A.8.15 Technological
Logging
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (26)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AU-2fullcovers — A.8.15's core requirement to record events and generate evidence directly accounts for the entirety of AU-2's identification, coordination, and specification of event types for logging; nothing in the target sits outside the source.
- AU-2mostlyaligns with — Both controls define the events and activities that must be captured in logs to support accountability and incident investigation.
- AU-3mostlyaligns with — Both specify the minimum data elements that each logged event must contain to enable reconstruction and correlation of security-relevant actions.
- AU-3mostlycovers — A.8.15's requirement to record events and generate evidence (with integrity and access controls) directly accounts for the bulk of au-3's mandated content fields that establish what/when/where/source/outcome/identity, but a residual of au-3's explicit, enumerated detail-level prescription sits outside the higher-level ISO wording.
- AU-9mostlyaligns with — Both require technical and procedural safeguards to prevent unauthorized modification or deletion of audit records, including by privileged users.
- AU-9mostlycovers — A.8.15's explicit requirements to ensure log integrity and prevent unauthorized access directly implement the core protection of audit information in AU-9, but AU-9's separate alerting-on-tampering obligation sits outside what A.8.15 records.
- AU-11partialaligns with — Both address retention and archival of log data when required for regulatory, evidentiary, or operational purposes.
- AU-11partialcovers — A.8.15's purpose includes generating evidence, identifying events, and supporting investigations, which overlaps with au-11's retention-for-investigations goal, but does not address the distinct retention-duration, regulatory, or organizational requirements that form the bulk of au-11.
- AU-6partialaligns with — Both emphasize systematic review and analysis of logged events to detect anomalies, indicators of compromise, and support incident response.
- AU-8partialaligns with — Both stress the need for synchronized, accurate time stamps across systems so that logs can be reliably correlated during analysis and investigations.
- AU-6covers — A.8.15's broad logging purposes (record events, generate evidence, ensure integrity, prevent unauthorized access, identify events, support investigations) address only a slice of AU-6's specific requirements for ongoing review, analysis, reporting of audit records, and risk-based adjustment of that process.
- AU-8covers — A.8.15's broad mandate to record events and generate evidence reaches the requirement to produce timestamps on audit records, but says nothing about clock synchronization, UTC/offset representation, or accuracy parameters that dominate au-8.
Aligned NIST CSF 2.0 outcomes (25)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.PS-04fullcovers — The ISO control mandates generation and protection of event logs that capture user, system, and security-relevant activity, directly satisfying the CSF requirement to produce logs for continuous monitoring.
- DE.AE-02mostlyaligns with — The control’s emphasis on log analysis to detect unusual or anomalous behaviour supports the CSF goal of analyzing potentially adverse events to understand associated activities.
- DE.AE-03mostlyaligns with — Requiring synchronized time sources and correlation of logs across systems enables the CSF outcome of correlating information from multiple sources to understand adverse events.
- DE.CM-01partialaligns with — By generating logs of network-related events and access attempts, the control contributes to the CSF outcome of monitoring networks and services for potentially adverse events.
- DE.CM-03partialaligns with — Logging of user activities, privilege use, and identity changes provides the data needed to monitor personnel activity and technology usage for adverse events.
- ID.RA-01partialaligns with — Analysis of logged security events can reveal vulnerabilities or misconfigurations that need to be identified, validated, and recorded.
- RS.AN-03partialaligns with — Preserved and protected logs supply the detailed event data required for post-incident analysis to determine what occurred and identify root cause.
- DE.AE-02implements — A.8.15 logging directly supplies the raw records whose analysis is DE.AE-02; the technical logging control therefore gives operational effect to the adverse-event analysis outcome, but the link is inferential rather than named.
- DE.AE-03implements — A.8.15's logging, event identification, and investigation-support functions give operational effect to multi-source correlation within the DE.AE detection-analysis domain, but do not name correlation explicitly
- DE.CM-01implements — A.8.15's logging and event-identification functions give operational effect to network monitoring for adverse events within the detection domain, but do not name or exclusively perform the monitoring itself
- DE.CM-03implements — A.8.15's logging, integrity, and event-identification functions give direct operational effect to the monitoring of personnel activity and technology usage that DE.CM-03 requires; the link is within the detection domain but the CSF outcome does not name logging specifically.
- ID.RA-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- RS.AN-03implements — A.8.15's logging, integrity, and event-identification functions give direct operational effect to the incident analysis and root-cause determination required by RS.AN-03; the link is within the shared incident-response domain but RS.AN-03 does not name logging as the specific means.
Related OWASP ASVS 5.0 requirements (16)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V16.2.2fullaligns with — ISO’s explicit call for synchronized time sources across systems implements the ASVS requirement that timestamps in security logs use a consistent, synchronized time base (UTC or offset) to enable correlation.
- V16.2.1mostlyaligns with — The ISO requirement to capture user IDs, system activities, dates/times, device and network identifiers for each event directly supports the ASVS mandate that every log entry contain the metadata needed for detailed security investigations.
- V16.3.1mostlyaligns with — Logging of successful and rejected system access attempts, privilege use, and identity changes satisfies the ASVS requirement to record all authentication operations with relevant metadata.
- V16.4.2mostlyaligns with — ISO’s controls preventing privileged users from deleting or altering their own logs and protecting against unauthorized log changes implement the ASVS requirement that logs be protected from unauthorized access and modification.
