ineffective controls' as reportable events, which can surface VDSO hijacking once observed; this is limited to human-detectable indicators rather than automated or comprehensive coverage of the stealthy in-process technique.
- T1055.015detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations and ineffective controls; this surfaces ListPlanting once observed as suspicious but the control itself supplies no instrumentation or monitoring and therefore only catches the slice that personnel happen to notice and choose to report.
- T1056detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, access violations, suspected malware, anomalous behaviour and ineffective controls — all of which surface many real-world input-capture realisations (especially user-noticed phishing/deception cases) once they occur, but does not instrument or automatically surface transparent hooking or non-obvious credential API captures.
- T1056.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of suspected malware, anomalous behaviour, access violations, and ineffective controls, which would surface many (but not all) keylogging implementations once observed by personnel; it does not instrument or automatically surface the technique itself.
- T1056.002detects — A.6.8 requires awareness and easy reporting of events including human errors, access violations, suspected malware, anomalous behaviour and ineffective controls; a GUI prompt that mimics legitimate credential dialogs can be recognised by attentive personnel as suspicious (especially when paired with monitoring or anomalous context), enabling reporting that surfaces the technique, but this is awareness-driven and depends on user vigilance rather than any automated or guaranteed mechanism.
- T1056.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'ineffective controls', and 'anomalous system behaviour' that would surface many web portal credential-capture artifacts once noticed by users or admins; this is genuine detection coverage but only a slice, as the technique can be silent, non-malware, and invisible to end users with no guaranteed instrumentation or automated discovery.
- T1056.004detects — A.6.8 requires personnel to report observed events including malware, anomalous behaviour, access violations and ineffective controls; credential API hooking is observable in principle as anomalous/malware behaviour but is a low-level in-process technique unlikely to be noticed by most users, so only a slice is actually detected via reporting.
- T1057detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, suspected malware, ineffective controls, and access violations; these can surface process-discovery activity when observed by personnel, but the clause itself only enables human reporting and does not instrument or monitor for the technique.
- T1059detects — Users reporting anomalous command-line or scripting activity can trigger early investigation that interrupts an adversary’s use of interpreters to execute malicious code.
- T1059.001detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations and ineffective controls; these can surface PowerShell abuse when observed by personnel, but the control itself supplies no instrumentation, automated discovery or guaranteed coverage of stealthy in-memory or non-powershell.exe execution.
- T1059.002detects — A.6.8 requires personnel to report observed events including anomalous system behaviour, suspected malware, access violations and ineffective controls; these can surface AppleScript abuse when it produces visible artifacts (e.g. fake dialogs, anomalous osascript processes, unexpected SSH interaction), but the clause depends on human observation and does not instrument or guarantee discovery of stealthy script execution.
- T1059.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations, and ineffective controls as reportable events, which would surface many (but not all) Windows command shell abuses once observed by personnel
- T1059.004detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, malware, access violations and ineffective controls — all of which surface Unix shell abuse when observed by personnel; it does not itself instrument or monitor for the technique.
- T1059.005detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behavior, access violations, and ineffective controls, which would surface many VB-based execution attempts once observed by personnel; it does not instrument or automatically detect the technique itself.
- T1059.006detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, and access violations, which would surface many Python-based execution artifacts once observed by personnel; however, it is a human-driven reporting process with no instrumentation, detection logic, or coverage of silent/automated abuse, leaving most technique executions unreported.
- T1059.007detects — A.6.8 requires personnel to report observed events including malware, anomalous behaviour, access violations, ineffective controls and suspected vulnerabilities, which can surface in-flight or post-execution JS abuse when noticed by users; this is genuine but only a slice because most T1059.007 executions (especially fileless, obfuscated or automated) produce no observable symptom for a human to report.
- T1059.007responds — A.6.8 makes personnel aware of the responsibility and easy procedure to report observed events including malware, anomalous behaviour, access violations and suspected vulnerabilities, which directly enables the containment/eradication steps of incident response once a JavaScript abuse technique is underway and noticed.
- T1059.008detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, access violations, malware, ineffective controls and non-compliance, which surfaces many T1059.008 executions once noticed by personnel; it does not itself instrument or monitor for the technique.
- T1059.009detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations, and ineffective controls — all of which can surface cloud API abuse when observed by personnel; this is genuine detection coverage but only a slice, as most T1059.009 executions are automated, non-obvious to humans, or occur without triggering the listed observable categories.
- T1059.010detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, and access violations, which would surface many AHK/AutoIT script executions or compiled payloads once noticed by users; it does not instrument or automatically detect the technique itself.
- T1059.011detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, and access violations that would surface Lua-based execution when observed by personnel; this is genuine detection coverage but only a slice, as the control depends on human recognition rather than automated instrumentation and does not address silent or embedded interpreter abuse.
- T1059.012detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations, and ineffective controls — all of which can surface hypervisor CLI abuse on ESXi; it stops at knowledge and does not act on the report.
- T1059.013detects — A.6.8 requires personnel to report observed events including anomalous system behaviour, suspected malware, access violations, and ineffective controls; this surfaces some in-flight or post-execution signs of container CLI/API abuse when noticed by users, but most containerized adversary activity is not directly observable by personnel and the control sets no instrumentation or automated detection.
- T1068detects — A.6.8 explicitly lists vulnerabilities, suspected malware, anomalous system behaviour, ineffective controls and access violations among the events personnel must report, which surfaces T1068 exploitation attempts or their indicators once observed by users; it is only partial because the control is awareness-and-reporting focused with no instrumentation, detection logic or automated coverage of the technique itself.
- T1069detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus ineffective controls or anomalous behaviour that would surface permission-group discovery activity; this yields detection knowledge once reported, but only for events that personnel actually notice and choose to report rather than automated or stealthy discovery.
- T1069.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations/vulnerabilities/suspected malware as reportable events, which would surface T1069.003 reconnaissance if noticed and reported by personnel; this is only a slice because the technique is typically low-and-slow, stealthy, and post-authentication, with most instances unlikely to be observed or recognized as anomalous by users.
- T1070detects — A.6.8 explicitly lists several T1070-relevant artifacts (log entries, access violations, anomalous behaviour, suspected malware, ineffective controls) as reportable events, so the mandated awareness+easy mechanism surfaces them when personnel notice; it does not instrument or guarantee detection of stealthy, selective modifications that blend with normal activity.
- T1070.003detects — A.6.8 explicitly lists human errors, non-compliance, access violations, anomalous system behaviour, and suspected malware as reportable events that personnel are trained to recognize and report quickly; these overlap with observable indicators of T1070.003 (e.g. history -c, rm ~/.bash_history, Clear-History, file deletion of ConsoleHost_history.txt), but the control stops at awareness and easy reporting channels without mandating automated detection or coverage of all platforms/variants.
- T1070.004detects — A.6.8 requires awareness and easy reporting of events including human errors, anomalous behaviour, access violations, malware, and ineffective controls that would surface file-deletion artifacts or post-intrusion cleanup; this yields detection knowledge but only for the subset personnel actually observe and choose to report, leaving automated or stealthy cases unreached.
- T1070.005detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, non-compliance, access violations, anomalous behaviour, and suspected malware as reportable events; an adversary's deliberate share-removal action (T1070.005) can surface as one of those observable anomalies if noticed by personnel, but the control itself only enables reporting and does not mandate or perform detection instrumentation.
- T1070.006detects — A.6.8 requires awareness and easy reporting of events including human errors, anomalous system behaviour, access violations, and suspected malware; timestomping produces observable anomalies (e.g. mismatched $SI/$FN timestamps or suspicious touch commands) that fit those categories and can be reported once noticed, but the control itself supplies no instrumentation, monitoring or automated detection and depends entirely on personnel happening to notice and report.
- T1070.007detects — A.6.8 requires personnel to report observed events including ineffective controls, anomalous behaviour, access violations, suspected malware, and vulnerabilities; these can surface T1070.007 artifacts or the preceding network activity that leaves them, but the control depends on human observation rather than automated or guaranteed discovery of the clearing action itself.
- T1070.008detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, non-compliance, access violations, suspected malware, anomalous behaviour, and ineffective controls — all of which surface T1070.008 mailbox-clearing activity when noticed by personnel; it does not itself instrument or monitor for the technique.
- T1070.009detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, non-compliance, access violations, anomalous behaviour, suspected malware, and ineffective controls — all of which can surface T1070.009 cleanup actions when observed by personnel; this is genuine but only a slice because the control is limited to what people notice and choose to report rather than automated or comprehensive detection.
- T1070.010detects — A.6.8 explicitly lists suspected malware infection among the reportable events that personnel are trained to recognize and report quickly, which surfaces the T1070.010 technique once it has produced observable artifacts; the remainder is stealthy or non-obvious relocations that evade human recognition.
- T1071.003detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, malware, access violations and ineffective controls; personnel observing suspicious mail-protocol traffic (or its artifacts) can report it, surfacing the technique, but the control itself supplies no instrumentation, monitoring or automated detection and reaches only what humans notice and choose to report.
- T1071.004detects — A.6.8 makes personnel aware of their responsibility (and the easy mechanism) to report observed events including anomalous system behaviour, suspected malware, access violations, ineffective controls and breaches; this surfaces knowledge of T1071.004 when its DNS tunneling/beaconing produces noticeable anomalies that a person actually sees, but the control itself supplies no instrumentation, automated scanning or network monitoring and therefore only catches the human-observable slice.
- T1071.005detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, suspected malware, access violations and ineffective controls; pub/sub C2 traffic that deviates from baseline or triggers anomaly detection can be reported as such an event, but the control itself only enables human reporting and does not perform or guarantee detection of the blended protocol abuse.
- T1072detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'ineffective controls', 'anomalous system behaviour' and 'vulnerabilities' in its event list; these surface adversary use/abuse of deployment tools once it produces observable effects, but the clause stops at reporting (no analysis or confirmation step) and many stealthy lateral-execution paths remain outside typical user-visible triggers.
- T1074detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, anomalous behaviour, access violations, suspected malware, ineffective controls and breaches — all of which can surface T1074 staging activity when observed by personnel; it does not itself instrument or analyse for the technique.
- T1074.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, anomalous behaviour, access violations, and suspected malware as reportable events; these surface many observable signs of local staging activity once it has occurred, but the control stops at reporting knowledge with no mandate to instrument, monitor, or analyse for the technique itself.
- T1074.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, anomalous behaviour, access violations, suspected malware, ineffective controls and breaches, which surfaces many observable precursors or indicators of remote data staging activity once it occurs.
- T1078detects — Prompt reporting of access violations and suspected account misuse increases the chance that compromised valid accounts are detected and contained before they are used for persistence or lateral movement.
- T1078responds — A.6.8 explicitly requires personnel to report security events including access violations, ineffective controls, breaches of confidentiality/integrity/availability, and anomalous behavior; once the technique is underway these reports enable the incident response process that contains and eradicates the abuse of valid accounts.
- T1078.001detects — A.6.8 requires awareness and easy reporting of events including access violations, ineffective controls, non-compliance, vulnerabilities, and anomalous behaviour; this surfaces default-account abuse once observed by personnel but does not instrument or guarantee detection of the technique itself.
- T1078.002detects — A.6.8 explicitly lists access violations, ineffective controls, breaches of confidentiality/integrity/availability, suspected malware, and anomalous behaviour as reportable events that personnel are trained to flag, which surfaces many (but not all) domain-account abuses once they are underway or leave observable traces.
- T1078.003detects — A.6.8 requires awareness and easy reporting of events including access violations, ineffective controls, anomalous behaviour, suspected malware, and vulnerabilities; this surfaces some T1078.003 activity (e.g. anomalous local-account use or post-abuse anomalies) once observed by personnel, but does not instrument or guarantee detection of credential abuse itself.
- T1078.004detects — A.6.8 requires awareness, easy mechanisms, and explicit inclusion of access violations/vulnerabilities/suspected malware in the list of reportable events, which surfaces many T1078.004 realizations (e.g., anomalous access or credential abuse) once noticed by personnel; it does not instrument or guarantee detection of stealthy or automated uses of valid cloud accounts.
- T1080detects — A.6.8 explicitly lists malware infection, anomalous system behaviour, access violations, and ineffective controls among the events personnel must report, which directly surfaces T1080's tainted files and directory-share pivots once observed; the remainder is the pre-execution delivery and lateral movement that occurs without any observable event for users to report.
- T1082detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, malfunctions, suspected malware, access violations and vulnerabilities as reportable events; this surfaces T1082 when personnel notice or the anomalous command itself is treated as an event, but only where it is observed and reported by people rather than automated tooling, leaving most stealthy or non-obvious executions unreached.
- T1083detects — A.6.8 requires personnel to report observed anomalous system behaviour, malware, access violations, ineffective controls and suspected vulnerabilities; file-and-directory discovery is observable as anomalous behaviour or access violations when performed by an insider or detected process, but the control only surfaces it after the fact via human reporting and does not instrument or guarantee detection of stealthy automated discovery.
- T1087detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour, which would surface many instances of account discovery once noticed by personnel; it does not instrument or automatically surface the technique itself.
- T1087.002detects — A.6.8 requires awareness and easy reporting of events including access violations, ineffective controls, anomalous behaviour and suspected malware; enumeration commands can be treated as such events when observed, but the control only surfaces knowledge after the fact and only where personnel notice and report rather than mandating instrumentation that would catch the technique reliably
- T1087.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour as reportable events; this surfaces some instances of T1087.003 (e.g. via logged access violations or Exchange cmdlets flagged as anomalous) but does not instrument or guarantee detection of the technique itself, especially when performed stealthily with valid credentials.
- T1087.004detects — A.6.8 requires personnel to report observed events including access violations, anomalous behaviour, ineffective controls and suspected malware; an adversary running cloud-account-enumeration commands after authenticated access can produce observable indicators (e.g. anomalous IAM API calls or unusual CLI usage) that fall inside the listed reportable situations, but the control itself only surfaces what personnel notice and choose to report rather than instrumenting or automatically detecting the technique.
- T1090.001detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behavior, access violations, malware, and breaches; internal proxy use can produce observable anomalies in traffic patterns, connections, or system behavior that personnel could report, but this is only a slice of detection as the control relies on human observation rather than automated or systematic discovery.
- T1090.002detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, access violations, ineffective controls, and suspected malware, which can surface proxy-based C2 as observable anomalies; however, the control is limited to personnel-driven reporting of noticed events rather than automated or comprehensive detection of the technique itself.
- T1090.003detects — A.6.8 requires personnel to report observed events including anomalous system behaviour, access violations, ineffective controls, suspected malware, and breaches of confidentiality/integrity/availability; these can surface multi-hop proxy activity when it manifests as observable anomalies, but the control relies on human recognition rather than automated detection and does not address stealthy or non-obvious proxy chains.
- T1091detects — A.6.8 explicitly lists suspected malware infection, anomalous system behaviour, and ineffective controls among the events personnel must report, which would surface T1091 once the removable-media infection has executed or is observed; this is genuine detection of the realised technique but only a slice (human-reported observables), as the control provides no instrumentation, automated discovery or coverage of air-gapped propagation before symptoms appear.
- T1092detects — A.6.8 explicitly lists suspected malware infection, anomalous system behaviour, access violations, and ineffective controls among the events personnel must report, which would surface many (but not all) observable indicators of removable-media C2 such as unexpected USB activity or lateral-movement artifacts; the control stops at awareness and easy reporting channels and does not itself perform detection.
- T1095detects — A.6.8 explicitly lists ineffective controls, anomalous system behaviour, access violations, suspected malware and vulnerabilities as reportable events that personnel must flag, which surfaces many T1095 indicators once observed; it does not instrument or monitor the network itself, so coverage is limited to what humans notice rather than automated detection of the technique.
- T1098detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, access violations, policy non-compliance, anomalous behaviour and suspected malware — which can surface account manipulation after it occurs — but does not mandate any automated or proactive detection mechanism, leaving most real-world instances unreported until noticed by chance.
- T1098.001detects — A.6.8 explicitly lists access violations, ineffective controls, non-compliance, suspected malware, and anomalous behaviour as reportable events that personnel are trained to flag, which would surface many T1098.001 actions once performed; it is only partial because the clause relies on human observers rather than automated instrumentation and cannot surface stealthy or privileged additions that evade notice.
- T1098.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus suspected malware or anomalous behaviour that would surface T1098.002 mailbox-permission changes when noticed by personnel; however, the control stops at enabling human reporting of already-visible events and does not itself instrument, scan, or surface stealthy permission grants.
- T1098.003detects — A.6.8 explicitly lists access violations, ineffective controls, non-compliance, and anomalous behaviour as reportable events that personnel are trained to flag, which surfaces T1098.003 when performed by an insider or noticed post-compromise; it does not instrument or surface the API-driven cases that occur outside human observation.
- T1098.004detects — A.6.8 explicitly lists access violations, ineffective controls, non-compliance, anomalous behaviour, and suspected malware as reportable events that personnel are trained to recognise and report, which would surface many (but not all) realisations of SSH authorized_keys modification once they are observable by a user or admin.