- V16.2.5partialaligns with — ISO’s recognition that logs may contain sensitive or PII data and the call for privacy-protection measures aligns with the ASVS requirement to enforce logging rules based on data-protection levels.
- V16.3.2partialaligns with — ISO’s requirement to log successful and rejected data/resource access attempts partially fulfills the ASVS need to log failed (and, at L3, all) authorization decisions.
- V16.3.3partialaligns with — The ISO directive to log security-system activations, configuration changes, and attempts to bypass controls aligns with the ASVS requirement to log both defined security events and bypass attempts.
- V16.4.3partialaligns with — ISO’s guidance on sending logs to a separate system for analysis, detection and alerting partially satisfies the ASVS requirement for secure, logically separate log transmission and storage.
Related weaknesses / CWE (52)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1304nonedetects — Logging can record power events but does not ensure or verify configuration integrity.
- CWE-385nonedetects — Detailed logging can reveal timing anomalies but does not prevent covert timing channels.
- CWE-807nonedetects — Logging may record the flawed decisions but does not prevent them.
- CWE-1050finds — Logging may detect excessive consumption but does not stop the loop.
- CWE-125finds — Logging can record evidence of an out-of-bounds read but does not prevent the weakness itself.
- CWE-1274finds — Logging can detect unauthorized writes to volatile memory but does not prevent the weakness.
- CWE-1295prevents — Logging control requires that only necessary information is recorded, directly mitigating debug messages that leak sensitive data.
- CWE-1323prevents — Logging controls define where and how trace data may be stored.
- CWE-200finds — Cryptographic hashing, append-only storage, and access restrictions on log files limit an attacker’s ability to read or tamper with recorded sensitive information.
- CWE-202finds — Logging query activity supports detection of inference attempts after the fact.
- CWE-210prevents — Logging policy can require suppression of sensitive data in error messages.
- CWE-222prevents — Logging ensures security-relevant events are recorded without truncation that could hide attack details.
- CWE-223prevents — Logging directly requires recording security-relevant events that the weakness omits.
- CWE-269finds — Logging every use of privileges and protecting those records makes it harder for an attacker who has obtained elevated rights to operate without leaving evidence.
- CWE-284finds — Forbidding privileged users from deleting or altering their own logs prevents abuse of elevated rights to conceal unauthorized actions.
- CWE-360finds — Logging can capture event data but does not inherently validate its authenticity against spoofing.
- CWE-390finds — Logging captures error conditions but does not guarantee subsequent handling or remediation.
- CWE-400finds — Specifying log storage limits and rotation procedures reduces the risk that unbounded log growth will exhaust disk or memory resources and cause denial of service.
- CWE-406finds — Logging provides visibility into high-volume traffic but does not itself limit or control it.
- CWE-507finds — Logging can detect Trojan Horse activity after the fact but does not prevent its presence.
- CWE-509finds — Logging supports detection of malware activity and replication attempts.
- CWE-511finds — Logging can record execution of time- or logic-triggered code, aiding detection after the fact.
- CWE-515finds — Logging may record covert storage activity but does not prevent the channel itself.
- CWE-532prevents — Requiring de-identification and privacy controls before logs leave the organization reduces the chance that sensitive data inadvertently captured in logs becomes exposed to external parties.
- CWE-535mitigates — Logging can capture error messages but does not prevent their exposure to users.
- CWE-69finds — Logging of file-system events can record ADS access attempts, aiding detection, but does not prevent the weakness itself.
- CWE-74finds — Logging supports detection of injection attempts but does not prevent the weakness.
- CWE-75finds — Logging can record injection attempts for detection but does not prevent the weakness.
- CWE-754finds — Logging can record unhandled exceptions but does not prevent the weakness itself.
- CWE-755finds — Logging captures unhandled exceptions, aiding detection but not preventing the weakness.
- CWE-778prevents — Mandating comprehensive event logging with user IDs, timestamps, and access attempts directly eliminates the absence of audit trails that would otherwise allow undetected exploitation.
- CWE-779prevents — A.8.15 directly requires logging to be configured so that only necessary events are recorded, preventing excessive data.
- CWE-91finds — Logging can record injection attempts for detection but does not prevent the weakness.
Mitigated MITRE ATT&CK techniques (2132)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log review for malicious C2, correlation, and identification of probing or IOCs, which surfaces obfuscated C2 traffic when it deviates from baselines.
- T1001responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including probing or C2-like patterns via correlation, UEBA, DNS checks, etc.) once the obfuscated traffic is underway, which matches the `responds` verb; it is only partial because the clause stops at identification/investigation and does not itself perform containment or eradication.
- T1001.001detects — A.8.15 requires log analysis, anomaly detection via SIEM/IDS/UEBA, DNS log review for malicious C2, and correlation to identify indicators of compromise; this surfaces some junk-data C2 (especially non-trivial patterns or known IOCs) but leaves substantial residue for novel or obfuscated junk that evades signature/behavior rules.
- T1001.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log review for malicious C2, correlation of events, and identification of indicators of compromise including probing; this surfaces steganographic C2 traffic when it produces observable network, DNS, or behavioral artifacts in the logged events, though it cannot see purely in-band hidden payloads without detectable side effects.
- T1001.002responds — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and incident identification explicitly surface suspected C2 (including hidden channels) once underway for further investigation and response, but steganography's concealment leaves a large undetected slice outside typical log/IDS observables.
- T1001.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log review for malicious C2, correlation of events, and identification of suspected incidents such as probing, all of which surface protocol/service impersonation that blends with or mimics legitimate traffic.
- T1001.003responds — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and incident identification explicitly surface and feed into the incident management process (5.25) once impersonated C2 traffic is underway, but this is limited to detectable cases rather than all impersonation variants.
- T1003detects — Recording privileged utility execution, file access, and system configuration changes can reveal attempts to dump credentials from memory or registry stores.
- T1003responds — A.8.15's log analysis, anomaly detection, and incident identification (e.g. via SIEM/UEBA/correlation) surface credential-dumping artifacts once the technique has run, feeding the incident response process, but this is only a slice of full containment/eradication.
- T1003.001detects — A.8.15 explicitly requires logging of privilege use, system access attempts, configuration changes, and security system activation/deactivation, plus log analysis with SIEM/IDS/UEBA rules, anomaly detection, and correlation to identify indicators of compromise such as LSASS dumping or SSP modifications.
- T1003.001responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. anomalous behaviour, indicators of compromise) and feed them into the incident management process (5.25), which is the core of `responds`; it does not itself contain or eradicate the LSASS dump once underway.
- T1003.002detects — A.8.15 explicitly requires logging of privilege use, system access attempts, configuration changes, and file/registry accesses plus SIEM/UEBA/correlation analysis to surface anomalous behaviour and indicators of compromise such as SAM extraction tools or registry saves.
- T1003.002responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. anomalous access or probing) once underway and feed them into incident management (5.25), which matches the `responds` verb; it is only partial because the control stops at detection/analysis/correlation and does not itself perform containment or eradication.
- T1003.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of logs (including successful/rejected access, privilege use, file access/deletion, and security system events), and identification of suspected incidents such as probing or malware, which surfaces T1003.003 activity on domain controllers or backups in most cases.
- T1003.003responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. probing, anomalous access to protected resources or files) once underway for further investigation under incident management, but this is limited to detection-plus-handover rather than full containment/eradication of the NTDS copy or credential theft itself.
- T1003.004detects — A.8.15 explicitly requires logging of privilege use, system access attempts, configuration changes, and security system events plus SIEM/IDS/UEBA-driven analysis to surface anomalous behaviour and indicators of compromise such as credential dumping tools or registry reads of the LSA secrets hive.
- T1003.004responds — A.8.15 requires log analysis (including SIEM/IDS/UEBA rules, anomaly detection, correlation, and explicit review of access attempts and privilege use) to identify suspected incidents such as credential access; once the technique is underway this surfaces it for the incident management process (5.25) that contains and eradicates it.
- T1003.005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including successful/rejected access, privilege use, configuration changes, and physical events), and identification of indicators of compromise such as probing or malware, which surfaces T1003.005 extraction activity when it generates observable events on monitored systems.
- T1003.006detects — A.8.15 explicitly requires logging of privilege use, system access attempts, configuration changes, and security system events, plus SIEM/IDS/UEBA-driven analysis and correlation to surface anomalous behaviour and indicators of compromise such as DCSync replication requests from non-DC accounts.
- T1003.006prevents — A.8.15 mandates logging of privilege use, system access attempts, configuration changes and security system activation/deactivation (including on domain controllers), which can be configured to surface or block unauthorized DCSync replication attempts via monitoring rules; however, it does not stop the privileged user or process from performing the API abuse itself.
- T1003.006responds — A.8.15 requires log analysis, anomaly detection via SIEM/IDS/UEBA/correlation, and feeding suspected incidents (e.g. privilege use, config changes, access attempts) into the incident management process (5.25) for containment/eradication once DCSync is underway.
- T1003.007detects — A.8.15 explicitly requires logging of access attempts, privilege use, file accesses (including to /proc), configuration changes, and anomalous behaviour via log analysis, SIEM, UEBA, and correlation, which surfaces the T1003.007 technique when it reads credential patterns from proc filesystem files.
- T1003.008detects — A.8.15 explicitly requires logging of successful/rejected access attempts to files and resources, use of privileges, system activities, and log analysis (with SIEM/UEBA/IDS rules, anomalous behaviour detection, and correlation) that surfaces the cat/unshadow read of /etc/shadow as an indicator of compromise.
- T1003.008prevents — A.8.15 mandates logging of access attempts (successful/rejected) to resources including files like /etc/shadow, plus protection of those logs from tampering or deletion; this surfaces the T1003.008 read attempt in analysis and can deter or block it via accountability and integrity controls, but does not stop a root-privileged or bypassed adversary from reading the files themselves.
- T1005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts, file activity, privilege use and configuration changes — all of which surface the reconnaissance and collection behavior named by T1005 after it runs.
- T1005responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous file-access patterns, correlation) can surface T1005 once underway as an information security event, enabling further investigation under incident management, but this is only a slice of the technique's forms (e.g. in-memory or non-audited collection) rather than containment/eradication.
- T1006detects — A.8.15 explicitly requires logging of system activities, privilege use, file access (incl. deletion), configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the utilities and direct volume reads that bypass normal monitoring; the named remainder is the pre-log or non-monitored platform slice (e.g. network devices).
- T1007detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, configuration changes, utility-program execution, and anomalous behaviour (via SIEM/UEBA/threat-intel correlation), which surfaces the reconnaissance commands and their outputs that constitute T1007; the named remainder is unmonitored or non-logged endpoints where the technique can run silently.