- T1098.005detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour as reportable events; device registration (especially self-enrollment or Intune/Entra ID abuse) can surface as anomalous behaviour or access-policy bypass but is not named, is not automatically instrumented, and depends on human recognition and voluntary reporting, leaving most instances undetected without additional controls.
- T1098.006detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus ineffective controls or anomalous behaviour, which would surface the permission-addition act once noticed by personnel; this is a genuine but minority slice because most container-cluster role additions (especially automated or post-compromise) occur without immediate human observation or reporting.
- T1098.007detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour in the list of reportable events; adding groups to maintain persistence is an access violation that would surface as anomalous behaviour if observed by personnel, but the control only surfaces what humans notice and choose to report rather than instrumenting or automatically detecting the technique itself.
- T1102detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'anomalous system behaviour', 'access violations' and 'ineffective controls' that can surface T1102 C2 traffic when observed by personnel; this is genuine detection via human reporting but only a slice of possible observables, as most T1102 use blends into expected web noise and is rarely noticed without automated tooling.
- T1102.001detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, malware, access violations and ineffective controls, which would surface observable indicators of dead-drop resolver C2 activity once it is underway; it does not instrument or guarantee discovery of the covert web-service channel itself.
- T1102.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'anomalous system behaviour', 'access violations' and 'ineffective controls' as reportable events; these surface some T1102.002 artifacts once the bidirectional channel produces observable anomalies, but the technique's use of common, expected web traffic (Google/Twitter, SSL/TLS, legitimate-looking posts) is designed to blend into noise and is not required to produce any of the listed triggers, leaving most executions undetected by this awareness-and-reporting control alone.
- T1102.003detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, suspected malware, access violations and ineffective controls; these can surface one-way C2 Web-service usage when observed by personnel, but the technique is designed to blend into expected legitimate traffic and produces no return channel that would normally be noticed internally.
- T1104detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behavior, malware, access violations and suspected vulnerabilities, which would surface many observable signs of a multi-stage C2 setup once it is running; it does not itself perform detection and leaves many stealthy or pre-compromise staging activities unreported.
- T1105detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'anomalous system behaviour', 'access violations' and 'ineffective controls' that can surface post-ingress tool-transfer artifacts once they are noticed by personnel; this is genuine but only a slice because most T1105 executions (silent downloads via C2, LOLBins, or file syncs) produce no observable event until after execution or lateral movement and rely on human recognition rather than automated detection.
- T1110detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus suspected malware or anomalous behaviour that would surface brute-force attempts (failed logins, unusual access patterns); however, it is a personnel-driven reporting process rather than automated detection, so coverage depends on whether humans notice and choose to report, leaving a large slice of automated or stealthy brute-force attempts unreached.
- T1110.001detects — A.6.8 makes personnel aware of their responsibility (and the easy mechanism) to report observed events including access violations, suspected malware, anomalous behaviour, ineffective controls and non-compliance; some password-guessing attempts produce visible artefacts (failed logons, lockouts, anomalous access patterns) that a trained user or admin can notice and report, but most guessing occurs at management ports or in automated fashion with no human-visible signal and the control has no instrumentation of its own.
- T1110.001prevents — A.6.8 makes personnel aware of their responsibility to report events (including access violations, ineffective controls, suspected malware, and anomalous behaviour) as quickly as possible; timely reporting of the authentication failures or lockouts produced by T1110.001 enables defenders to act before the adversary succeeds, which is what `prevents` asserts on the event lane. `mostly` because the clause itself only ensures reporting occurs; actual prevention still depends on downstream response speed and coverage of the targeted services.
- T1110.001responds — A.6.8 makes personnel aware of their responsibility to report security events (including access violations, ineffective controls, suspected malware, anomalous behaviour, and breaches of confidentiality/integrity) as quickly as possible once identified, enabling timely response once the guessing technique is underway; the named remainder is stealthy guessing (e.g. LDAP/Kerberos paths or low-and-slow attempts) that evades detection by personnel.
- T1110.002detects — A.6.8 explicitly lists access violations, ineffective controls, suspected malware, and vulnerabilities among the events personnel must report, which would surface many password-cracking attempts or their artifacts once observed; it does not instrument or guarantee detection of the offline cracking activity itself.
- T1110.003detects — A.6.8 makes personnel aware of their responsibility (and the easy mechanism) to report observed events including access violations, suspected malware, anomalous behaviour, ineffective controls, and non-compliance; this surfaces some password-spraying attempts that personnel notice, but the technique is deliberately throttled and uses low-visibility protocols precisely to stay below human and alerting thresholds, so only a minority slice is caught.
- T1110.004detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus suspected malware or anomalous behaviour that would surface credential-stuffing attempts; this gives detection knowledge of the technique once attempted, but only through voluntary human reporting rather than automated instrumentation, leaving most automated or stealthy executions outside its scope.
- T1110.004prevents — A.6.8 makes personnel aware of their duty to report events including suspected malware, access violations, breaches of confidentiality/integrity/availability, and ineffective controls; timely reporting of a credential breach or anomalous login failures can trigger response that stops credential-stuffing attempts before they succeed, but this is only a slice of the technique (depends on human detection and action, does not block the attempt itself).
- T1110.004responds — A.6.8 requires personnel to report observed security events (including breaches, access violations, suspected malware, anomalous behaviour and ineffective controls) as soon as possible; credential-stuffing attempts produce exactly those observable signals (failed logins, lockouts, anomalous access patterns), so once the technique is underway the mandated reporting enables timely incident response.
- T1111detects — A.6.8 explicitly lists access violations, ineffective controls, suspected malware, anomalous behaviour and vulnerabilities among the events personnel must report, which directly surfaces many T1111 indicators (keyloggers, token capture, SMS compromise) once observed by users; it does not instrument or guarantee detection of the technique itself.
- T1112detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behaviour, access violations, suspected malware, and vulnerabilities; Registry modification for defense evasion/persistence can surface as one of those observable events if noticed by personnel, but most stealthy Registry changes (especially remote or hidden-key variants) produce no inherent alert and rely on optional human observation rather than mandated detection.
- T1113detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, and ineffective controls in the list of reportable events; screen-capture activity (especially via native utilities or RAT features) can surface as observable anomalous behaviour that personnel are instructed to report, but the control stops at enabling human reporting and does not itself instrument, monitor, or guarantee detection of the technique.
- T1114detects — A.6.8 requires awareness, easy mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'breaches of confidentiality', and 'ineffective controls' that would surface many T1114 realizations (e.g., anomalous forwarding rules or exfiltration), but does not mandate automated detection or cover stealthy collection from clients/servers outside user awareness.
- T1114.001detects — A.6.8 requires awareness and easy reporting of events including human errors, access violations, anomalous behaviour, malware, ineffective controls and suspected vulnerabilities; local email collection can surface as one of those observable events (e.g. anomalous file access or malware) and therefore be reported, but the clause does not mandate any automated detection mechanism and many stealthy instances will not be noticed by personnel.
- T1114.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour, which would surface many instances of credentialed Exchange/Office 365 email collection once noticed by personnel; it does not instrument or automatically surface the technique itself.
- T1114.003detects — A.6.8 explicitly lists access violations, ineffective controls, anomalous behaviour, suspected malware, and breaches of confidentiality expectations among the events personnel must report, which directly surfaces many (but not all) T1114.003 realisations once the forwarding rule is active and produces observable effects.
- T1115detects — A.6.8 requires awareness and easy reporting of events including human errors, access violations, anomalous behaviour, malware, and ineffective controls; clipboard data collection can surface as observable anomalous behaviour or suspected malware but is not required to be instrumented or monitored by the control itself.
- T1119detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective controls', 'anomalous system behaviour', 'access violations', 'suspected malware', and 'vulnerabilities' that would surface many automated collection artifacts or side-effects once they occur, but does not mandate any detection capability, monitoring, or analysis that would discover stealthy or silent instances of T1119.
- T1120detects — A.6.8 requires personnel to report observed events including ineffective controls, anomalous system behaviour, access violations, suspected malware, and vulnerabilities; peripheral device discovery can produce observable artifacts (e.g. anomalous USB enumeration, unexpected device logs) that fit those categories and would therefore surface via the mandated reporting mechanism, but the control depends on human observation rather than automated detection and leaves many stealthy discovery techniques unreported.
- T1123detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'anomalous system behaviour', 'access violations' and 'ineffective controls' as reportable events, which would surface many (but not all) T1123 realizations once observed by personnel; it does not instrument or automatically surface the technique itself.
- T1125detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'malfunctions or anomalous system behaviour', 'access violations' and 'ineffective controls' as reportable events; these surface T1125 once it is underway on monitored/observed systems, but only when personnel notice and report rather than via automated detection.
- T1127detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, anomalous system behaviour, malware infection, and ineffective controls — all of which can surface T1127 activity when observed by personnel; this is genuine but only a slice because the control is purely human-driven, depends on someone noticing and choosing to report, and has no instrumentation, alerting, or automated detection component.
- T1127.001detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, malware, access violations and ineffective controls; these can surface MSBuild abuse when observed, but the clause only enables voluntary human reporting and does not mandate any automated detection mechanism that would reliably catch the technique.
- T1127.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'vulnerabilities', 'anomalous system behaviour', and 'ineffective controls' as reportable events; these surface some (but not all) indicators of ClickOnce abuse such as unexpected child processes of DFSVC.EXE, anomalous .appref-ms/.application files, or user-execution popups, yet the clause stops at enabling human reporting and does not itself instrument or automate detection of the technique.
- T1127.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations and ineffective controls — all of which can surface JamPlus-based proxy execution when observed by personnel; this is genuine but only a slice, as the control depends on human recognition rather than automated instrumentation and does not reach silent or non-obvious abuse of a build tool.
- T1129detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behavior, access violations and ineffective controls, which can surface T1129 once the shared-module load has occurred and is observable by personnel; this is genuine detection but only a slice, as most in-process module loads (especially non-malicious-looking or automated ones) are not noticed or reported by people.
- T1132.001detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, ineffective controls, malware, and breaches; this surfaces encoded C2 traffic when observed as anomalous by personnel, but the clause is limited to human reporting and does not instrument or guarantee detection of the encoding technique itself.
- T1132.002detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behaviour, suspected malware, access violations and vulnerabilities; this surfaces some non-standard encoding in C2 traffic when observed as anomalous by personnel, but does not instrument or guarantee detection of the encoding technique itself.
- T1133detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour, which would surface many T1133 uses once noticed by personnel; it does not itself instrument or monitor for the technique.
- T1134detects — A.6.8 requires personnel to report observed events including access violations, ineffective controls, anomalous behaviour, suspected malware, and vulnerabilities; this surfaces some T1134 instances after the fact when noticed by users, but most token manipulation is silent, low-privilege, or non-obvious to humans and therefore outside the reporting mechanism.
- T1134.001detects — A.6.8 requires awareness and easy reporting of events including access violations, ineffective controls, anomalous behaviour, suspected malware, and vulnerabilities; token impersonation can surface as one of those observable events if noticed by personnel, but the control only enables reporting and does not itself perform detection.
- T1134.002detects — A.6.8 requires awareness and easy reporting of events including access violations, ineffective controls, anomalous behaviour, suspected malware, and vulnerabilities; these can surface T1134.002 when observed by personnel, but the control is limited to human-reported events and does not instrument or automatically detect the technique itself.
- T1134.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour, which would surface many T1134.003 instances once noticed; it stops short of any automated or continuous detection capability and depends on human recognition of the subtle token-creation artifact.
- T1134.005detects — A.6.8 requires awareness and easy reporting of events including access violations, ineffective controls, anomalous behaviour, and suspected malware; SID-History Injection produces observable indicators (e.g. anomalous privilege use, unexpected SID values, or lateral movement) that fit those categories and can therefore be reported, but the clause itself only enables detection via human reporting rather than mandating automated discovery or coverage of all instances.
- T1135detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, access violations, and suspected malware as reportable events; these can surface network share discovery when observed by personnel, but the control is limited to human-reported events and does not instrument or monitor for the technique itself.
- T1136detects — A.6.8 explicitly lists access violations, ineffective controls, non-compliance, anomalous behaviour and suspected malware as reportable events that personnel are trained to flag, which would surface many (but not all) instances of an adversary-created account once it is present and observable by users or monitoring.
- T1136.001detects — A.6.8 requires awareness and easy reporting of events including access violations, non-compliance, system changes outside process, and anomalous behaviour; these can surface local account creation when observed, but the control only enables voluntary human reporting of already-visible events and does not instrument or automatically detect the technique itself.
- T1136.002detects — A.6.8 requires awareness and easy reporting of events including access violations, non-compliant changes, anomalous behaviour and suspected malware, which would surface the creation of a rogue domain account if noticed by personnel; this is genuine but only a slice because the technique can be performed stealthily by an already-privileged adversary without triggering any of the listed observable situations for most users.
- T1136.003detects — A.6.8 explicitly lists access violations, non-compliance, ineffective controls, anomalous behaviour, and suspected vulnerabilities/malware as reportable events that personnel are trained to flag, which would surface many T1136.003 creations after the fact; it is limited to human-visible/observable events rather than automated detection of stealthy low-privilege cloud account creation.
- T1137detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, non-compliance, anomalous behaviour, access violations, suspected malware, and vulnerabilities, which would surface many T1137 abuse indicators if noticed by personnel; it does not itself instrument or monitor for the technique.
- T1137.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'human errors', 'non-compliance', 'access violations' and 'ineffective controls' that can surface anomalous Office macro behavior or unauthorized template changes after the fact; this is genuine but only a slice because the control is purely about personnel-initiated reporting of observed events and does not itself instrument, scan or monitor for the technique.
- T1137.001prevents — A.6.8 makes personnel aware of their duty to report events including human errors, non-compliance, access violations, suspected malware, and ineffective controls; this can surface and stop the macro-persistence technique before it is used at scale, but reporting is after-the-fact, depends on user recognition, and does not block the initial template modification or registry hijack.
- T1137.002detects — A.6.8 requires awareness and easy reporting of events including human errors, non-compliance, access violations, anomalous behaviour and suspected malware; these can surface Office Test Registry abuse after it occurs, but the control is personnel-driven rather than automated and many stealthy persistence changes go unreported.
- T1137.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, non-compliance, anomalous behaviour, access violations, and suspected malware as reportable events; this surfaces the T1137.003 technique when observed by personnel but only for the subset that triggers visible anomalies rather than the stealthy persistence itself.
- T1137.004detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'anomalous system behaviour', 'access violations' and 'vulnerabilities' in the list of reportable events; these surface the T1137.004 technique when observed by personnel, but only the human-observable slice (not the underlying registry/mailbox change itself) and only after the persistence is already present.
- T1137.005detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, non-compliance, access violations, malware, and anomalous behaviors that would surface the creation or triggering of malicious Outlook rules as a reportable event, but only if/when observed by personnel — it does not instrument or surface the technique autonomously.
- T1137.005responds — A.6.8 requires personnel to report security events (including malware, anomalous behavior, breaches, and access violations) as quickly as possible once identified, directly enabling the incident response process that contains and eradicates the persistence mechanism once the malicious rule is triggered by a crafted email.
- T1137.006detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'system changes that have not gone through the change management process', 'malfunctions or other anomalous system behaviour', and 'vulnerabilities' — all of which can surface add-in persistence when observed by personnel; this is a genuine but minority slice because most add-in installations are not overtly anomalous or user-visible at install time and the control stops at reporting (no guarantee of analysis or detection).
- T1140detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behavior, breaches, and vulnerabilities, which would surface many observable deobfuscation actions (e.g. certutil use, anomalous commands, or user-triggered execution) if noticed by personnel; it does not instrument or guarantee detection of all instances, especially stealthy or non-user-visible ones.
- T1176detects — A.6.8 explicitly lists reporting of vulnerabilities, ineffective controls, anomalous behaviour, malware, and access violations (all observable indicators that can surface a malicious or abused extension after installation), but the control is limited to awareness-driven human reporting rather than automated or systematic detection of the technique itself.
- T1176.001detects — A.6.8 explicitly lists suspected malware infection, access violations, ineffective controls, anomalous system behaviour, and vulnerabilities among the events personnel must report, which directly surfaces many (but not all) of the post-install behaviours, stealth modifications, and persistence mechanisms described for T1176.001; it does not instrument or surface the silent file-based installation techniques themselves.
- T1176.002detects — A.6.8 requires awareness and easy reporting of events including vulnerabilities, malware, anomalous behaviour, and breaches; this surfaces the technique once a user notices the suspicious extension or its effects, but only for the human-observable slice and not for stealthy or non-user-facing abuse.
- T1185detects — A.6.8 requires awareness and easy reporting of events including vulnerabilities, ineffective controls, anomalous behaviour, malware, and access violations; these surface many (but not all) T1185 realizations once the hijacking is underway or observed by personnel.
- T1187detects — A.6.8 explicitly lists access violations, suspected malware, anomalous behavior, and ineffective controls among the events personnel must report, which would surface many forced-authentication attempts once noticed; it is limited to what users actually observe and choose to report rather than automated or comprehensive detection.