- T1007responds — A.8.15 requires log analysis and monitoring (including of system activities, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation) to identify suspected incidents such as probing or malware, which can surface T1007 execution in an ongoing event for further incident handling (5.25); this is genuine but only a slice because the control's focus is post-execution detection rather than containment/eradication once the discovery technique is underway.
- T1008detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation across synchronized logs (including network, DNS, and physical), and identification of indicators like probing or outbound C2 — which surfaces fallback channel usage when it produces observable events.
- T1010detects — A.8.15 explicitly requires log analysis and monitoring of events (including system activities, privilege use, application transactions, anomalous behaviour via UEBA/SIEM/IDS correlation) that surfaces T1010's use of native commands/APIs to enumerate windows as an indicator of compromise or reconnaissance.
- T1010responds — A.8.15's log analysis and monitoring activities (including correlation, UEBA, anomalous behaviour detection, and review of access attempts) can surface T1010 once it runs as an indicator in event logs, but this is limited to cases where the enumeration produces observable events and is not the control's primary focus.
- T1011detects — A.8.15 requires log analysis and monitoring (including network/DNS/physical logs, anomalous behaviour, UEBA, and correlation) that can surface exfiltration over secondary media when it produces observable events inside the monitored scope, but the clause sets scope by policy and does not mandate coverage of all alternative media (Bluetooth, RF, cellular) or all platforms.
- T1011.001detects — A.8.15 requires log analysis and monitoring (including anomalous behaviour, network connections, physical events, and correlation) that can surface Bluetooth exfiltration when it produces observable events inside the chosen scope, but the clause sets that scope by policy rather than mandating Bluetooth-specific instrumentation, leaving many realisations (especially proximity-only, non-networked) outside what is required.
- T1012detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, resource access attempts, and anomalous behaviour via SIEM/UEBA/threat-intel analysis, which surfaces Registry queries performed by adversaries as part of discovery.
- T1014detects — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and review of access/system events can surface rootkit indicators (e.g. anomalous hooks, hidden processes via behavioral deviation), but rootkits are designed to evade exactly these logging and monitoring mechanisms at kernel/firmware levels.
- T1016detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, network-related events, and log analysis (including SIEM/UEBA, anomalous behaviour detection, DNS logs, and correlation) that surfaces T1016 execution or its artifacts post-facto.
- T1016.001detects — A.8.15 explicitly requires logging, analysis, and monitoring of network activity (including outbound connections, anomalous behaviour, DNS logs, and correlation) that surfaces Internet Connection Discovery as an indicator of compromise or unusual activity.
- T1016.001responds — A.8.15's log analysis and monitoring explicitly surface anomalous outbound activity (e.g. DNS, connections to known-malicious C2) and feed incident handling, which is the `responds` act once discovery is underway; it is only a slice because the control does not itself contain/eradicate the actor or the already-completed discovery.
- T1016.002detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including via UEBA, SIEM, correlation, and review of access attempts), which can surface Wi-Fi discovery commands, file reads, or API calls as indicators of compromise; partial because the control's scope is set by what the organization chooses to log/monitor and does not mandate coverage of all Wi-Fi-specific discovery artifacts across platforms.
- T1018detects — A.8.15 explicitly requires logging, protection, and analysis of events including system access attempts, privilege use, configuration changes, network activity, alarms, and anomalous behaviour via SIEM/UEBA/correlation to identify indicators of compromise such as discovery commands or unusual network enumeration.
- T1018responds — A.8.15 requires log analysis (including correlation, UEBA, SIEM/IDS rules, and review of access attempts, alarms, and anomalous behavior) plus identification of suspected incidents for further investigation under the incident management process, which directly enacts containment/eradication once discovery activity is underway.
- T1020detects — A.8.15 requires determining, collecting, protecting, and analyzing logs of events including access attempts, configuration changes, privilege use, file access/deletion, alarms, and anomalous behavior via SIEM/UEBA/threat intel/correlation; this surfaces automated exfiltration (and its prerequisite collection) as an information security event or indicator of compromise in most cases, though some stealthy automated exfil may evade the defined logging scope.
- T1020responds — A.8.15's log analysis, anomaly detection, and incident identification (e.g. via SIEM/UEBA/correlation) surface and trigger response to automated exfiltration once underway, with the named remainder being fully stealthy/encrypted transfers that produce no observable events.
- T1020.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, DNS log review for malicious C2, correlation of logs including physical events, and identification of suspected incidents such as probing, all of which surface traffic mirroring or its exfiltration artifacts after the technique runs.
- T1021detects — Recording remote-service connections, privilege escalations, and network-address details helps identify lateral-movement activity over protocols such as RDP or SMB.
- T1021prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour analysis (with time sync and integrity protection), which can surface or deter some T1021 abuse of valid accounts over remote services but does not stop the login or execution itself.
- T1021responds — A.8.15 requires log analysis (including correlation, UEBA, SIEM/IDS rules, and review of access attempts) plus identification of suspected incidents for further investigation under the incident management process, which directly enacts the containment/eradication steps that `responds` names once the remote-service technique is underway.
- T1021.001detects — A.8.15 explicitly requires logging of successful/rejected access attempts, use of privileges, system activities, and log analysis (with SIEM/UEBA/IDS correlation and anomaly detection) that surfaces RDP logins by valid accounts as potential indicators of compromise or anomalous behavior.
- T1021.001prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour analysis (with time sync and integrity protection), which can surface or block unauthorized RDP logons before lateral movement succeeds; it does not stop the technique when valid credentials and an enabled RDP service are already present.
- T1021.001responds — A.8.15 requires log analysis and correlation (including of successful/failed access attempts, privilege use, and anomalous behaviour) to identify suspected incidents such as unauthorized RDP logons for further investigation under the incident management process; this is the core of `responds` once the technique is underway, but only a slice because the clause does not itself contain or eradicate the RDP session or actor foothold.
- T1021.002detects — A.8.15 explicitly requires logging, protection, and analysis of events including successful/rejected access attempts, use of privileges, file access/deletion, network activity, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces SMB admin share access (especially when paired with valid accounts or pass-the-hash) as an indicator of compromise.
- T1021.002prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes, and file access/deletion (including on network shares), plus analysis to surface anomalous behaviour; this can prevent the technique when it would be stopped by detection of the initial access or early lateral movement, but leaves the bulk of the technique (valid-account SMB/RPC execution, pass-the-hash variants, and post-access actions) untouched.
- T1021.002responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. anomalous access, privilege use, configuration changes) once the SMB share interaction is underway, feeding into incident response per 5.25, but does not itself contain or eradicate the active adversary session.
- T1021.003detects — A.8.15 explicitly requires logging, protection, and analysis of events including successful/rejected access attempts, privilege use, system configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces DCOM lateral movement (T1021.003) when it occurs.
- T1021.003prevents — A.8.15 mandates logging of access attempts, privilege use, configuration changes, and anomalous behaviour (with analysis via SIEM/UEBA), which can surface and deter some DCOM lateral movement by privileged accounts but does not stop the technique from running when valid credentials and ACLs permit it.
- T1021.003responds — A.8.15 requires log analysis, correlation, and identification of suspected incidents (including probing or anomalous remote access) to feed the incident management process (5.25), which directly enables containment/eradication once DCOM lateral movement is underway; partial because it only surfaces the event rather than performing the response actions.
- T1021.004detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, system activities, and log analysis (with SIEM/UEBA/correlation/threat intel) to identify anomalous behaviour and indicators of compromise such as unauthorized SSH logins by valid accounts.
- T1021.004prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour analysis (including SSH logins), which can surface misuse of valid accounts before further actions; this constrains the technique in monitored environments but does not stop the initial authorized SSH login itself.
- T1021.004responds — A.8.15 requires log analysis, correlation, anomaly detection (including successful access attempts, privilege use, configuration changes), and explicit routing of suspected incidents into the incident management process (5.25), which directly enacts containment/eradication once the SSH login technique is underway.
- T1021.005detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, system activities, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces VNC-based remote access and post-auth abuse as security events or indicators of compromise.
- T1021.005prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour (with analysis and correlation), which can surface and thereby deter some abuse of valid accounts over VNC but does not stop the technique from running.
- T1021.005responds — A.8.15 requires log analysis, anomaly detection, correlation, and identification of suspected incidents (including probing or unauthorized access attempts) to feed the incident management process (5.25), which directly enacts the containment/eradication steps that `responds` names once the VNC technique is underway.
- T1021.006detects — A.8.15 explicitly requires logging, protection, and analysis of events including successful/rejected access attempts, use of privileges, system activities, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces WinRM-based remote interaction by a valid account as an indicator of compromise.
- T1021.006prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, system changes, and anomalous behaviour (with analysis and correlation), which can prevent some abuse of valid accounts via WinRM by enabling detection and blocking before or during execution, but does not stop the technique itself from running when valid credentials are presented.
- T1021.006responds — A.8.15 requires log analysis, correlation, and identification of suspected incidents (including anomalous access and privilege use) to trigger further investigation under the incident management process, which directly enacts the `responds` verb once the WinRM technique is underway.
- T1021.007detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour analysis (SIEM/UEBA/threat intel/correlation), which surfaces T1021.007 logins and post-auth actions in cloud environments; the named remainder is fully stealthy or non-logged sessions outside the defined scope.
- T1021.007responds — A.8.15 requires log analysis (including correlation, UEBA, SIEM/IDS rules, and review of access attempts) to identify suspected incidents such as anomalous logins or probing, then routes them to incident management (5.25) for response once the technique is underway.
- T1021.008detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, system activities, configuration changes, and log analysis (with SIEM/UEBA/threat intel/correlation) that surfaces anomalous direct VM console logins as indicators of compromise or incidents.
- T1021.008prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes and anomalous behaviour (with analysis to surface indicators of compromise), which can prevent some abuse of valid accounts for direct cloud VM console access by enabling timely detection and response before pivoting; however, it does not stop the initial authentication or connection itself.
- T1021.008responds — A.8.15's log analysis, correlation, anomaly detection (including successful/failed access, privilege use, configuration changes), and identification of suspected incidents directly support responding to (containing/eradication steps for) an in-progress T1021.008 session once underway.
- T1025detects — A.8.15 requires log analysis and monitoring (including of file access, removable media via physical logs, anomalous behaviour, and correlation) that can surface the T1025 technique after it runs, but this is scoped by what the organization chooses to log/monitor and does not guarantee detection of all instances (e.g. non-logged USB activity or unmonitored physical access).