- T1189detects — A.6.8 explicitly lists reporting of vulnerabilities, malware, anomalous behaviour, ineffective controls, breaches and human errors; these surface many (but not all) observable indicators of a drive-by compromise once the technique has executed on an endpoint.
- T1189responds — A.6.8 requires personnel to report observed events (including malware, anomalous behaviour, access violations, ineffective controls and suspected vulnerabilities) as quickly as possible so the organisation can contain and eradicate an incident once underway; this directly matches the `responds` verb on the event lane.
- T1190detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities plus anomalous/malfunction behaviors that surface public-facing exploits; this surfaces knowledge of the technique after it begins but only for events personnel actually notice and choose to report.
- T1190responds — A.6.8 makes personnel aware of the duty and easy mechanism to report events including vulnerabilities, ineffective controls, breaches, malware, and anomalous behaviour; once reported this feeds the incident response process that contains and eradicates an ongoing T1190 exploitation, but the control itself performs none of the containment/eradication actions and many T1190 cases (e.g. fully automated or zero-day against unmonitored edge devices) produce no reportable event observable by personnel.
- T1197detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behavior, access violations and ineffective controls; BITS abuse can surface as anomalous background jobs, suspected malware or policy violations that personnel are trained to report, but this is limited to human-observable indicators and does not instrument or automatically surface the stealthy, low-footprint technique itself.
- T1199detects — Rapid reporting of anomalous system behaviour and access violations can surface early indicators of an adversary leveraging a trusted third-party relationship before the foothold expands.
- T1200detects — A.6.8 requires awareness and easy reporting of events including breaches of physical security measures, access violations, anomalous hardware behaviour, and suspected malware, which would surface many (but not all) hardware additions once introduced and noticed by personnel
- T1201detects — A.6.8 requires awareness and easy reporting of events including access violations, ineffective controls, non-compliance, and suspected malware; password policy discovery is an observable precursor that can be treated as one of those event types once noticed, but the control only surfaces what personnel actually report and does not instrument or scan for the technique itself.
- T1202detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'malfunctions or other anomalous system behaviour', 'access violations', 'suspected malware infection', and 'ineffective information security controls' that can surface indirect command execution artifacts; this is genuine but only a slice because the control is personnel-driven, post-facto, and does not mandate automated detection of stealthy proxy utilities or WSL abuse.
- T1203detects — A.6.8 explicitly lists vulnerabilities, suspected malware, anomalous system behaviour, ineffective controls and access violations among the events personnel must report, which surfaces T1203 exploitation (or its immediate effects) once observed by a user; this is genuine but only a slice because most exploitation for client execution is designed to be silent, non-interactive and invisible to the end-user who is not expected to notice it before code runs.
- T1203responds — A.6.8 explicitly lists suspected malware, vulnerabilities, anomalous behaviour, ineffective controls and breaches as reportable events; once T1203 exploitation has occurred these become observable on the estate, triggering the reporting/response procedure that contains and eradicates the incident (the technique has run and its effects are addressed).
- T1204detects — Educating users to report suspected malware or unexpected file behaviour raises the likelihood that malicious user execution attempts are identified before the payload fully executes.
- T1204prevents — A.6.8 makes users aware of their duty to report events (including suspected malware, anomalous behaviour, breaches of policy, and access violations) quickly so the organisation can act before impact grows; this awareness and easy reporting channel can stop some social-engineering-driven user executions from completing or from leading to full compromise, but it does not stop the user from performing the initial action the adversary is soliciting.
- T1204responds — A.6.8 requires personnel to report observed events (including malware, anomalous behavior, breaches, and human-error execution of malicious code) so the organization can respond; this directly engages the containment/eradication steps of `responds` once T1204 has occurred, with the bounded remainder being fully automated or non-user-visible executions that produce no observable event for a person to report.
- T1204.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, suspected malware, access violations, and anomalous behaviour as reportable events, which would surface many (but not all) user clicks on malicious links once observed by personnel; it does not itself instrument or monitor for the technique.
- T1204.001prevents — A.6.8 makes personnel aware of their duty to report events (including suspected malware, anomalous behaviour, breaches, and vulnerabilities) quickly so the organisation can act before impact grows; this lowers the chance the malicious-link technique succeeds or spreads, but does not stop the user from clicking in the first place.
- T1204.001responds — A.6.8 requires personnel to report events (including malware, anomalous behavior, breaches, and suspected vulnerabilities) as quickly as possible once identified, enabling the incident response process that contains and eradicates the T1204.001 execution once underway; the named remainder is events that go entirely unobserved by any person.
- T1204.002detects — A.6.8 explicitly lists suspected malware infection, human errors, access violations, anomalous system behaviour, and ineffective controls among the events personnel must report, which would surface many (but not all) malicious-file executions once the user opens the file and follow-on effects appear
- T1204.002prevents — A.6.8 makes users aware of their duty to report events including suspected malware, anomalous behavior, and breaches, which can lead to rapid response that stops the malicious file from achieving execution in many cases, but does not stop the user action itself and leaves many delivery vectors (e.g., zero-day or non-reported openings) untouched.
- T1204.002responds — A.6.8 requires personnel to report events (including malware, anomalous behavior, breaches, and human-error openings of malicious files) as quickly as possible so the organization can contain and eradicate the incident once underway, which is exactly what `responds` names on the event lane.
- T1204.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of suspected malware, anomalous behavior, vulnerabilities, and ineffective controls, which would surface many T1204.003 events once noticed by personnel; it does not itself instrument or scan for the technique.
- T1204.004detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, non-compliance, suspected malware, anomalous behaviour, and access violations — all of which surface T1204.004 once the user realises something is wrong; it does not instrument or automatically surface the social-engineering trick itself.
- T1204.004responds — A.6.8 requires personnel to report events (including malware, anomalous behaviour, human errors, access violations, and suspected incidents) as quickly as possible once they occur; this directly engages the post-execution response activities (containment, eradication, evidence collection) once the user has pasted and run the malicious command.
- T1204.005detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behavior, vulnerabilities and ineffective controls; this surfaces knowledge of a realized T1204.005 installation after the fact, but only for events that personnel actually notice and choose to report rather than automated or comprehensive detection.
- T1205detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous system behaviour, access violations, suspected malware, and vulnerabilities; this surfaces some T1205 instances (e.g. anomalous packets or firewall changes) once observed by personnel, but does not instrument or guarantee detection of the stealthy signaling itself.
- T1205.001detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, access violations, malware, ineffective controls and suspected vulnerabilities, which would surface port-knocking attempts if observed by personnel; however the control is limited to human reporting channels and does not itself instrument or monitor for the low-level packet sequences or firewall changes described in the technique.
- T1205.002detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous system behaviour, malware, access violations and vulnerabilities; socket filter installation and passive activation can surface as one of those observable events if noticed by personnel, but the technique's stealth (no active socket until trigger, low overhead, raw socket invisibility) leaves most instances unreported.
- T1207detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective controls', 'access violations', 'vulnerabilities', 'suspected malware', and 'anomalous system behaviour' in the list of reportable events, which would surface many observable indicators of rogue DC registration or its downstream effects; however, the technique is explicitly designed to bypass logging/SIEM sensors and can delete metadata, so detection depends on whether personnel notice and report the precursor symptoms rather than automated coverage.
- T1210detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities plus anomalous/malfunction behaviors that would surface exploitation of remote services; this enables detection via human-reported events but only for the subset observable by personnel, not automated or silent exploitation.
- T1211detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities plus anomalous/malfunction behaviors that can surface exploitation attempts for stealth; this detects some T1211 instances (especially those generating observable events) but leaves the stealth/evasion core (no telemetry, hidden operation) mostly unreached.
- T1212detects — A.6.8 explicitly lists vulnerabilities and several exploitation-adjacent indicators (malfunctions/anomalous behaviour, access violations, ineffective controls, suspected malware) as reportable events that personnel are trained to surface, providing detection coverage once observed; it is partial because the control is awareness-driven and human-dependent rather than an automated or guaranteed mechanism, and many exploitation-for-credential-access cases (especially remote or low-and-slow) produce no observable event for a person to report.
- T1213.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective controls', 'breaches', 'human errors', 'non-compliance', 'access violations', 'vulnerabilities' and 'suspected malware' as reportable events; this surfaces many T1213.002 precursors (e.g. policy leaks, unsecured creds, anomalous access) once noticed by personnel, but does not instrument or automatically detect the repository mining itself.
- T1213.004detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations/vulnerabilities/malware as reportable events, which surfaces adversary mining of CRM data once noticed by personnel; it does not instrument or automatically detect the technique itself.
- T1213.005detects — A.6.8 explicitly lists reporting of ineffective controls, breaches, human errors, non-compliance, access violations, vulnerabilities, malware, and anomalous behaviour (including discussions of incident response), which would surface many T1213.005 indicators if messaged internally; it is limited to what personnel notice and choose to report rather than automated or comprehensive detection.
- T1216detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations and ineffective controls — all of which can surface T1216 proxy execution when observed by personnel; it does not itself instrument or guarantee detection of the technique.
- T1216.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'vulnerabilities', 'anomalous system behaviour' and 'breaches' in the list of reportable events; these surface knowledge of T1216.001 abuse when observed by personnel, but the control stops at reporting and does not itself instrument or analyze for the technique.
- T1216.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit coverage of anomalous system behaviour, suspected malware, access violations, and ineffective controls; these surface many instances of SyncAppvPublishingServer abuse when observed by personnel, but the control stops at reporting knowledge and does not itself instrument or analyse the technique.
- T1218detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behavior, malware, access violations and vulnerabilities, which would surface many (but not all) instances of proxy execution once observed by personnel.
- T1218.001detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behavior, breaches, and vulnerabilities, which would surface a CHM-based payload once observed by personnel; this is genuine but only a slice because the technique can execute silently without any user-visible event or human observer.
- T1218.002detects — A.6.8 requires personnel to report observed events including malware, anomalous behaviour, access violations, ineffective controls and suspected vulnerabilities, which would surface many (but not all) instances of control.exe abuse if noticed by users; the control itself supplies no instrumentation or automated detection.
- T1218.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations and ineffective controls — all of which surface CMSTP abuse when observed by personnel, but only after execution has begun and only for the subset of events that personnel actually notice and choose to report.
- T1218.003responds — A.6.8 requires personnel to report events (including malware, anomalous behavior, access violations, ineffective controls) once observed; this surfaces the CMSTP abuse in flight for incident response to contain/eradicate, which is exactly what `responds` names on the event lane.
- T1218.004detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'anomalous system behaviour', 'access violations' and 'ineffective controls' that can surface InstallUtil proxy execution when observed by personnel; this is genuine detection coverage but only a slice, as the technique is fileless, can be silent, and most instances will not produce a reportable event noticed by users.
- T1218.005detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'anomalous system behaviour', and 'vulnerabilities' in what personnel should report, which surfaces some mshta.exe abuse when it produces observable anomalies or is suspected; this is only a slice because most mshta executions (especially initial or stealthy ones) produce no reportable event without additional monitoring controls.
- T1218.005responds — A.6.8 requires personnel to report observed events (including malware, anomalous behaviour, access violations, ineffective controls) as soon as possible; once the mshta abuse has begun, reporting it triggers the incident-response process that contains and eradicates the actor's foothold.
- T1218.007detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations and ineffective controls; this can surface msiexec abuse after it occurs, but only when observed and voluntarily reported by personnel rather than through automated or guaranteed detection.
- T1218.008detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, and access violations, which would surface many (but not all) observable signs of odbcconf.exe abuse as an information security event
- T1218.009detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations and ineffective controls; this can surface the technique when observed by personnel but does not instrument or guarantee detection of the signed-binary proxy execution itself.
- T1218.010detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'anomalous system behaviour', and 'ineffective controls' that would surface observable indicators of Regsvr32 abuse (e.g. unexpected process behavior or proxy execution), but does not itself perform detection and leaves many stealthy or non-user-visible instances unreported.
- T1218.010responds — A.6.8 makes personnel the detection surface for anomalous system behaviour, suspected malware, access violations, ineffective controls and other observables that would be raised by a Regsvr32 Squiblydoo execution, then feeds those events into the incident-response process that contains and eradicates the actor's foothold once the technique is underway.
- T1218.011detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'anomalous system behaviour', 'access violations' and 'ineffective controls' that can surface rundll32.exe proxying when observed by personnel; this is genuine detection coverage but only a slice, as most T1218.011 executions are fileless, masqueraded, or occur without a human witness to report.
- T1218.012detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'anomalous system behaviour', 'access violations' and 'ineffective controls' that would surface many instances of verclsid.exe abuse as observable events, but does not itself perform detection and leaves many proxy-execution cases (especially those not yet flagged as anomalous) unreported.
- T1218.013detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'anomalous system behaviour', and 'ineffective controls' in its event list, which would surface many mavinject.exe abuse cases once observed; it does not itself instrument or monitor for the technique.
- T1218.014detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations and ineffective controls — all of which can surface MMC abuse when observed by personnel; it does not itself instrument or guarantee detection of the technique.
- T1218.015detects — A.6.8 explicitly lists suspected malware infection, anomalous system behaviour, access violations, and ineffective controls among the events personnel must report, which would surface many (but not all) realisations of Electron abuse such as unexpected child processes or planted JS; it does not instrument or guarantee discovery of every stealthy instance.
- T1219detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'anomalous system behaviour', and 'breaches' in the list of reportable events; these surface post-compromise use of remote access tools when observed by personnel, but the control is limited to human-reported events and does not instrument or guarantee detection of stealthy RAT usage.
- T1219responds — A.6.8 requires personnel to report events (including malware, anomalous behavior, access violations, and EDR-abuse indicators) as quickly as possible so the organization can contain and eradicate an ongoing T1219 session once it is underway.
- T1219.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations and ineffective controls — all of which can surface IDE tunneling when observed by personnel; it does not itself instrument or monitor for the technique.
- T1219.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations and ineffective controls, which would surface many legitimate-desktop-support C2 sessions once noticed; it does not itself instrument or monitor for the technique.
- T1219.003detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous system behaviour, physical security breaches, access violations and suspected malware; hardware KVM installation or anomalous remote sessions can surface as one of those observable events if personnel notice it, but most of the technique (physical insertion and post-compromise C2) is invisible to users and therefore unreported.
- T1220detects — A.6.8 requires personnel to report observed events including anomalous system behaviour, suspected malware, access violations, and vulnerabilities; these can surface XSL script processing when noticed, but most instances (especially remote/Squiblytwo or file-extension-obfuscated) go unseen by users and the clause contains no instrumentation or automated detection.
- T1221detects — A.6.8 requires personnel to report observed events including ineffective controls, anomalous behavior, suspected malware, access violations and vulnerabilities; this surfaces some post-execution or post-delivery indicators of T1221 (e.g. anomalous document behavior or suspected malware) but does not instrument or surface the template-reference injection itself, which is the core of the technique.
- T1222.001detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, access violations, policy non-compliance, anomalous behaviour and suspected malware; these surface many (but not all) T1222.001 instances once performed, yet the clause stops at reporting and does not itself instrument or analyse for the technique.
- T1222.002detects — A.6.8 requires personnel to report observed events including ineffective controls, access violations, anomalous behaviour, suspected malware, and vulnerabilities; an adversary using chmod/chown to alter permissions can produce observable indicators (e.g. anomalous permission changes, access violations, or ineffective ACLs) that fall inside the listed reportable situations and are therefore surfaced when reported.
- T1482detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behavior, access violations, and suspected malware; domain trust enumeration via API/LDAP/Nltest can surface as anomalous behavior or access probing and would therefore be reportable, but the clause is silent on automated detection and only surfaces what personnel happen to notice and choose to report.
- T1484detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations, ineffective controls, policy non-compliance, anomalous behaviour, and suspected malware as reportable events; these surface many T1484 indicators (e.g. unexpected GPO/trust/federation changes) once noticed by personnel, but the control stops at reporting and does not itself instrument or analyse for stealthy or reverted modifications.
- T1484.001detects — A.6.8 requires personnel to report observed events including ineffective controls, access violations, anomalous behaviour, non-compliance and suspected malware; these overlap some observable indicators of GPO modification (e.g. unexpected SYSVOL writes, anomalous GPO changes, privilege anomalies) but miss stealthy or automated modifications that produce no user-visible cue, so detection is a genuine but minority slice.
- T1484.002detects — A.6.8 explicitly lists access violations, ineffective controls, non-compliance, anomalous behaviour, and suspected vulnerabilities as reportable events that personnel are trained to flag, which would surface many trust modifications once noticed; it stops short of automated or comprehensive detection and excludes stealthy changes that evade human observation.
- T1485detects — A.6.8 explicitly lists human errors, non-compliance, access violations, ineffective controls, anomalous behaviour, suspected malware, and vulnerabilities as reportable events that personnel must flag, which surfaces many T1485 precursors or early indicators (especially insider/worm-like propagation); it does not instrument or surface the actual overwrite/deletion itself once executed at scale.
- T1485responds — A.6.8 requires personnel to report events including malware, anomalous behaviour, breaches of availability, ineffective controls and access violations; once reported these feed directly into the incident response process that contains and eradicates an in-progress data-destruction campaign (the technique is already running when the observable events occur).
- T1485.001detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, non-compliance, access violations, anomalous behaviour, and suspected malware; a lifecycle policy change that destroys data would surface as one of those observable events if noticed by personnel, but the control only surfaces knowledge via human reporting and does not instrument or guarantee detection of the API-driven technique itself.
- T1486detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'ineffective controls', 'anomalous system behaviour', and 'vulnerabilities' in what must be reported, which surfaces many ransomware precursors or early signs (e.g., anomalous encryption activity or malware) once observed by personnel; it does not instrument or automatically detect the technique itself.
- T1486recovers — A.6.8 makes personnel aware of the responsibility and easy procedure to report events including malware, anomalous behaviour, breaches of availability, and suspected ransomware-like encryption; timely reporting enables the incident response process that performs recovery (e.g. from backups), exactly as the event-lane recovers anchor grades A.8.13 vs T1486.
- T1486responds — A.6.8 makes personnel aware of their responsibility to report events (including malware, anomalous behaviour, breaches of availability, and suspected incidents) quickly via an easy mechanism so that response can begin; this directly matches the `responds` verb of acting once the ransomware technique is underway to contain/eradicate it, with the named remainder being fully automated or silent infections that evade human detection/reporting.
- T1489detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective controls', 'anomalous system behaviour', 'access violations', 'suspected malware', and other observable precursors that would surface service-stop activity once noticed by personnel; this is genuine detection coverage but only a slice, as most T1489 executions (especially automated, cloud API, or stealthy variants) are not guaranteed to produce a reportable human-visible event and fall outside the clause's personnel-focused scope.
- T1490detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective information security controls', 'breaches of physical security measures', 'malfunctions or anomalous system behaviour', 'access violations', and 'suspected malware infection' as reportable events; these surface many T1490 actions (e.g. vssadmin deletion, bcdedit changes, snapshot removal) once performed, but the clause stops at reporting and does not require automated detection or coverage of all platforms/variants (e.g. cloud policy changes).
- T1491detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, integrity breaches, human errors, anomalous behaviour, access violations and suspected malware, which would surface many (but not all) observable signs of defacement once it has occurred.
- T1491.001detects — A.6.8 explicitly lists human errors, non-compliance, access violations, anomalous system behaviour, ineffective controls and breaches of integrity expectations as reportable events; internal defacement matches several of these observable symptoms and would therefore surface via the mandated reporting mechanism, but the clause is silent on automated detection, covers only what personnel notice and choose to report, and excludes the post-compromise stealthy timing noted in the T1491.001 description.
- T1491.001responds — A.6.8 makes personnel aware of the responsibility and easy procedure to report observed events including human errors, anomalous behaviour, access violations, ineffective controls and breaches of integrity expectations; this directly enables the containment/eradication steps of incident response once internal defacement (a realised integrity breach) is noticed, but the clause stops at reporting and does not itself perform response actions.
- T1491.002detects — A.6.8 requires awareness and easy reporting of events including breaches of integrity, access violations, anomalous behaviour, ineffective controls and suspected malware, which would surface external defacement once noticed by personnel; it does not itself instrument or monitor for the technique.
- T1496detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, malware infection, ineffective controls, and access violations, which would surface many resource-hijacking manifestations (e.g. cryptomining CPU spikes, unexpected proxy traffic) once noticed by personnel; it does not instrument or guarantee detection of stealthier cases.
- T1496.001detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, ineffective controls and breaches of availability; this surfaces compute hijacking (esp. via symptoms like high resource use or competing-malware kills) once it is underway, but only if personnel notice and report rather than through automated means, leaving most stealthy or non-obvious cases unreached.
- T1496.001responds — A.6.8 requires personnel to report observed events (including anomalous system behaviour, malware, ineffective controls, and availability breaches) so the organisation can respond; this surfaces compute hijacking once underway but does not itself contain or eradicate it.
- T1496.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, malware infection, ineffective controls, and availability breaches, which would surface many bandwidth-hijacking events once noticed; it does not itself instrument or monitor to discover them proactively, leaving the bulk of detection to other controls.
- T1496.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, ineffective controls, anomalous behaviour, and breaches that would surface SMS-pumping indicators (e.g. sudden SMS volume spikes or cost anomalies) once observed by personnel, but does not itself instrument or monitor for them.
- T1496.004detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective controls', 'breaches of confidentiality/integrity/availability', 'access violations', 'suspected malware', and 'anomalous system behaviour' in the list of reportable events; these surface many T1496.004 realisations (e.g. quota exhaustion, unexpected service enablement, anomalous LLM/proxy behaviour) once noticed by personnel, but the control stops at reporting and does not itself instrument or analyse for the technique.
- T1498detects — A.6.8 requires awareness, easy mechanisms, and explicit inclusion of 'ineffective information security controls', 'malfunctions or other anomalous system behaviour', 'breaches of availability expectations', and 'suspected malware' in what must be reported, which surfaces many Network DoS manifestations once underway; it does not instrument, monitor, or guarantee detection of the attack itself.
- T1498responds — A.6.8 requires personnel to report observed events (including anomalous behaviour, ineffective controls, availability breaches and suspected malware) as quickly as possible so that response actions can be taken; this directly engages the containment/eradication steps of an in-progress Network DoS once it is noticed by users or monitoring, though pre-compromise reconnaissance and the bandwidth-exhaustion impact itself sit outside the reporting act.
- T1498.001detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous system behaviour, access violations, suspected malware, and breaches of availability expectations; a direct network flood is observable as anomalous traffic or availability impact and would be reported once noticed, but the control only surfaces it after the fact via human reporting and does not itself instrument or monitor for the flood.
- T1498.001responds — A.6.8 makes personnel the detection surface for anomalous system behaviour, malfunctions, ineffective controls and suspected incidents (including availability-impacting floods), triggering the incident-response process that contains and eradicates the attack once underway; the named remainder is fully automated floods that produce no observable human-visible artefact before impact is realised.
- T1498.002detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous system behaviour, access violations, vulnerabilities and suspected malware; this surfaces some observable precursors or indicators of a reflection amplification (e.g. anomalous traffic or vulnerable reflectors) once they are noticed by personnel, but does not instrument or guarantee detection of the attack itself.
- T1498.002responds — A.6.8 makes personnel aware of the responsibility and easy mechanism to report security events (including anomalous system behaviour, ineffective controls, availability breaches and suspected malware), which directly enables the detection-and-response workflow once a reflection amplification flood is observed underway.
- T1499detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous system behaviour, access violations, suspected malware, and breaches of availability expectations; this surfaces many Endpoint DoS manifestations after they begin, but the clause stops at reporting and does not itself instrument or analyse for the attack.
- T1499responds — A.6.8 makes personnel the detection surface for anomalous system behaviour, malfunctions, ineffective controls and suspected malware that are the observable precursors or in-flight indicators of Endpoint DoS; once reported the incident-response process (A.5.26) can contain and eradicate, satisfying the verb at the event-already-underway rung.
- T1499.001detects — A.6.8 requires personnel to report observed anomalous system behaviour, malfunctions, ineffective controls, access violations and suspected malware — which can surface an OS-exhaustion flood once it is underway and noticeable to users or admins; this is genuine but only a slice, as the technique can be launched remotely at network scale with no local human-visible indicator before impact, and the control itself performs no instrumentation or automated detection.
- T1499.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'malfunctions or other anomalous system behaviour' plus 'ineffective information security controls' in the list of reportable events, which would surface many service-exhaustion floods once they manifest as observable anomalies; it does not instrument or guarantee detection of the technique itself.
- T1499.002responds — A.6.8 makes personnel aware of the responsibility and easy procedure to report security events (including anomalous behaviour, access violations, ineffective controls, suspected malware, and breaches of availability expectations), which directly enables the detection-triggered response process once a service-exhaustion flood is underway; it stops short of performing containment/eradication itself.
- T1499.003detects — A.6.8 requires awareness, easy mechanisms, and explicit inclusion of anomalous system behaviour, malfunctions, ineffective controls, and access violations in the list of reportable events, which would surface many application-exhaustion floods once they manifest as observable anomalies; it does not instrument or guarantee detection of the technique itself, especially pre-impact or in unmonitored layers.
- T1499.004detects — A.6.8 explicitly lists vulnerabilities, malfunctions/anomalous behaviour, ineffective controls and suspected malware as reportable events that personnel must flag, which surfaces exploitation attempts or their immediate effects once observed; it is only partial because the clause relies on human awareness and voluntary reporting rather than any automated detection mechanism and does not reach stealthy or zero-day crashes that produce no observable anomaly.
- T1499.004responds — A.6.8 mandates timely reporting of events including ineffective controls, anomalous behaviour, vulnerabilities, suspected malware and breaches so that an incident response process can be triggered once the exploitation is underway, which is exactly what `responds` names; the named remainder is events that go entirely unreported.
- T1505detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities plus anomalous system behaviour (which covers malicious server components once noticed), but does not itself perform detection — it surfaces events only after human recognition, leaving most stealthy installations undetected until impact or separate monitoring.
- T1505.002detects — A.6.8 explicitly lists suspected malware infection, access violations, anomalous system behaviour, ineffective controls, and non-compliance as reportable events that personnel are trained to flag, which would surface a maliciously registered or invoked transport agent; the remainder is stealthy agents that trigger only on narrow adversary criteria and produce no observable anomaly.
- T1505.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, suspected malware, anomalous behaviour, and ineffective controls — all of which surface web-shell indicators when observed by personnel; it does not itself instrument or scan for the technique.
- T1505.003responds — A.6.8 mandates awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, malware, anomalous behaviour, and ineffective controls; once a web shell (or its indicators) is noticed it triggers the incident-response pipeline that contains and eradicates the persistent backdoor.
- T1505.004detects — A.6.8 explicitly lists suspected malware infection, access violations, anomalous system behaviour, ineffective controls and vulnerabilities among the events personnel must report, which would surface many (but not all) post-installation indicators of a malicious IIS component; the control stops at awareness/reporting and does not itself instrument or analyse for the technique.
- T1505.005detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behavior, access violations, vulnerabilities, and ineffective controls; this surfaces the DLL modification or replacement once observed by personnel, but the technique is a low-observable persistence change unlikely to be noticed without specific monitoring or scanning, leaving most instances undetected.
- T1505.006detects — A.6.8 requires personnel to report observed events including anomalous system behaviour, malware, access violations, ineffective controls and suspected vulnerabilities; this surfaces some post-installation indicators of a malicious VIB (e.g. unexpected listeners, firewall changes or anomalous boot behaviour) but does not instrument or guarantee detection of the VIB installation itself or its masquerading, leaving most of the technique unseen until effects manifest.
- T1518detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behavior, vulnerabilities, suspected malware, and access violations; these can surface Software Discovery when observed as an anomalous action or vulnerability probe, but the clause is personnel-driven rather than automated monitoring and does not guarantee detection of stealthy or non-reported instances.
- T1518.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective information security controls', 'malfunctions or anomalous system behaviour', 'suspected malware infection', and 'vulnerabilities' as reportable events, which would surface many instances of security-software discovery when observed by personnel; it does not instrument or guarantee automated detection of the technique itself.
- T1518.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective controls', 'anomalous system behaviour', 'vulnerabilities', and 'suspected malware' that would surface backup-software discovery activity if observed and reported by personnel.
- T1525detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, anomalous system behaviour, malware infection, and ineffective controls; these surface the post-implant image (or its use) when observed by personnel, but do not instrument or guarantee discovery of the registry implant itself.
- T1526detects — A.6.8 makes personnel aware of their responsibility (and the easy mechanism) to report observed events including ineffective controls, anomalous behaviour, access violations, suspected malware, and vulnerabilities; this surfaces knowledge of T1526 when a human notices the enumeration activity or its artifacts, but only for the human-observable slice and only after the fact.
- T1528detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus suspected vulnerabilities/malware as reportable events, which can surface token theft once observed by personnel; however, many stealthy technical paths (container compromise, IMDS requests, OAuth phishing without user suspicion) produce no observable event for personnel to report, leaving detection dependent on voluntary human observation rather than systematic instrumentation.
- T1529detects — A.6.8 requires awareness and easy reporting of events including malfunctions/anomalous behaviour, ineffective controls, breaches of availability expectations, and suspected malware — all of which can surface a shutdown/reboot when observed by personnel, but the control stops at reporting (no monitoring or automated detection) and many T1529 vectors (API, privilege escalation, remote CLI, post-wipe) produce no observable event for a person to report.
- T1530detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations, ineffective controls, breaches of confidentiality, and vulnerabilities, which would surface many T1530 realisations (misconfigs, public buckets, leaked creds) once observed by personnel; it does not instrument or automatically detect the technique itself.
- T1531detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous behavior as reportable events, which surfaces T1531 once observed by personnel; it does not instrument or automatically detect the technique itself.
- T1531responds — A.6.8's purpose and guidance exist to drive timely reporting of events (including access violations, account manipulations, ineffective controls, anomalous behaviour and suspected malware) so they can be actioned; once T1531 is underway this feeds directly into the incident response workflow that contains and eradicates the actor's changes.
- T1534detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, access violations, suspected malware, ineffective controls, and non-compliance as reportable events; these surface many (but not all) observable indicators of an internal spearphishing campaign once it reaches users, without guaranteeing detection of every delivery vector or pre-compromise staging.
- T1534prevents — A.6.8 makes personnel aware of their duty to report events (including suspected malware, access violations, breaches of confidentiality/integrity, and anomalous behaviour) quickly so effects can be minimised; this can interrupt the multi-staged internal spearphishing campaign before further compromise or payload delivery succeeds, but only for the subset of realisations that users actually notice and report rather than the initial credential/device compromise or stealthy delivery vectors.
- T1534responds — A.6.8 makes personnel the detection surface for the phishing campaign (human errors, anomalous behaviour, suspected malware, access violations, breaches of confidentiality) and explicitly feeds those events into the incident response process that contains and eradicates the internal spearphishing once underway.
- T1535detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective information security controls', 'malfunctions or anomalous system behaviour', 'access violations', and 'suspected malware infection' (among others) that would surface creation and operation of instances in unused/unmonitored regions; this is genuine but only a slice because the control is purely personnel-driven reporting with no instrumentation, automated discovery, or coverage of silent/undetected region activity.
- T1537detects — A.6.8 explicitly lists several detectable precursors to T1537 (access violations, ineffective controls, anomalous behaviour, suspected malware, non-compliance) and requires personnel to report them quickly via an easy mechanism, which surfaces the technique when those indicators are noticed; it is only partial because the control depends on human observation rather than automated monitoring and does not address stealthy internal cloud-account transfers that blend with normal API traffic.
- T1538detects — A.6.8 requires awareness, easy mechanisms, and explicit inclusion of access violations plus anomalous behaviour in the list of reportable events; this surfaces the T1538 technique when a legitimate user or admin notices and reports the anomalous dashboard use, but only if observed by personnel (not the system itself) and only for the subset of realisations that cross a human-visible threshold.
- T1539detects — A.6.8 requires personnel to report observed events including malware, anomalous behaviour, access violations, ineffective controls and suspected vulnerabilities, which would surface many local-browser or malware-based instances of T1539 after they occur; it does not instrument or surface the stealthier network/proxy/AiTM vectors or the post-theft use of the cookie.
- T1539responds — A.6.8 requires personnel to report observed events (including malware, access violations, anomalous behaviour, breaches of confidentiality/integrity, and suspected vulnerabilities) once they occur; this surfaces T1539 artifacts (e.g. cookie theft via malware, JS injection, or phishing) for incident response containment and eradication while the technique is underway.
- T1542.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities plus anomalous system behaviour (which covers firmware modification indicators), enabling detection via human-reported events; partial because it depends on personnel noticing and reporting rather than automated or guaranteed discovery of stealthy firmware changes.
- T1542.003detects — A.6.8 explicitly lists suspected malware infection, anomalous system behaviour, ineffective controls, and vulnerabilities among the events personnel must report, which can surface a bootkit once it produces observable symptoms; this is genuine but only a minority slice because bootkits execute before the OS and commonly evade user-visible indicators until after persistence is achieved.
- T1542.004detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, anomalous system behaviour, ineffective controls, and suspected malware as reportable events; this surfaces knowledge of a ROMMONkit implant once observed by personnel, but only for the human-visible slice (not autonomous detection) and leaves the 'difficult to detect' stealth property named in the technique as a bounded remainder.
- T1542.005detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, malfunctions, access violations, and suspected malware as reportable events; these surface T1542.005 activity once observed by personnel, but only the human-observable slice (not automated network-device boot sequences or silent config changes), making the coverage a chosen implementation slice rather than a bounded remainder.
- T1543detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous system behaviour, malware, access violations and vulnerabilities; this surfaces T1543 when observed by personnel but does not instrument or guarantee discovery of the technique itself.
- T1543.001detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behavior, access violations, and ineffective controls; this can surface a Launch Agent persistence technique once observed by personnel, but only for the subset of cases that produce noticeable indicators (most stealthy or disguised agents produce none).