- T1027detects — A.8.15 mandates log analysis (including UEBA, SIEM rules, anomaly detection, DNS logs, and correlation) that can surface indicators of obfuscation such as anomalous file activity or encoded payloads, but this is scoped by what the organization chooses to log/monitor and does not inherently catch all obfuscation variants (e.g., in-transit, command obfuscation, or split benign files).
- T1027responds — A.8.15's log analysis and anomaly detection (SIEM/UEBA/IDS correlation, review of access attempts and alarms) can surface obfuscated payloads or commands once they trigger observable events, enabling response; this is limited to post-execution detection rather than containing or eradicating the technique itself.
- T1027.001detects — A.8.15 requires log analysis and monitoring for anomalous behaviour, indicators of compromise, and unusual activity (including via SIEM, UEBA, trend/pattern analysis and threat intel), which can surface binary padding as an IOC when it produces observable anomalies such as oversized files or checksum mismatches in collected logs; this is a genuine but minority slice of the technique's evasion surface.
- T1027.002detects — A.8.15 requires log analysis (with SIEM/IDS/UEBA/threat intel) and specific monitoring to surface anomalous behaviour and indicators of compromise, which can catch many packing artifacts or post-unpacking execution; it does not guarantee detection of novel/custom packers that leave no observable artifacts in the listed events.
- T1027.003detects — A.8.15 requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and review of events (including file access, system changes, network activity, and physical logs) that can surface steganography indicators such as unusual image exfiltration or anomalous behavior, but does not guarantee detection of the hidden payload itself or cover all stego techniques.
- T1027.003responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of logs including network/DNS/physical) can surface steganography indicators once the technique has run and produced observable artifacts (e.g. unusual exfil images or patterns), which is the core of `responds`; it is only partial because the control's scope is limited to what is logged and analysed per the organisation's policy, leaving many stego carriers (audio, video, non-monitored files) outside its view.
- T1027.004detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including via SIEM/UEBA/threat intel), which can surface the use of native compilers or unusual compilation activity after delivery; this is a genuine but minority slice of the technique, as most instances occur without producing detectable log events or anomalous patterns that analysis would reliably flag.
- T1027.004responds — A.8.15's log analysis and monitoring for anomalous behaviour (SIEM/UEBA/IDS correlation, review of access attempts, unusual activity) can surface the compilation step or its precursors once underway, enabling incident response, but does not act on or contain the technique itself and leaves the bulk of delivery/embedding unseen.
- T1027.005detects — A.8.15 requires log analysis and monitoring to identify indicators of compromise, anomalous behaviour, malware infection and probing, which surfaces many (but not all) cases of an adversary removing indicators from a tool after detection/quarantine
- T1027.006detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, unusual activity (including via SIEM/IDS/UEBA rules, DNS logs, and correlation), which surfaces HTML smuggling as a delivery vector when it triggers logged events or anomalies; this is genuine but only a slice because the technique is designed to produce benign-looking MIME content that evades filters and many standard log patterns.
- T1027.006responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and identification of suspected incidents (e.g. probing or malware) directly enables response once HTML smuggling has occurred and is underway.
- T1027.007detects — A.8.15 mandates log analysis, SIEM/IDS rules, UEBA, anomaly detection on events (including process/file activity and privilege use) plus correlation to surface indicators of compromise; this surfaces some in-flight or post-execution artifacts of dynamic API resolution on Windows but leaves large slices (purely in-memory resolution with no observable call, no anomalous pattern, or no matching rule) unreached.
- T1027.008detects — A.8.15 requires log analysis and monitoring (SIEM/IDS/UEBA/threat intel/anomaly detection) that can surface stripped payloads as unusual/malicious binaries or anomalous behavior during incident analysis, but this is indirect, depends on other tools, and leaves many stripped payloads undetected until later stages.
- T1027.009detects — A.8.15 requires log analysis and monitoring (SIEM/UEBA/IDS rules, anomalous behaviour detection, correlation of access/config/privilege events) that can surface embedded-payload indicators once they trigger observable events, but the control does not mandate detection of the embedding act itself or of payloads that never reach a logged event.
- T1027.009responds — A.8.15's log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomalous behaviour detection, correlation) can surface indicators once an embedded-payload technique has executed and produced observable events, but the control stops at identification and hands off to incident handling without containing or eradicating the payload itself.
- T1027.010detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including command-line and system activities), and identification of indicators of compromise such as probing or malware that can surface obfuscated commands in logs.
- T1027.010responds — A.8.15 requires log analysis and correlation (including UEBA, SIEM/IDS rules, anomalous behaviour detection, and physical logs) to identify suspected incidents such as probing or malware once they are underway, which matches the `responds` verb; it is only partial because the control stops at detection/analysis and hands off to incident handling (5.25) rather than performing containment/eradication itself.
- T1027.011detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of events (including those in event logs, configuration changes, privilege use, and alarms) to surface indicators of compromise; this directly surfaces fileless storage activity that touches or generates observable events in those very stores (Windows event logs, Registry changes, shared-memory anomalies), though some purely in-RAM or heavily obfuscated cases remain outside routine log-based detection.
- T1027.011responds — A.8.15's log analysis and monitoring explicitly target anomalous behaviour and indicators of compromise (including in event logs themselves), enabling response once fileless storage activity is underway; this is bounded to detectable slices rather than all obfuscated or non-log forms.