- T1543.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, malware, access violations, and vulnerabilities, which would surface many systemd service creations/modifications if noticed by personnel; it does not itself instrument or monitor for the technique.
- T1543.002responds — A.6.8 explicitly lists anomalous system behaviour, malware infection, access violations, ineffective controls and non-compliance as reportable events; once the malicious systemd service runs, these observables trigger the reporting/response pipeline the control mandates.
- T1543.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'anomalous system behaviour', 'access violations', 'ineffective controls' and 'vulnerabilities' in the list of reportable events; these surface many T1543.003 artifacts (new/changed services, hidden/masquerading services, driver loads) once observed by personnel, but the control stops at reporting and supplies no instrumentation, so only the human-observable slice is covered.
- T1543.003responds — A.6.8 requires personnel to report observed events (including anomalous system behaviour, malware, access violations, ineffective controls) once they notice them, which matches the containment/eradication act of `responds` once the service-creation technique is underway and observable; it does not act on the technique itself and leaves many stealthy or automated instances unreported.
- T1543.004detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'malfunctions or anomalous system behaviour', 'access violations', and 'ineffective controls' in the list of reportable events; these surface the technique or its artifacts once present, but only if personnel notice and choose to report them, leaving the bulk of stealthy or automated daemon launches undetected by this awareness-and-reporting control alone.
- T1543.005detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations, and ineffective controls, which would surface many T1543.005 manifestations once observed by personnel; it does not instrument or guarantee discovery of stealthy container daemon/service modifications that evade human notice.
- T1546detects — A.6.8 makes personnel aware of their responsibility (and the easy mechanism) to report a broad list of observable events that explicitly includes access violations, anomalous system behaviour, suspected malware, ineffective controls, and human errors — many of which are the observable manifestations or by-products of an adversary creating or invoking a T1546 event trigger; this surfaces knowledge of the technique after it has run, but only when a human notices and chooses to report, which is a genuine but minority slice of the technique's possible executions.
- T1546responds — A.6.8 makes personnel report observed events (including anomalous behavior, malware, access violations, and ineffective controls) so the organization can respond; this surfaces T1546 once it has run and is observable, satisfying the `responds` verb at the detection-to-handling boundary, but only a slice of T1546 executions are noticed by users rather than stealthily.
- T1546.001detects — A.6.8 explicitly lists human errors, non-compliance, access violations, anomalous system behaviour, and suspected malware as reportable events that personnel are trained to recognise and report, which would surface many (but not all) T1546.001 realisations once the modified association is triggered; the control does not instrument or surface the registry change itself before execution.
- T1546.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'anomalous system behaviour', 'access violations' and 'ineffective controls' as reportable events; these surface the screensaver persistence technique once it has executed and is observable by users, but the clause stops at reporting (no monitoring or automated detection) and many technique artifacts (registry changes, inactive-trigger execution) remain invisible to end users.
- T1546.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations, and vulnerabilities, which would surface many observable signs of a WMI event subscription (e.g. anomalous WmiPrvSe.exe behaviour or new subscriptions), but does not mandate any automated detection and leaves coverage dependent on whether personnel actually notice and report the specific indicators.
- T1546.003responds — A.6.8's purpose and guidance require personnel to report events (including anomalous behaviour, malware, access violations, ineffective controls) as quickly as possible so incidents can be contained/eradicated once underway; T1546.003's anomalous WMI subscription, SYSTEM-level execution and persistence are reportable events that trigger the response procedure.
- T1546.004detects — A.6.8 explicitly lists human errors, non-compliance, system changes outside change management, anomalous system behaviour, access violations, suspected malware, and vulnerabilities as reportable events; these overlap with observable indicators of T1546.004 (e.g. unexpected shell config changes or anomalous commands), but the control is limited to awareness-driven human reporting rather than automated detection and does not reach stealthy or non-obvious modifications.
- T1546.005detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations, and ineffective controls, which would surface trap-based persistence when observed as anomalous; this is only a slice because the control depends on human recognition/reporting rather than automated detection and does not reach all stealthy or non-anomalous uses.
- T1546.006detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations and ineffective controls; these can surface LC_LOAD_DYLIB additions once observed, but the control itself only enables human reporting and supplies no instrumentation or automated detection of the binary-header modification.
- T1546.007detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, malware, access violations and ineffective controls; these can surface Netsh Helper DLL persistence when observed, but the control depends on personnel noticing and reporting rather than any automated or guaranteed detection of the registry-based technique.
- T1546.008detects — A.6.8 requires awareness and easy reporting of events including human errors, non-compliance, access violations, anomalous behaviour, and suspected malware; these can surface T1546.008 when the modification or anomalous login-screen behaviour is noticed by personnel, but most instances (especially pre-login or remote) remain invisible to users and the clause does not mandate any automated detection.
- T1546.009detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'ineffective controls', 'anomalous system behaviour' and 'vulnerabilities' as reportable events, which would surface many (but not all) observable signs of an AppCert DLL being abused for persistence or privilege escalation once it is active.
- T1546.010detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behavior, access violations and ineffective controls, which would surface AppInit DLL abuse once observed by personnel, but does not itself instrument or monitor for the technique.
- T1546.011detects — A.6.8 explicitly lists suspected malware infection, anomalous system behaviour, access violations, ineffective controls and non-compliance as reportable events; these overlap with observable indicators of shim abuse (e.g. unexpected DLL injection, privilege-elevation side-effects, persistence via hijacked binaries), so the control surfaces knowledge of the technique once it is noticed by personnel, but only for the subset of cases that produce visible anomalies rather than stealthy shim installation or execution.
- T1546.012detects — A.6.8 requires awareness and easy reporting of events including human errors, non-compliance, access violations, anomalous behaviour, malware infection and vulnerabilities; these overlap some observable indicators of IFEO abuse (e.g. unexpected registry changes, anomalous process launches, suspected malware) but do not mandate any automated or systematic detection mechanism, leaving most stealthy or post-execution instances unreported.
- T1546.013detects — A.6.8 explicitly lists human errors, non-compliance, access violations, system changes outside change management, anomalous behaviour, suspected malware, and vulnerabilities as reportable events; a modified PowerShell profile would surface under several of those categories once observed by personnel, but the control only surfaces what people notice and report and supplies no instrumentation or automated detection.
- T1546.014detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'anomalous system behaviour', 'ineffective controls' and 'vulnerabilities' in the list of reportable events; these surface emond rule abuse when observed by personnel, but the control only enables human reporting of already-visible symptoms and does not instrument or surface the underlying rule placement or daemon trigger itself.
- T1546.015detects — A.6.8 explicitly lists reporting of ineffective controls, anomalous system behaviour, access violations, suspected malware, and vulnerabilities; COM hijacking produces all of these observable signals that personnel could report, but the control only surfaces them if users notice and report, leaving the bulk of stealthy Registry-based persistence undetected without additional monitoring.
- T1546.016detects — A.6.8 requires personnel to report observed events including malware, anomalous behaviour, access violations, ineffective controls and suspected vulnerabilities; this surfaces installer-script abuse after execution or during installation but only when noticed by a human, leaving the bulk of stealthy or automated abuse undetected.
- T1546.017detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations, and vulnerabilities, which would surface udev rule abuse once observed by personnel; this is a genuine but minority slice because most udev-rule persistence is not directly observable by end-users or without prior instrumentation.
- T1546.017responds — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations and ineffective controls; once the udev-triggered malicious execution is underway this surfaces it as an incident for response, but the control stops at reporting and does not itself contain or eradicate.
- T1546.018detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'anomalous system behaviour', 'access violations' and 'vulnerabilities' in the list of reportable events; these surface the technique when observed by personnel, but the control is silent on automated detection, covers only what humans notice and choose to report, and does not address stealthy or post-persistence execution.
- T1547detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, anomalous system behaviour, access violations, suspected malware, and ineffective controls — all of which can surface T1547 artifacts after the fact; it does not instrument or guarantee detection of the technique itself, leaving most stealthy or non-user-visible cases unreached.
- T1547.001detects — A.6.8 explicitly lists suspected malware infection, anomalous system behaviour, access violations, and ineffective controls among the events personnel must report, which would surface many (but not all) T1547.001 artifacts once they are present and observable by a user or admin.
- T1547.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'anomalous system behaviour', and 'ineffective controls' in the list of reportable events; these can surface T1547.002 once it has run and produced observable effects, but the control stops at enabling human reporting and does not itself instrument or analyze for the technique.
- T1547.003detects — A.6.8 requires personnel to report observed events including anomalous system behaviour, suspected malware, access violations and ineffective controls; these can surface a time-provider persistence implant at runtime, but the control depends on human observation rather than automated detection and does not guarantee coverage of stealthy or pre-execution registration.
- T1547.004detects — A.6.8 explicitly lists human errors, non-compliance, access violations, system changes outside change management, anomalous behaviour, and suspected malware as reportable events; these overlap some observable indicators of a Winlogon Helper DLL modification, but the control only surfaces knowledge via voluntary personnel reporting and does not instrument or guarantee discovery of the registry abuse itself.
- T1547.005detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'anomalous system behaviour', 'ineffective controls' and 'vulnerabilities' in the list of reportable events, which would surface many SSP abuses post-boot; this is limited to a slice because the control is purely personnel-driven (no instrumentation, no automated detection of Registry changes or LSA loading) and many adversary actions occur silently at boot before any human observes them.
- T1547.006detects — A.6.8 requires personnel to report observed anomalous system behaviour, suspected malware, access violations, ineffective controls and vulnerabilities; kernel module loading (especially unsigned or rootkit-like) can surface as one of those observables and therefore be reported, but the control supplies no mechanism that actually finds the technique and most instances (silent kernel tampering, hidden LKMs) remain undetected without additional tooling.
- T1547.007detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'anomalous system behaviour', and 'ineffective controls' in the list of reportable events, which would surface T1547.007 if observed by personnel; this is only a slice because the technique is a silent plist modification with no guaranteed observable symptom at the moment of execution.
- T1547.008detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behavior, access violations, ineffective controls and vulnerabilities; this surfaces LSASS driver tampering once observed by personnel but does not instrument or guarantee discovery of the stealthy persistence technique itself.
- T1547.009detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behavior, access violations, ineffective controls and human errors; these can surface shortcut-modification persistence when observed, but the control supplies no mechanism or scope guarantee that the technique itself will be noticed before or during execution.
- T1547.010detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'ineffective controls', 'anomalous system behaviour' and 'vulnerabilities' in the list of reportable events, which would surface many observable signs of a port monitor being installed or running; however, the control is purely about personnel-driven reporting of noticed events and does not itself instrument, monitor, or guarantee discovery of stealthy registry/API abuse.
- T1547.012detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behavior, access violations, and ineffective controls; this surfaces the technique once observed by personnel but does not instrument or guarantee detection of the boot-time DLL load itself.
- T1547.013detects — A.6.8 requires awareness and easy reporting of events including human errors, non-compliance, access violations, anomalous behaviour, malware and vulnerabilities; these surface many (but not all) indicators of an XDG Autostart persistence modification once it has occurred.
- T1547.014detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'anomalous system behaviour', and 'ineffective controls' as reportable events; these surface T1547.014 once the malicious Active Setup execution or Registry change is noticed by personnel, but the control itself only enables human-driven detection of a narrow, post-execution slice rather than any automated or comprehensive coverage of the persistence technique.
- T1547.015detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'anomalous system behaviour', and 'ineffective controls' in the list of reportable events; these surface some T1547.015 artifacts post-execution on macOS but the clause sets scope by awareness rather than mandating instrumentation that would catch the technique in all cases (e.g., stealthy Service Management Framework login items).
- T1548detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus ineffective controls or anomalous behaviour that would surface many T1548 instances once observed by personnel; it does not instrument or automatically surface the technique itself.
- T1548.001detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, access violations, anomalous behaviour, vulnerabilities and suspected malware; these overlap some observable indicators of setuid/setgid abuse (e.g. unexpected privilege-changing binaries or anomalous execution), but the control stops at enabling human reporting and does not itself perform or guarantee detection.
- T1548.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour as reportable events, which would surface many UAC-bypass techniques once observed by personnel; it does not itself instrument or guarantee detection of the bypasses that are silent or occur without user-visible anomaly.
- T1548.003detects — A.6.8 explicitly lists access violations, ineffective controls, non-compliance, suspected malware, and anomalous behaviour as reportable events that personnel are trained to recognise and report, which surfaces T1548.003 abuse when observed; it does not instrument or guarantee detection of every instance (especially silent or non-interactive abuse).
- T1548.004detects — A.6.8 requires personnel to report observed events including human errors, access violations, anomalous behavior, suspected malware, ineffective controls, and vulnerabilities; these overlap with observable indicators of T1548.004 abuse (e.g., unexpected credential prompts, modified legitimate programs, or world-writable file loads), but the control only surfaces knowledge via human reporting and does not instrument or guarantee detection of the technique itself.
- T1548.005detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour, which surfaces some instances of temporary elevated cloud access (especially when noticed by personnel), but does not instrument or monitor for the technique itself and leaves the bulk of stealthy or automated abuse undetected.
- T1548.006detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour, which would surface TCC database manipulation or unexpected permission grants if noticed and reported by personnel; this is only a slice because the technique can be silent, privilege-escalating, or occur without observable user-visible events that trigger reporting.
- T1550detects — A.6.8 requires awareness and easy reporting of events including access violations, ineffective controls, anomalous behaviour, suspected malware, and vulnerabilities; these can surface T1550 use (or its prerequisite credential access) when observed by personnel, but the control is limited to human-reported events and does not itself instrument or monitor for the technique.
- T1550.001detects — A.6.8 requires awareness and easy reporting of events including access violations, suspected malware, anomalous behaviour, ineffective controls and breaches of confidentiality/integrity expectations; these can surface use of a stolen application access token once it produces observable effects, but the technique itself is designed to be hard to distinguish from legitimate API use and many scenarios (e.g. initial token theft or silent background refresh) fall outside what personnel would notice or report.
- T1550.003detects — A.6.8 requires awareness and easy reporting of events including access violations, ineffective controls, anomalous behaviour, suspected malware, and vulnerabilities; these can surface PtT activity (e.g. anomalous Kerberos use or dumped tickets) when observed by personnel, but the control is limited to human reporting of noticed events and does not itself instrument or monitor for the technique.
- T1550.004detects — A.6.8 requires awareness and easy reporting of events including breaches, access violations, malware, anomalous behaviour and vulnerabilities; this surfaces knowledge of a realised T1550.004 (e.g. via reported anomalous login, suspected malware or access violation) but does not instrument or guarantee detection of the cookie theft or reuse itself.
- T1552detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, ineffective controls, anomalous behaviour, and suspected malware as reportable events; this surfaces some T1552 instances (e.g. via human observation of anomalous credential files or malware) but does not instrument or guarantee detection of credential searches or insecure storage itself.
- T1552.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities plus anomalous behavior (malware, access violations, ineffective controls) that would surface credential-in-files discoveries; this enables detection of the technique's artifacts once found by personnel, but only for the human-observable slice and not automated or silent file-system searches.
- T1552.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities plus anomalous system behaviour, which can surface credential-search activity once observed by personnel; this is a genuine but minority slice of detection because the control depends on human recognition rather than automated or comprehensive technical detection of the technique.
- T1552.003detects — A.6.8 explicitly lists human errors, non-compliance, access violations, and suspected malware as reportable events that personnel are trained to recognize and report, which would surface many instances of credential typing that produced the history file; it does not instrument or scan the history files themselves.
- T1552.005detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, ineffective controls, anomalous behaviour, and suspected malware as reportable events; this surfaces the SSRF vector and anomalous metadata API queries when observed by personnel, but does not instrument or surface the technique itself when executed without generating such an observable event.
- T1552.006detects — A.6.8 requires awareness and easy reporting of events including vulnerabilities, access violations, ineffective controls, and anomalous behaviour; these can surface GPP credential exposure once discovered by personnel, but the control itself provides no instrumentation, monitoring, or automated detection of the technique.
- T1552.007detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, suspected malware, anomalous behaviour, access violations and ineffective controls — all of which surface T1552.007 when observed by personnel; it does not itself instrument or monitor for the technique.
- T1552.008detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, suspected malware, access violations, and anomalous behavior that would surface many instances of credentials appearing in chat messages, but does not itself instrument or monitor for the technique.
- T1553detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities plus anomalous/malware/system behaviors that can surface subverted trust controls (e.g., via user suspicion or ineffective controls), but only when personnel notice and choose to report; it does not instrument or automatically surface the technique itself.
- T1553.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities plus anomalous system behaviour, which would surface many Gatekeeper bypasses once noticed by personnel; it does not itself instrument or monitor for the technique.
- T1553.003detects — A.6.8 explicitly lists reporting of vulnerabilities, ineffective controls, anomalous system behaviour, suspected malware, and access violations; hijacking a SIP/trust provider to subvert signature validation is an anomalous behaviour and a vulnerability that personnel could observe and report, but the control only surfaces knowledge via human reporting and does not instrument or guarantee discovery of the registry/DLL tampering itself.
- T1553.004detects — A.6.8 explicitly lists suspected malware infection, access violations, ineffective controls, anomalous behaviour, and vulnerabilities among the events personnel must report, which directly surfaces many (but not all) instances of T1553.004 once the root-certificate installation has occurred or is noticed; the control stops at reporting and does not guarantee discovery of every stealthy or supply-chain case.
- T1553.005detects — A.6.8 requires personnel to report observed events including ineffective controls, anomalous behaviour, suspected malware, access violations and vulnerabilities; an MOTW bypass may surface as one of those observable events (e.g. anomalous file behaviour or suspected malware) and therefore be detected via human reporting, but the clause itself supplies no automated or technical detection and many bypasses remain invisible to users.
- T1553.006detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective information security controls', 'non-compliance with policy', 'access violations', 'vulnerabilities', and 'suspected malware' as reportable events; these surface many T1553.006 policy modifications after they occur, but the clause stops at reporting (no monitoring, no automated detection) and many stealthy kernel/registry changes remain unseen by personnel, so only a slice is covered.
- T1554detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behavior, access violations, ineffective controls and vulnerabilities; this surfaces some T1554 instances (e.g., suspected infection or post-modification anomalies) but not the stealthy binary-patching act itself, which is outside the listed observable triggers and relies on voluntary human reporting rather than automated detection.
- T1555detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, access violations, suspected malware, ineffective controls, and anomalous behaviour — all of which can surface credential-theft activity from password stores; it does not itself instrument or monitor for the technique.
- T1555.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus suspected malware (both relevant to credential dumping from Keychain), so events can be surfaced when noticed by personnel; it does not instrument or guarantee detection of the technique itself.
- T1555.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, malware, access violations, and anomalous behaviour in the list of reportable events, which would surface many instances of browser-credential theft once noticed; it does not itself instrument or monitor for the technique.
- T1555.004detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, suspected malware, access violations, anomalous behaviour and ineffective controls; these surface many T1555.004 indicators (e.g. credential-dumping tools, anomalous Credential Manager access, or malware-like behaviour) once noticed by personnel, but the control stops at reporting and supplies no automated detection, so only a slice of realisations is caught.
- T1555.005detects — A.6.8 requires awareness and easy reporting of events including suspected malware, anomalous behaviour, access violations, vulnerabilities and ineffective controls; these can surface T1555.005 in flight or post-facto when observed by personnel, but the clause itself only enables reporting and does not mandate any automated detection mechanism or coverage of in-memory extraction or brute-force attempts against the master password.
- T1555.006detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus suspected malware or anomalous behaviour that would surface credential theft from a secrets manager; this detects the technique once observed by personnel but only where it is noticed and reported, leaving the bulk of stealthy API-driven exfiltration outside that human observation slice.
- T1556detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, breaches, access violations, vulnerabilities, malware, and anomalous behaviour; these surface many (but not all) T1556 modifications once they produce observable effects, yet the control itself only enables voluntary human reporting and does not instrument or guarantee discovery of stealthy process changes.
- T1556.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'malfunctions or other anomalous system behaviour', 'access violations' and 'ineffective information security controls' in the list of reportable events; these surface the Skeleton Key patch and its effects once observed by personnel, but the control itself only gathers reports and does not instrument or scan for the technique.
- T1556.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'vulnerabilities', and 'anomalous system behaviour' in its event list; a malicious password filter DLL can surface as any of those (or as ineffective controls/human error), enabling detection via personnel reporting, but only if the anomaly is noticed and reported rather than stealthily persisting.
- T1556.003detects — A.6.8 requires personnel to report observed events including ineffective controls, anomalous behaviour, access violations, suspected malware, and vulnerabilities; these overlap some observable indicators of PAM modification but miss stealthy or non-obvious changes that produce no user-visible anomaly.
- T1556.005detects — A.6.8 explicitly lists reporting of vulnerabilities, ineffective controls, anomalous behaviour, access violations and suspected malware as events that personnel must report, which would surface the reversible-encryption setting or its exploitation when observed; the remainder is stealthy or automated adversary use that evades human recognition.
- T1556.006detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, access violations, anomalous behavior, suspected malware, and vulnerabilities; these overlap with observable signs of MFA modification/disablement but only where personnel notice and choose to report them, leaving most technical realizations (e.g. config changes, host file edits) undetected without human observation.
- T1556.007detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'ineffective controls', 'anomalous system behaviour', and 'vulnerabilities' as reportable events; these surface many of the observable artifacts (DLL injection, config edits, new PTA agents, anomalous auth) once they occur, but the control stops at enabling human reporting and does not itself instrument or analyze for the technique.
- T1556.008detects — A.6.8 makes personnel aware of their responsibility (and the easy mechanism) to report observed events including access violations, suspected malware, anomalous behaviour, ineffective controls and vulnerabilities; this surfaces some instances of a Network Provider DLL being planted/used (when noticed by users or admins), but most executions are silent and technical with no user-visible indicator.
- T1556.009detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour, which would surface policy modifications when noticed by personnel; however, stealthy adversarial changes (especially in IaaS/IdP without obvious malfunction or breach symptoms) often evade human observation, leaving a large slice undetected until impact.
- T1557detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, breaches of confidentiality/integrity/availability, anomalous behavior, access violations, and suspected malware — which would surface many realized AiTM instances (e.g. via observed anomalies, credential theft symptoms, or traffic manipulation effects) but does not instrument or guarantee discovery of the positioning itself, especially pre-impact or in non-user-visible cases.
- T1557.001detects — A.6.8 requires personnel to report observed events including ineffective controls, anomalous behavior, access violations, suspected malware, and vulnerabilities; name resolution poisoning produces observable anomalous network behavior, unexpected authentication flows, and access anomalies that fit these categories and can therefore be detected/reported by users, but the control does not itself instrument or surface the technique and many instances (especially automated/stealthy poisoning) remain unseen by personnel.
- T1557.002detects — A.6.8 requires personnel to report observed events including ineffective controls, anomalous system behaviour, access violations, suspected malware, and vulnerabilities; ARP cache poisoning produces observable anomalies (e.g., unexpected MAC-IP mappings, traffic interception symptoms) that fit several listed categories and can therefore be detected via human reporting, but the control itself supplies no automated or technical detection and depends entirely on whether personnel notice and choose to report.
- T1557.003detects — A.6.8 requires personnel to report observed events including ineffective controls, anomalous system behaviour, access violations, suspected malware, and vulnerabilities; rogue DHCP responses or resulting AiTM anomalies can be noticed and reported by users or admins, but the control relies on human observation rather than automated detection and does not address the technique's stealthy network-layer execution.
- T1557.004detects — A.6.8 explicitly lists reporting of vulnerabilities, ineffective controls, anomalous system behaviour, suspected malware, access violations and human-error situations that would surface an evil-twin Wi-Fi Pineapple or rogue AP once observed by personnel; this supplies detection knowledge but only for the slice that reaches a human observer rather than automated network-layer discovery.
- T1558detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour, which would surface many T1558 instances (e.g. via klist use, ticket anomalies, or related violations) once observed by personnel; it does not instrument or guarantee detection of the technique itself.
- T1558responds — A.6.8 makes personnel aware of the responsibility and easy procedure to report events including access violations, suspected malware, ineffective controls, and anomalous behaviour; once reported this enables the incident response process that contains/eradicates an in-progress T1558 technique, but the control itself only governs reporting (not the full response) and many T1558 actions (e.g. silent ticket theft via memory scraping) can complete without triggering a reportable event.
- T1558.001detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, breaches, anomalies, access violations, vulnerabilities and suspected malware; this surfaces knowledge of golden-ticket use or its precursors (e.g. KRBTGT compromise, anomalous TGS requests) when observed by personnel, but only where those indicators reach human notice rather than automated detection.
- T1558.002detects — A.6.8 explicitly lists access violations, ineffective controls, anomalous system behaviour, suspected malware, and vulnerabilities as reportable events that personnel are trained to flag, which would surface silver ticket usage or its prerequisites in many cases, but the control is limited to human-aware reporting and does not instrument or guarantee detection of stealthy offline forgery.
- T1558.003detects — A.6.8 explicitly lists access violations, vulnerabilities, suspected malware, anomalous behaviour, and ineffective controls as reportable events that personnel are trained to recognise and report, which would surface Kerberoasting activity or its indicators once observed; this is genuine but only a slice because the control is purely awareness-and-reporting (no instrumentation, no automated detection, and relies on human recognition of subtle ticket requests or RC4 hashes).
- T1558.004detects — A.6.8 requires personnel to report observed events including access violations, ineffective controls, anomalous behaviour, suspected malware, and vulnerabilities; AS-REP roasting produces observable indicators (e.g. anomalous AS-REQ traffic without timestamps, unusual LDAP enumeration, or post-crack account use) that fit those categories and can therefore be detected and reported when noticed by users or monitoring, but the control itself only enables reporting and does not mandate or perform any detection mechanism.
- T1558.005detects — A.6.8 requires personnel to report observed events including access violations, anomalous behaviour, suspected malware, ineffective controls and vulnerabilities; an adversary reading or exfiltrating a ccache file on disk can produce observable indicators (unusual klist/kinit use, unexpected file access in /tmp, anomalous Kerberos activity) that fall inside the listed reportable situations, but the control is silent on automated detection, relies on human recognition, and does not address in-memory macOS ccache theft.
- T1559detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behavior, access violations, suspected malware, and vulnerabilities; this surfaces some IPC-abuse artifacts once they manifest observably to personnel, but leaves the bulk of stealthy in-process IPC (especially library-level or non-anomalous) outside the reporting slice.
- T1559.001detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations, ineffective controls and suspected vulnerabilities, which would surface many COM-abuse indicators if noticed by personnel; it does not instrument or guarantee discovery of the technique itself.
- T1559.002detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations and ineffective controls; these can surface DDE-based execution in flight or post-execution, but the clause only creates a reporting channel rather than mandating instrumentation that reliably discovers the technique itself.
- T1559.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, suspected malware, anomalous behaviour, access violations and ineffective controls — all of which surface XPC abuse when observed by personnel, but only when the technique produces a noticeable symptom that a user or admin actually reports; silent or non-obvious exploitation (e.g. stealthy privilege escalation via malformed XPC messages) is outside the clause's scope.
- T1560.001detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, breaches of confidentiality/integrity/availability, and access violations; these can surface the use of archiving utilities during/after data collection in many but not all cases (e.g. silent use of built-in tools on non-monitored endpoints leaves a large unaddressed slice)
- T1560.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'anomalous system behaviour', and 'ineffective controls' that can surface custom archival activity when observed by personnel; this is genuine detection coverage but only a slice, as the technique itself is silent and non-interactive, most instances produce no observable event until exfiltration, and the control stops at reporting rather than mandating automated detection.
- T1561detects — A.6.8 explicitly lists malware infection, anomalous system behaviour, ineffective controls, and access violations among the events personnel must report, which would surface disk-wiping activity once observed; the remainder is that the control depends on human recognition and does not itself instrument or automatically detect the technique.
- T1561.001detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, breaches of availability, ineffective controls and access violations; these overlap some observable indicators of T1561.001 (e.g. anomalous disk writes, malware infection) but do not mandate any automated or systematic detection mechanism, leaving most execution undetected until reported.
- T1561.002detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, breaches of availability expectations, and ineffective controls; this surfaces the T1561.002 technique (or its immediate effects) when observed by personnel, but only for the human-observable slice and not automated or stealth execution.
- T1561.002recovers — A.6.8 requires timely event reporting (including malware, anomalous behaviour, breaches of availability, and ineffective controls) so that incident response can begin; once the wipe technique has run, reporting enables the restore-from-backup actions that recover the destroyed boot structures and availability.
- T1561.002responds — A.6.8 requires personnel to report events including malware, anomalous behaviour, breaches of availability expectations, ineffective controls and physical breaches; once reported these feed directly into incident response that contains and eradicates an in-progress disk-structure wipe (the technique is already running when the observable occurs).
- T1563detects — A.6.8 requires awareness and easy reporting of events including access violations, anomalous behaviour, ineffective controls and suspected malware, which would surface many hijacking indicators once observed by personnel; it does not itself instrument or monitor for the technique.
- T1563.001detects — A.6.8 requires personnel to report observed events including access violations, anomalous system behaviour, suspected malware, ineffective controls and breaches; SSH session hijacking (especially via agent compromise or root-level socket access) produces observable indicators that fit these categories and would therefore surface through the mandated reporting mechanism, but the control depends on human recognition and does not itself instrument or scan for the technique.
- T1563.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour, which would surface RDP hijacking once noticed by personnel; this is a genuine but minority slice because most hijackings (especially of disconnected sessions or by insiders with System rights) produce no observable event for users to report.
- T1564detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective controls', 'anomalous system behaviour', 'access violations', 'suspected malware', and 'vulnerabilities' in what must be reported, which surfaces many (but not all) T1564 hiding techniques once observed by personnel; it does not instrument or automatically detect hidden artifacts itself.
- T1564.002detects — A.6.8 explicitly lists access violations, ineffective controls, anomalous behaviour, suspected malware, and vulnerabilities as reportable events that personnel are trained to flag, which would surface many (but not all) hidden-user artifacts once noticed by an observant user or admin; it does not instrument or guarantee discovery of stealthily created accounts.
- T1564.003detects — A.6.8 requires personnel to report observed events including anomalous system behaviour, suspected malware, ineffective controls, and access violations; a hidden-window technique is observable as anomalous behaviour or malware when noticed by users, so the reporting mechanism surfaces it, but only when a human sees the absence of an expected window or other side-effect (most instances remain invisible by design).
- T1564.004detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations and ineffective controls; personnel observing suspicious NTFS ADS/EA usage could report it, but the control itself performs no detection and many stealthy uses go unnoticed by humans.
- T1564.005detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous system behaviour, suspected malware, and vulnerabilities; this surfaces hidden file system use once observed as anomalous by personnel, but the technique is designed to evade standard tools and user visibility so only a slice is caught via human reporting.
- T1564.006detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, malware, access violations and ineffective controls; these can surface T1564.006 activity once observed, but the control itself only enables human reporting and does not instrument or automatically detect virtual-instance execution or artifacts.
- T1564.008detects — A.6.8 explicitly lists reporting of ineffective controls, breaches, non-compliance, access violations, suspected malware, and anomalous behaviour (all of which can surface the creation or effect of malicious email-hiding rules), but the control is limited to awareness-driven human reporting and does not itself instrument or scan for the technique.
- T1564.009detects — A.6.8 requires awareness and easy reporting of events including vulnerabilities, malware, anomalous behaviour, ineffective controls and breaches; this surfaces resource-fork hiding when observed by personnel, but the control itself supplies no instrumentation, automated discovery or detection mechanism and reaches only what humans notice and choose to report.
- T1564.010detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, malware, access violations and ineffective controls; these can surface process-argument spoofing when observed as anomalous, but the control is personnel-driven awareness rather than automated detection and leaves most in-process memory manipulation unseen.
- T1564.011detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'malfunctions or other anomalous system behaviour of software or hardware' plus 'suspected malware infection' in the list of reportable events; this surfaces the anomalous execution of nohup/silentlyContinue-style commands when observed by personnel, but does not instrument or guarantee detection of the technique itself.
- T1564.012detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'ineffective information security controls', 'anomalous system behaviour', and 'vulnerabilities' as reportable events, which would surface many (but not all) uses of well-known AV exclusions when observed by personnel
- T1564.013detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'malfunctions or other anomalous system behaviour of software or hardware' and 'suspected malware infection' (plus ineffective controls), which can surface the anomalous /proc state or utility discrepancies produced by a bind mount; this is genuine but only a slice because the control is personnel-driven awareness/reporting rather than automated detection and many stealthy bind-mount cases produce no obvious reportable anomaly.
- T1564.014detects — A.6.8 explicitly lists suspected malware infection, anomalous system behaviour, ineffective controls, and vulnerabilities among the events personnel must report, which would surface xattr-based hiding if observed; however the control is purely awareness-and-reporting and does not itself instrument, scan, or monitor for the technique.
- T1565detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, breaches of integrity, human errors, non-compliance, anomalous behaviour, access violations and suspected malware — all of which surface realized or attempted data manipulation (T1565) once it has occurred; it does not instrument or automatically discover the technique itself, leaving most instances dependent on observant personnel.
- T1565.001detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, breaches of integrity, human errors, non-compliance, anomalous behaviour, access violations and suspected malware — all of which can surface stored-data manipulation after it has occurred; the control stops at discovery via human reporting and does not itself analyse or confirm the technique.
- T1565.002detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, breaches of integrity, anomalous behaviour, access violations and suspected malware, which would surface many (but not all) instances of in-transit data manipulation once observed by personnel.
- T1565.003detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous system behaviour, access violations, suspected malware, and vulnerabilities; runtime data manipulation (via binary alteration or masquerading) would surface as one of those observable anomalies if noticed by personnel, but the control is purely about enabling human reporting rather than any automated or guaranteed detection mechanism.
- T1566detects — Clear reporting channels for suspicious emails or links enable security teams to detect and respond to phishing campaigns before initial access is achieved.