- T1027.012detects — A.8.15 explicitly requires logging and analysis of events including successful/rejected access attempts, file access/deletion, privilege use, system configuration changes, alarms from access control/IDS, anomalous behaviour via SIEM/UEBA/threat intel, and correlation of logs (including physical) to identify indicators of compromise and suspected incidents such as malware or probing; this surfaces LNK icon smuggling when it triggers observable events on Windows (e.g. malicious download, invocation, or post-compromise execution) but leaves a bounded remainder for stealthy cases that generate no logged anomaly.
- T1027.012responds — A.8.15's log analysis and monitoring explicitly surface indicators of compromise, anomalous behaviour and suspected incidents (including post-compromise payload downloads), enabling further investigation under incident management, but the technique's smuggling and LNK metadata abuse can occur without generating a detectable log event.
- T1027.013detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of events such as file access/deletion, configuration changes, and privilege use that can surface indicators of obfuscated malicious files (e.g. anomalous payloads or logs), but does not guarantee detection of the obfuscation itself or cover all file artifacts.
- T1027.014detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and correlation of events (including malware signatures and indicators of compromise) which surfaces polymorphic malware in flight or post-execution; it is limited to a slice because polymorphic code is designed to evade signature-based and many behavioral detections, leaving substantial residue outside monitored scopes or novel mutations.
- T1027.014responds — A.8.15's log analysis and monitoring explicitly surface indicators of compromise, anomalous behaviour and suspected incidents (including malware), which can be triggered by polymorphic code's execution footprint changes, enabling response once underway; partial because it depends on the specific anomalous patterns being logged/analyzed rather than guaranteeing response to all polymorphic mutations.
- T1027.015detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/patterns/threat intel, and monitoring of file access/deletion, system activities, and suspicious events that can surface compressed or concatenated archives used for obfuscation or delivery.
- T1027.016detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including via UEBA, SIEM, IDS signatures, and correlation), which can surface the presence or effects of junk-code-obfuscated malware; this is a genuine but minority slice because the control does not specifically target or reliably identify the obfuscation technique itself.
- T1027.017detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules, correlation of logs (including from web/file/DNS/physical sources), and identification of indicators like probing or malware that can surface SVG smuggling when the technique produces observable events in those monitored channels; it does not guarantee coverage of all delivery vectors or silent SVG-embedded payloads.
- T1027.017responds — A.8.15's log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomaly detection, correlation of events including file access and security system alarms) can surface SVG smuggling once the malicious payload executes or triggers observable behavior, enabling incident response; this is limited to post-execution detection of effects rather than the smuggling act itself.
- T1027.018detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspicious events (including via SIEM, UEBA, pattern analysis and correlation), which can surface the presence of invisible Unicode in files/scripts as part of broader anomaly or IOC detection; it does not specifically target or guarantee detection of this Unicode abuse technique.
- T1029detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/pattern analysis, correlation of logs (including network activity and timing), and identification of indicators of compromise or unusual behavior, which surfaces scheduled exfiltration blending with normal traffic patterns.
- T1029responds — A.8.15's log analysis, anomaly detection, correlation, and identification of suspected incidents (including unusual outbound patterns or probing) directly supports containment/eradication response once scheduled exfiltration is underway, with the named remainder being fully stealthy timing that evades all detection rules.
- T1030detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, DNS log review for malicious outbound connections, and correlation of logs (including network activity) to identify indicators of compromise; this surfaces the technique when chunked transfers deviate from known patterns, but only where such monitoring is scoped in and the evasion does not fully mimic normal traffic.
- T1033detects — A.8.15 requires log analysis and monitoring of events (including successful/unsuccessful access attempts, privilege use, and anomalous behaviour via SIEM/UEBA/correlation) that can surface T1033 execution or its artifacts in logs, but this depends on chosen scope, does not cover all platforms or non-log-based discovery methods, and stops at identification rather than guaranteeing detection of every instance.
- T1036detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts, configuration changes, privilege use, and process activity — all of which surface masquerading artifacts (renamed binaries, spoofed metadata, fake service names) once they execute and generate observable events.
- T1036responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation) can surface masquerading once underway as an indicator of compromise, enabling incident response, but this is a minority slice of the broad technique (many masquerading variants leave no detectable log artifact).
- T1036.001detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, unusual activity (including via SIEM, UEBA, trend/pattern analysis and threat intelligence), plus correlation of logs across systems; this surfaces the use of invalid/mimicked code signatures when they trigger events, alarms, or deviate from known patterns.
- T1036.002detects — A.8.15 explicitly requires log analysis and monitoring for anomalous behaviour, indicators of compromise, and correlation of events (including file access, system activities, and unusual patterns via UEBA/SIEM), which surfaces disguised filenames or RTLO abuse when it appears in logged events, but this depends on whether the specific anomalous display or file metadata is within the chosen scope of logging and analysis rules.
- T1036.003detects — A.8.15 explicitly requires logging of utility-program use, privilege use, process/file activity and anomalous behaviour, plus SIEM/UEBA/correlation analysis that surfaces renamed binaries masquerading as legitimate utilities (the exact T1036.003 evasion); the named remainder is fully stealthy renames that produce no observable deviation from baseline.
- T1036.003responds — A.8.15's log analysis and monitoring explicitly surface renamed-utility anomalies (via UEBA, pattern/trend analysis, correlation, and review of access/execution events) once the technique has run, feeding into incident handling; this is genuine response but only a slice, as the clause does not itself contain/eradicate the actor or artifact.