- T1566responds — A.6.8 explicitly requires personnel to report security events (including breaches, malware, access violations, and human-error incidents that result from a successful phish), enabling timely response once the technique has run and produced observable effects.
- T1566.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of suspected malware, access violations, human errors, non-compliance, and ineffective controls — all of which surface spearphishing attachment when noticed by personnel; it does not instrument or scan for the technique itself, leaving the large remainder of unreported or unrecognized instances
- T1566.001prevents — A.6.8 makes personnel aware of their duty to report events including suspected malware, access violations, human errors, and ineffective controls; timely reporting of a delivered spearphishing attachment (or its anomalous effects) can trigger blocking or containment before User Execution, but the control itself does not stop the email from arriving or the attachment from being opened.
- T1566.001responds — A.6.8's defined purpose and guidance require personnel to report events (including suspected malware, breaches, human errors, access violations, and anomalous behaviour) as quickly as possible so the organisation can contain and eradicate an incident once underway, which is exactly what `responds` names on the event lane; the named remainder is that the initial delivery step has already succeeded before any report occurs.
- T1566.002detects — A.6.8 explicitly lists human errors, non-compliance, access violations, suspected malware, ineffective controls, and breaches as reportable events that personnel are trained to recognize and report, which surfaces many (but not all) spearphishing-link deliveries once the email arrives and is noticed by the recipient; it does not instrument or surface the delivery itself at scale or before user interaction.
- T1566.002prevents — A.6.8 makes personnel aware of their duty to report events (including suspected malware, access violations, anomalous behaviour, ineffective controls, and human errors) as quickly as possible to minimise impact; this awareness can stop the spearphishing link from completing its full effect when the recipient recognises and reports it before clicking or granting consent, but the control does not stop the email from being delivered or the link from being followed in the common case where the recipient does not recognise it.
- T1566.002responds — A.6.8 makes personnel the detection surface for spearphishing events (including the listed human-error, access-violation, malware and anomalous-behaviour indicators), hands them to the incident-response process for containment/eradication once underway, and explicitly covers the social-engineering delivery step that T1566.002 relies on; the named remainder is the fully automated or pre-compromise reconnaissance slice that never reaches a user.
- T1566.003detects — A.6.8 requires awareness, easy mechanisms, and explicit inclusion of human errors, non-compliance, access violations, suspected malware, and ineffective controls, all of which surface spearphishing attempts once reported; it does not itself instrument or monitor for the technique.
- T1566.004detects — A.6.8 explicitly lists human errors, non-compliance, access violations, suspected malware, and ineffective controls (among others) as reportable events that personnel are trained to recognize and report quickly; vishing social engineering that produces these observable effects would surface via the mandated reporting mechanism, but the control is silent on automated detection of the voice call or pre-incident phishing message itself and depends on user awareness/initiative.
- T1566.004prevents — A.6.8 makes personnel aware of their duty to report events (including human errors, non-compliance, access violations, suspected malware, and ineffective controls) quickly via an easy mechanism, which can interrupt a vishing campaign before the victim completes the requested action such as divulging credentials or installing tools.
- T1566.004responds — A.6.8 explicitly requires personnel to report security events (including human errors, access violations, suspected malware, breaches of confidentiality/integrity/availability, and non-compliance) as quickly as possible to enable timely response that contains or eradicates an in-flight spearphishing-voice event once underway; the named remainder is events that evade user detection entirely.
- T1567detects — A.6.8 requires awareness and easy reporting of events including breaches of confidentiality/availability, anomalous behaviour, access violations and suspected malware, which can surface T1567 exfiltration when observed by personnel; however the control is limited to what humans notice and choose to report rather than any systematic detection mechanism.
- T1567.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'breaches of information confidentiality' and 'access violations' (among other triggers) in what personnel must report, which surfaces exfiltration events once observed by users; this is genuine but only a slice because most T1567.001 executions are not directly visible to end-users or trigger the listed human-facing indicators.
- T1567.002detects — A.6.8 requires awareness and easy reporting of events including breaches of confidentiality, anomalous behavior, access violations and suspected malware, which can surface exfiltration to cloud storage when observed by personnel; however, the control is limited to what humans notice and report rather than any automated or comprehensive detection of the technique.
- T1567.003detects — A.6.8 requires awareness and easy reporting of events including breaches of confidentiality, anomalous behavior, malware, and access violations; these can surface exfiltration to text sites when observed by personnel, but the control itself only enables reporting and does not perform or guarantee detection of the technique.
- T1567.004detects — A.6.8 explicitly lists suspected malware, anomalous behaviour, access violations, ineffective controls and breaches of confidentiality expectations among the events personnel must report, which would surface webhook-based exfiltration if observed; the control stops at awareness and easy reporting channels and does not itself perform detection, leaving most realisations of T1567.004 (especially blended HTTPS SaaS traffic) unreached.
- T1567.004responds — A.6.8 requires personnel to report observed security events (including breaches, anomalous behaviour, access violations and suspected malware) as quickly as possible; webhook exfiltration is an observable event that, once underway, can be reported to trigger incident response, satisfying the `responds` verb on a genuine but minority slice of the technique (the detection/reporting moment after the exfil has begun).
- T1568detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behavior, ineffective controls, and access violations; these surface T1568 activity once observed by personnel, but the control is limited to human reporting of already-visible events and does not instrument or automatically detect dynamic resolution itself.
- T1568.001detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, malware, access violations and ineffective controls; fast-flux C2 produces observable anomalies (rapid DNS flux, unusual resolver behaviour) that fit those categories and can therefore be reported, but the control itself only enables reporting and does not perform or mandate any detection mechanism.
- T1568.002detects — A.6.8 makes personnel aware of their duty to report observed anomalous system behaviour, suspected malware, or access violations that could surface DGA-driven C2 traffic, but the control itself only gathers human-reported events and does not instrument or surface the technique autonomously.
- T1568.003detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, suspected malware, access violations and ineffective controls; DNS-calculation C2 produces observable anomalies (unusual DNS, unexpected ports, beaconing) that fit those categories and would surface if reported, but the control itself only enables reporting and does not perform or guarantee detection.
- T1569detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, malware, access violations and ineffective controls, which would surface many instances of service abuse once observed by personnel; this is genuine detection coverage but only a slice, as the control depends on human recognition rather than automated instrumentation and does not reach stealthy or non-obvious service abuse.
- T1569.001detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations and ineffective controls; this surfaces launchctl abuse when observed by personnel but does not instrument or guarantee detection of the technique itself.
- T1569.002detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous system behaviour, malware, access violations and breaches; this surfaces many observable signs of T1569.002 (new/modified service execution, anomalous services.exe activity) once it occurs, but only if personnel notice and choose to report rather than the control mandating automated or systematic detection.
- T1569.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, malfunctions, access violations, and suspected malware as reportable events; this surfaces some systemctl abuse (e.g. via observable anomalies) but leaves the bulk of stealthy or non-anomalous invocations undetected as the control is awareness-driven rather than instrumentation-driven.
- T1570detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations, and ineffective controls — all of which can surface lateral tool transfer when observed by personnel; it does not itself instrument or guarantee detection of the technique.
- T1571detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous system behaviour, access violations and suspected malware; non-standard port usage can surface as one of those observable events (especially if it triggers anomaly detection), but the control itself only enables reporting once noticed and does not mandate any specific detection mechanism or coverage of this technique.
- T1572detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, ineffective controls, and access violations, which would surface many observable signs of protocol tunneling once noticed by personnel; it does not itself instrument or monitor for the technique.
- T1573detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behavior, ineffective controls, and vulnerabilities, which would surface suspected encrypted C2 channels when observed by personnel; this is a genuine but minority slice of detection because most encrypted C2 is not human-observable and the control stops at reporting rather than mandating automated detection.
- T1574detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behaviour, access violations, suspected malware, and vulnerabilities; these surface many (but not all) hijack-execution-flow indicators once they occur or are observed by personnel.
- T1574.001detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behavior, access violations, ineffective controls and vulnerabilities; this surfaces some T1574.001 instances (e.g. via observed anomalies or suspected malware) but does not instrument or guarantee detection of the technique itself.
- T1574.004detects — A.6.8 requires personnel to report observed events including malware, anomalous behavior, access violations and ineffective controls; a realized dylib hijacking (especially if it produces visible anomalies or suspected malware) can be reported by users, but the control does not itself instrument or surface the technique and many stealthy cases go unnoticed.
- T1574.005detects — A.6.8 requires personnel to report observed events including ineffective controls, anomalous behavior, access violations, suspected malware, and vulnerabilities; these overlap some observable indicators of T1574.005 (e.g., anomalous installer behavior or post-exploit malware), but most instances occur silently during installation without triggering user-visible events, and the control only surfaces what users notice and choose to report.
- T1574.006detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations and ineffective controls; these surface many (but not all) dynamic linker hijacking cases once they run, especially via user-visible symptoms or logs, yet miss stealthy in-process cases without observable indicators or when personnel do not recognise the event.
- T1574.007detects — A.6.8 requires personnel to report observed events including anomalous system behaviour, suspected malware, access violations, and ineffective controls; these can surface a PATH hijack in flight or after execution, but only when a human notices and reports it, leaving the bulk of stealthy or automated executions undetected.
- T1574.008detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations and ineffective controls; these can surface search-order hijacking once it has executed and produced observable effects, but the control itself only enables reporting and does not mandate any detection mechanism or monitoring that would surface the technique before or during execution.
- T1574.009detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behavior, access violations, vulnerabilities and suspected malware; an observed unquoted-path hijack would qualify as one or more of those and therefore be surfaced by personnel, but the clause itself supplies no instrumentation, automated discovery or guaranteed coverage of the technique.
- T1574.010detects — A.6.8 explicitly lists access violations, ineffective controls, vulnerabilities, anomalous behaviour, and suspected malware as reportable events, any of which would surface the permission flaw or its exploitation once observed by personnel; this is genuine but only a slice because the control depends on human recognition and does not itself instrument or scan for the condition.
- T1574.011detects — A.6.8 explicitly lists access violations, ineffective controls, non-compliance, vulnerabilities, and anomalous behaviour as reportable events that personnel are trained to flag, which surfaces many (but not all) realisations of this Registry-permissions technique once an anomalous change or service start occurs.
- T1574.012detects — A.6.8 explicitly lists suspected malware infection, anomalous system behaviour, access violations, and ineffective controls among the events personnel must report, which would surface COR_PROFILER abuse when observed; the remainder is in-memory or stealthy instances that produce no observable anomaly for users to notice or report.
- T1574.013detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'suspected malware infection', 'access violations', 'anomalous system behaviour', and 'ineffective controls' as reportable events; these can surface the technique when observed by personnel, but the stealthy in-process hijack (often masked under legitimate processes and not necessarily producing obvious user-visible anomalies) is only a minority slice of what the control actually catches.
- T1574.014detects — A.6.8 requires personnel to report observed events including anomalous system behaviour, suspected malware, access violations and ineffective controls; these can surface AppDomainManager injection in flight when noticed, but the control depends on human recognition rather than automated detection and leaves most stealthy in-process cases unreported.
- T1578detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations, ineffective controls, anomalous behaviour, and suspected malware as reportable events; these surface T1578 modifications after they occur via personnel observation, but only where the change is noticeable to humans rather than fully stealthy or automated, leaving a large slice of cloud-native modifications undetected by this governance/reporting clause.
- T1578.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective information security controls', 'access violations', 'vulnerabilities', 'suspected malware', and 'anomalous system behaviour' that would surface creation of a snapshot to bypass restrictions; this is genuine detection via human reporting but only a slice, as the control does not mandate automated or technical detection of the technique itself.
- T1578.002detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behaviour, access violations, non-compliance and suspected malware, which would surface creation of a new cloud instance when noticed by personnel; this is a genuine but minority slice because most T1578.002 executions (especially automated or stealthy ones) produce no observable event for humans to report.
- T1578.003detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, breaches, anomalies, access violations, malware and vulnerabilities; this surfaces the deletion (or its precursor anomalous behavior) when personnel notice and report it, but the control depends on human observation rather than automated detection and does not address silent/automated instance termination that leaves no observable event for users.
- T1578.004detects — A.6.8 requires awareness, easy mechanisms, and explicit inclusion of 'malfunctions or other anomalous system behaviour', 'system changes that have not gone through the change management process', and 'ineffective information security controls' in the list of reportable events, which would surface a revert/snapshot restore in many environments; it does not itself instrument or guarantee detection of the technique.
- T1578.005detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations, ineffective controls, policy non-compliance, anomalous behavior, and vulnerabilities, which would surface many T1578.005 modifications if noticed by personnel; however, stealthy quota/policy changes that avoid triggering alerts or human observation (especially in IaaS without explicit monitoring) remain undetected, making it a genuine but incomplete slice.
- T1584detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, ineffective controls, anomalous behaviour, malware, and access violations, which would surface many instances of infrastructure compromise (especially post-breach anomalies or malware); it does not instrument or guarantee detection of stealthy pre-positioning on third-party assets before use.
- T1584.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities plus anomalous behavior that would surface many hijack indicators (e.g., unauthorized changes, access violations, suspected compromise), but only after the fact and only if personnel notice and report them; it does not instrument or automatically surface the pre-attack hijack itself.
- T1586.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, access violations, malware, anomalous behaviour and ineffective controls in the list of reportable events; this surfaces knowledge of many T1586.003 precursors or realisations (e.g. credential theft, suspicious cloud-account activity) once observed by personnel, but does not instrument or guarantee detection of the compromise itself, especially pre-compromise reconnaissance or stealthy account use.
- T1588.006detects — A.6.8 requires personnel to report observed vulnerabilities (and related events like ineffective controls or anomalous behaviour) as soon as identified, which surfaces knowledge of the vulnerability to the organisation; this is detection at the point of human observation, but the technique is performed by the adversary in the pre-compromise phase against public or closed databases, so only a minority slice is reached.
- T1595detects — A.6.8 requires awareness and easy reporting of events including vulnerabilities, ineffective controls, anomalous behavior, and suspected malware, which can surface active scanning when observed as probing or reconnaissance activity; however, it depends on personnel noticing and reporting rather than automated or guaranteed detection of the technique.
- T1595.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities plus anomalous system behaviour, which would surface scanning activity if observed by personnel; however, external/pre-attack scanning of public IP blocks is typically invisible to internal personnel until it triggers a detectable anomaly, leaving most of the technique outside the control's reach.
- T1595.002detects — A.6.8 requires personnel to report observed events including vulnerabilities and anomalous behavior, which can surface adversary vulnerability scanning if noticed, but most external/pre-attack scans produce no observable event for personnel to report.
- T1595.003detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, breaches, vulnerabilities, anomalous behavior, and suspected malware; this can surface wordlist scanning if observed as anomalous probing or vulnerability discovery, but the control is personnel-driven with no instrumentation or automated detection of external reconnaissance.
- T1598detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, non-compliance, access violations, suspected malware, and ineffective controls — all of which surface many T1598 phishing-for-information attempts once received and noticed by personnel; it does not instrument or guarantee detection of the electronic delivery, spoofing, or evasive techniques themselves.
- T1598prevents — A.6.8 makes personnel aware of their responsibility to report events (including human errors, non-compliance, access violations, suspected malware, and ineffective controls) as quickly as possible to minimize incident effects, which lowers the odds that a successful T1598 phishing-for-information attempt goes unreported and unmitigated; it does not stop the phishing message from being sent or the information from being divulged.
- T1598.001detects — A.6.8 explicitly lists human errors, non-compliance, access violations, suspected malware, ineffective controls, and breaches as reportable events that personnel are trained to recognize and report, which would surface many spearphishing attempts once the recipient notices them; it does not instrument or automatically detect the delivery itself on third-party services before the target interacts.
- T1598.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, non-compliance, access violations, suspected malware, and ineffective controls — all of which surface spearphishing attachment attempts when noticed by recipients; it does not instrument or guarantee detection of the electronic delivery itself.
- T1598.003detects — A.6.8 requires personnel to report observed events including human errors, non-compliance, access violations, suspected malware, ineffective controls and anomalous behaviour; a user who notices a suspicious spearphishing link or resulting anomalous login can report it, surfacing the technique after delivery but before or during credential theft.
- T1598.003responds — A.6.8 explicitly lists spearphishing indicators (human errors, access violations, suspected malware, ineffective controls, anomalous behaviour) as reportable events; once reported the incident-response pipeline can contain/eradicate the phishing campaign that is already underway, which is exactly what `responds` names on the event lane.
- T1599detects — A.6.8 requires personnel to report observed events including ineffective controls, anomalous system behaviour, access violations, suspected malware, and vulnerabilities; these overlap with observable indicators of boundary device compromise or reconfiguration that enables T1599, but the control is limited to human-reported events and does not itself instrument or surface the technique programmatically.
- T1599.001detects — A.6.8 requires personnel to report observed events including ineffective controls, anomalous behavior, access violations, and suspected malware, which can surface NAT modifications after they occur; however, the control is limited to human-reported events and does not mandate automated detection mechanisms for network device configuration changes.
- T1601.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, anomalous system behaviour, ineffective controls, and suspected malware as reportable events; these surface some (but not all) indicators of a T1601.001 patch, especially post-compromise or during testing, yet miss stealthy in-memory or boot-loader methods that produce no observable event for personnel to report.
- T1601.002detects — A.6.8 requires personnel to report observed events including ineffective controls, anomalous behavior, non-compliance, vulnerabilities, and suspected malware; an observable downgrade (e.g. via anomalous boot, version change, or weakened cipher use) can be reported and therefore detected, but the control depends on human observation and does not instrument or surface the technique itself.
- T1602detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, ineffective controls, anomalous behavior, access violations, and suspected malware as reportable events; this surfaces T1602 activity when observed by personnel but only where it manifests in one of those observable forms rather than stealthy repository access itself.
- T1602.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, ineffective controls, anomalous behavior, and access violations, which would surface an observed SNMP MIB dump as a reportable event; however, the control only enables detection if personnel notice and report it, leaving automated or stealthy cases unreached.
- T1602.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, access violations, anomalous behaviour, ineffective controls and suspected malware as reportable events; a configuration dump via management protocols can surface as anomalous system behaviour, access violation or ineffective controls and therefore be detected via personnel reporting, but this is only a slice of possible realisations (especially stealthy or automated ones) rather than a bounded remainder.
- T1606detects — A.6.8 requires awareness and easy reporting of events including access violations, ineffective controls, anomalous behaviour, suspected malware, and vulnerabilities; this surfaces some T1606 activity (e.g. anomalous token use or post-forgery access) once observed by personnel, but the technique's generation phase is largely silent and non-observable to users, leaving most of the class undetected by this reporting mechanism alone.
- T1606.001detects — A.6.8 requires awareness and easy reporting of events including access violations, suspected malware, anomalous behaviour, ineffective controls and breaches; forged cookies used for access would surface as observable anomalies or violations if noticed by personnel, but this is a minority slice dependent on human observation rather than systematic detection.
- T1606.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations, suspected malware, anomalous behaviour, ineffective controls and vulnerabilities in the list of reportable events; this surfaces some SAML forgery indicators (e.g. anomalous auth, suspected compromise of signing material) once observed by personnel, but does not instrument or guarantee detection of the forgery technique itself.
- T1608.005detects — A.6.8 requires personnel to report observed events including ineffective controls, breaches, human errors, non-compliance, anomalous behaviour, access violations, vulnerabilities, and suspected malware — any of which can surface a prepared malicious link target (e.g. cloned phishing site, typosquatted domain, anomalous redirect) once it is encountered; this is genuine but only a slice because the control is limited to human observation and reporting after the link target exists and is presented, with no instrumentation, automated discovery, or coverage of pre-deployment adversary preparation on PRE platforms.
- T1609detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations, and ineffective controls — all of which can surface T1609 execution in a monitored environment, but only when personnel notice and choose to report; the control itself supplies no automated detection.
- T1610detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, anomalous system behaviour, ineffective controls, and suspected malware as reportable events; container deployment (especially anomalous/privileged/vulnerable ones) can surface as one of those observable events if noticed by personnel, but the control stops at enabling reporting and does not itself instrument or surface the technique.
- T1611detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, ineffective controls, anomalous behaviour, access violations and suspected malware as reportable events; these surface many T1611 indicators (e.g. anomalous system behaviour, privilege-escalation artifacts, container escapes) once observed by personnel, but the control stops at reporting and does not itself instrument or guarantee discovery of the technique.
- T1612detects — A.6.8 requires awareness and easy reporting of events including vulnerabilities, malware, anomalous behaviour, and ineffective controls; building a malicious image on-host can surface as one of those observable events if noticed by personnel, but the control itself only enables reporting and does not perform or guarantee detection.
- T1613detects — A.6.8 requires personnel to report observed events including anomalous system behaviour, access violations, ineffective controls, and suspected malware, which can surface container/resource discovery activity once noticed by users or admins; this is a genuine but minority slice because most discovery is automated, silent, or occurs without triggering human-visible indicators.
- T1615detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective information security controls', 'non-compliance with policy', 'access violations', 'vulnerabilities', and 'suspected malware' as reportable events; discovery of Group Policy settings (especially via anomalous commands like gpresult or PowerShell Empire functions) can surface as one of those observable events if personnel notice or monitoring flags it, but the control is personnel-driven awareness rather than automated or guaranteed detection of the technique itself.
- T1620detects — A.6.8 requires awareness and easy reporting of events including malware, anomalous behaviour, access violations and ineffective controls; reflective loading can surface as one of those observable events (especially if it triggers alerts or is noticed by personnel), but the control itself only enables reporting after detection has already occurred elsewhere and does not mandate or perform the detection.
- T1621detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour, which would surface MFA fatigue or repeated MFA request patterns if noticed and reported by personnel; this is only a slice because the control depends on human observation and voluntary reporting rather than automated detection of the technique itself.
- T1647detects — A.6.8 requires personnel to report observed events including anomalous system behaviour, suspected malware, access violations, and ineffective controls; plist modification can produce observable anomalies (e.g. unexpected Dock changes, background apps, or anomalous process behaviour) that fit those categories and would therefore surface via the mandated reporting mechanism, but the control depends on human recognition and does not instrument or guarantee discovery of the file change itself.
- T1648detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behaviour, malware, access violations and vulnerabilities; this surfaces many T1648 indicators (e.g. unexpected functions, triggered workflows, anomalous IAM changes) once observed by personnel, but only where humans notice and report them rather than automated detection.
- T1649detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, suspected malware, anomalous behaviour, access violations and ineffective controls — all of which surface certificate theft or forgery when observed by personnel; this is genuine but only a slice because the technique can be performed silently by an adversary with no human witness or anomalous symptom that triggers reporting.
- T1649responds — A.6.8 requires timely reporting of events (including breaches, access violations, vulnerabilities, ineffective controls, and suspected malware) once identified by personnel, which directly enables the incident response process once the certificate theft or forgery is discovered.
- T1652detects — A.6.8 requires personnel to report observed anomalous system behaviour, malfunctions, ineffective controls, suspected malware, access violations and vulnerabilities; device-driver enumeration can produce observable artifacts (unusual lsmod/driverquery use, anomalous Registry or /dev access) that fit those reportable categories and would therefore surface via the mandated reporting mechanism.
- T1653detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous system behaviour, non-compliance, and suspected malware; these can surface power-setting abuse as an observable event, but only when noticed and voluntarily reported by personnel — the control itself performs no active detection.
- T1654detects — A.6.8 requires awareness, easy mechanisms, and explicit inclusion of 'ineffective controls, breaches, human errors, non-compliance, anomalous behaviour, access violations, vulnerabilities, suspected malware' so that personnel report them; this surfaces many T1654 indicators (esp. anomalous logs, access violations, suspected malware) but does not instrument or guarantee detection of stealthy log enumeration itself, especially real-time monitoring of IR or bulk SIEM export.
- T1657detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, non-compliance, access violations, suspected malware, ineffective controls, breaches, and anomalous behaviour as reportable events; these surface many T1657 precursors or early indicators (e.g., BEC social engineering, unauthorized transfers, ransomware extortion demands) once noticed by personnel, but the control stops at reporting and has no instrumentation, monitoring, or automated detection of the financial-theft technique itself.
- T1657responds — A.6.8 makes personnel aware of the responsibility and easy procedure to report events (including breaches, malware, access violations, and anomalous behaviour) so that incidents can be contained and eradicated once underway; this directly matches the `responds` verb but is limited to the detection-and-reporting slice rather than full incident-handling actions such as eradication or recovery.
- T1659detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behaviour, malware, access violations and vulnerabilities; this surfaces some T1659 manifestations (e.g. observed anomalous traffic or suspected malware) once they reach personnel, but upstream ISP-level or silent injection that evades user-visible indicators is outside the clause's personnel-focused mechanism.
- T1665detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, anomalous behaviour, ineffective controls, and suspected malware as reportable events, which surfaces some hiding/evasion artifacts once observed by personnel; however, the control is limited to human-initiated reporting of noticed events and does not itself instrument, scan, or automatically detect hidden C2 infrastructure, traffic filtering, or domain masking.
- T1666detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations, non-compliance, ineffective controls, and vulnerabilities as reportable events; these surface a meaningful slice of T1666 activity (e.g., unauthorized hierarchy changes or policy-evading account creation) once observed by personnel, but the control stops at enabling human reporting and does not itself instrument or surface the API-driven technique.
- T1667detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective information security controls', 'breaches of ... availability expectations', 'malfunctions or other anomalous system behaviour', and 'suspected malware infection' — any of which can surface email bombing once the flood produces observable effects; this is genuine but only a slice because the control is purely personnel-driven reporting with no instrumentation, detection logic, or coverage of the registration/spam-delivery phase itself.
- T1669detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of access violations plus anomalous system behaviour, which would surface many instances of unauthorized or bridged Wi-Fi connections once noticed by personnel; it does not instrument or guarantee detection of the technique itself.
- T1671detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, access violations, anomalous behaviour, ineffective controls and suspected malware as reportable events; these surface many T1671 indicators (e.g. new OAuth consent, anomalous app integration, unexpected service principal) once noticed by personnel, but the control stops at enabling human reporting and does not itself instrument, scan or analyse for the technique.
- T1673detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of anomalous system behaviour, suspected malware, access violations and ineffective controls; these surface VM enumeration when noticed by personnel, but the technique is typically silent, non-user-visible, and runs post-compromise with no guaranteed observer, leaving most executions undetected.
- T1675detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, anomalous system behaviour, access violations, and suspected malware as reportable events; these surface many observable indicators of T1675 (e.g., anomalous vmtoolsd activity or unauthorized guest command execution) once noticed by personnel, but the control stops at reporting and does not itself instrument or analyze for the technique.
- T1677detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities, suspected malware, anomalous behavior, and ineffective controls in the list of reportable events, which would surface many poisoned-pipeline indicators once observed by personnel; it does not itself instrument or scan the CI/CD pipeline, leaving the bulk of stealthy injection scenarios undetected until human notice occurs.
- T1684detects — A.6.8 requires awareness, easy mechanisms, and explicit inclusion of human errors, policy non-compliance, access violations, suspected malware, and ineffective controls in event reporting, which surfaces many social engineering outcomes after the user has acted; it does not instrument or surface the pre-action influence itself.
- T1684prevents — A.6.8 makes personnel aware of their duty to report events (including human errors, non-compliance, access violations, suspected malware, and ineffective controls) quickly via an easy mechanism, which can stop social engineering from succeeding or escalating when users recognize and report the attempt before acting on it; this is only a slice because the control does not stop users from being influenced or acting in the first place.
- T1684.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of human errors, non-compliance, access violations, suspected malware, and ineffective controls — all of which surface many impersonation/social-engineering events once noticed by personnel; it does not instrument or automatically detect the technique itself.
- T1684.001prevents — A.6.8 makes personnel aware of their duty to quickly report events including human errors, access violations, suspected malware, ineffective controls, and non-compliance, which can surface many impersonation attempts (especially internal or anomalous ones) before the tricked action completes; this stops the technique from fully succeeding in a meaningful slice of cases, but reporting is after the fact for the initial deception and does not stop the social engineering itself.
- T1684.001responds — A.6.8 explicitly requires personnel to report impersonation-driven events (phishing, social engineering, suspected breaches, access violations, human errors) once they occur, enabling timely incident response that contains and eradicates the ongoing campaign per the event-lane definition of `responds`.
- T1684.002detects — A.6.8 explicitly lists reporting of suspected malware, access violations, breaches of confidentiality/integrity, anomalous behaviour, and vulnerabilities, all of which surface knowledge of an Email Spoofing attempt once it reaches personnel; this is genuine but only a slice because the control is personnel-driven awareness and has no instrumentation, automated monitoring, or detection of the technique itself before delivery or human observation.
- T1685detects — A.6.8 requires awareness, easy mechanisms, and explicit inclusion of 'ineffective information security controls', 'malfunctions or anomalous system behaviour', 'access violations', and 'suspected malware infection' in what must be reported, which surfaces many (but not all) T1685 actions once performed by an adversary or noticed by personnel.
- T1685.001detects — A.6.8 requires personnel to report observed events including ineffective controls, anomalous behaviour, access violations, suspected malware and vulnerabilities; these overlap with observable indicators of T1685.001 (e.g. audit-policy changes, service-stop commands, registry writes to EventLog keys) but only when a human notices and chooses to report them, leaving the bulk of stealthy or automated modifications undetected by this awareness-and-reporting mechanism alone.
- T1685.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective information security controls', 'malfunctions or anomalous system behaviour', and 'vulnerabilities' (among others) that would surface an adversary's tampering with cloud logging as a reportable event, but it only creates the conditions for human detection and does not itself instrument, monitor, or guarantee discovery of the technique.
- T1685.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective information security controls', 'malfunctions or anomalous system behaviour', and 'suspected malware infection' as reportable events, which can surface UI spoofing that falsifies tool status; this is genuine but only a slice because the control is purely personnel-driven awareness/reporting with no instrumentation, automated discovery, or coverage of non-human-detectable spoofing.
- T1685.004detects — A.6.8 requires personnel to report observed events including ineffective controls, anomalous behaviour, suspected malware, access violations and vulnerabilities; this surfaces some T1685.004 realisations after the fact when noticed by users or admins, but the control is silent on automated detection, kernel-level hooking or pre-emptive discovery of the modification itself.
- T1685.005detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective information security controls', 'malfunctions or anomalous system behaviour', and 'suspected malware' as reportable events, which can surface log-clearing as anomalous; this is a genuine but minority slice of the technique (most instances are not reported by users before impact).
- T1685.005responds — A.6.8 requires timely reporting of events (including ineffective controls, anomalous behaviour, access violations, suspected malware, and breaches) once they occur, which directly enables the incident response process that contains and eradicates an ongoing log-clearing technique.
- T1685.006detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of 'ineffective information security controls', 'malfunctions or other anomalous system behaviour', and 'suspected malware infection' (among others) that would surface log-clearing activity if observed by personnel; this is genuine but only a slice because the control is personnel-driven awareness/reporting rather than automated detection and does not reach all log-clearing variants or non-observable cases.
- T1685.006responds — A.6.8 requires personnel to report security events (including breaches of availability expectations, anomalous behaviour, access violations, and suspected malware) as quickly as possible to enable effective incident response; clearing logs is exactly such an event that, once reported, triggers containment/eradication under the incident-handling process the reporting feeds.
- T1686detects — A.6.8 explicitly lists ineffective controls, anomalous system behaviour, non-compliance, access violations and suspected malware as reportable events that personnel are trained to surface, which would include observable signs of a firewall being disabled or modified; this is genuine but only a slice because the control is purely about awareness and easy reporting channels rather than any automated or guaranteed detection mechanism.
- T1686.001detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of ineffective controls, policy non-compliance, access violations, anomalous behavior, and vulnerabilities, which would surface many instances of a cloud firewall being disabled or modified; however, it depends on personnel noticing and voluntarily reporting rather than any automated or guaranteed detection, leaving a large slice of stealthy or privileged modifications unreached.
- T1686.002detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of ineffective controls, access violations, anomalous behavior, vulnerabilities, and suspected malware as reportable events, which would surface many instances of firewall tampering once observed by personnel; it does not itself instrument or guarantee detection of the technique when it occurs unobserved.
- T1686.003detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of ineffective controls, anomalous system behaviour, access violations, and suspected malware as reportable events; these surface many (but not all) T1686.003 realisations once the firewall change is noticed by personnel.
- T1687detects — A.6.8 requires awareness, easy reporting mechanisms, and explicit inclusion of vulnerabilities plus anomalous/malfunction behaviors that can surface exploitation of defensive components; this detects some instances of T1687 but only those observed and reported by personnel, leaving the bulk of stealthy or automated exploitation unreached.
- T1688detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behaviour, malware, access violations and breaches; safe-mode abuse that disables EDR produces observable anomalies or symptoms that fit those categories and can therefore be reported, but the clause itself only enables detection via human reporting and does not instrument or guarantee discovery of the underlying BCD/registry changes.
- T1689detects — A.6.8 requires awareness and easy reporting of events including ineffective controls, anomalous behavior, non-compliance, vulnerabilities and suspected malware; downgrade attacks produce several of those observables (e.g., use of legacy PowerShell without SBL, anomalous boot-manager downgrade, protocol fallback) that personnel could notice and report, but the clause stops at enabling human reporting and does not itself instrument or surface the technique.
- T1690detects — A.6.8 requires awareness and easy reporting of events including anomalous system behaviour, ineffective controls, suspected malware, and access violations; these can surface T1690's history-clearing commands or environment changes when observed by personnel, but the control itself only enables reporting and does not instrument or guarantee detection of the technique.
Prevented OWASP Web Top 10 (2025) risks (12)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A09mitigates — A.6.8's reporting awareness and easy mechanism enable faster detection/response to realized logging/alerting failures (e.g., via human-reported anomalies or breaches), bounding incident impact without addressing the logging/alerting defects themselves.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.