- T1036.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including process/task/service activity, privilege use, configuration changes), and identification of indicators of compromise, which surfaces masquerading of tasks/services when they deviate from known benign patterns.
- T1036.004responds — A.8.15's log analysis and monitoring explicitly surface anomalous behaviour and suspected incidents (including via UEBA, SIEM, IDS, and correlation of events such as privilege use, configuration changes, and service activity), enabling response once the masquerading technique has run; it does not itself contain or eradicate.
- T1036.005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/pattern matching, correlation of events (including file access, privilege use, configuration changes, and creation of identities/resources), and identification of indicators of compromise, which surfaces most instances of masquerading via legitimate-looking names/locations after the fact.
- T1036.005responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of access/configuration/privilege events) can surface indicators once the masquerading resource is used or creates observable activity, which is the core of `responds` once the technique is underway; it is only a slice because the placement itself is silent and many instances produce no detectable deviation from legitimate patterns.
- T1036.006detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including via UEBA, SIEM, and correlation of file-access, privilege-use, and process events), which can surface the suspicious double-click/execution of a disguised file, but does not guarantee detection of this specific macOS/Linux filename trick.
- T1036.007detects — A.8.15 explicitly requires log analysis and monitoring of events (including file access, resource access attempts, alarms, anomalous behaviour via UEBA/SIEM/IDS, and correlation with physical logs) that can surface double-extension masquerading when it triggers observable indicators, but this is limited to post-execution or specific monitored contexts rather than universal detection of the filename technique itself.
- T1036.008detects — A.8.15 explicitly requires logging of file accesses/deletions, privilege use, configuration changes, and anomalous behaviour via log analysis (SIEM/UEBA/patterns/threat intel), which surfaces masquerading artifacts (e.g. mismatched signatures/extensions, polyglots) post-placement as indicators of compromise.
- T1036.008responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous file-access patterns, correlation of successful/rejected accesses and physical events) can surface indicators once a masqueraded payload is transferred, stored or executed, enabling incident response; this is genuine but only a slice because the technique itself is not an event that is reliably logged or anomalous until after execution or specific detection rules are triggered.
- T1036.009detects — A.8.15 explicitly requires log analysis and monitoring of system activities, process-related events (use of privileges, utility programs, file access, alarms), anomalous behaviour via UEBA/trend analysis/correlation, and inclusion of physical monitoring to surface indicators of compromise such as unusual process tree patterns after the double-fork or daemon techniques run.
- T1036.010detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, unusual account creation/renaming patterns, and correlation of events (including identity creation and privilege use), which surfaces T1036.010 post-execution; the named remainder is stealthy or non-logged masquerading outside monitored scope.
- T1036.010responds — A.8.15 requires log analysis and correlation (including of account creation, privilege use, identity changes, and anomalous patterns) to identify suspected incidents once underway for further investigation under incident management; this is the core of `responds` but only a slice because the control stops at detection/analysis and does not itself perform containment or eradication.
- T1036.011detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including via UEBA, SIEM, process activity patterns, and correlation of logs such as command-line arguments visible in /proc/<PID>/cmdline or ps output), which surfaces the in-memory argument overwrite once it has occurred.
- T1036.012detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and correlation of events (including network activity, access attempts, and outbound connections) to surface indicators of compromise; spoofed browser fingerprinting that deviates from baselines or known patterns is detectable in those logs, though coverage is not exhaustive for all stealth variants or non-logged traffic.
- T1036.012responds — A.8.15's log analysis and monitoring explicitly surface anomalous behaviour and indicators of compromise (including via UEBA, pattern analysis, DNS logs, and correlation), which can respond to and help contain an in-flight T1036.012 masquerading attempt once underway; this is bounded by the fact that the technique is designed to blend with legitimate traffic and many spoofed attributes are not logged or flagged as anomalous.
- T1037detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of boot/logon events, and review of successful/failed access and privilege-use logs, which surfaces T1037 execution or its persistence artifacts after the fact.
- T1037responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/UEBA/IDS rules on events like privilege use, config changes, or boot-time activity) enable response once the persistence script has executed and produced observable artifacts, but this is limited to detection-driven response rather than containment/eradication of the script itself.
- T1037.001detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, system configuration changes, and log analysis (with SIEM/UEBA/threat intel) that surfaces anomalous logon behavior and indicators of compromise such as unexpected logon scripts.
- T1037.001responds — A.8.15's log analysis and monitoring explicitly surface anomalous logon activity and suspected incidents (including persistence mechanisms) for investigation under the incident management process, which is the core of `responds`; it is only partial because the control's scope is limited to what is logged and analyzed rather than guaranteeing containment or eradication of the already-executed script.
- T1037.002detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, identity creation/modification, and log analysis (including SIEM/UEBA rules, anomalous patterns, and correlation) that surfaces login-hook plist modifications or root-privilege script execution as indicators of compromise.
- T1037.002responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including configuration changes, privilege use, and security system events that can surface a login-hook modification), then feeds them into incident management (5.25) for response; this acts once the technique is underway but only on the subset of observable events rather than containing or eradicating the hook itself.
- T1037.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of events (including logon, privilege use, script/application execution, and configuration changes), and identification of indicators of compromise, which surfaces the execution of a network logon script for persistence.
- T1037.004detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, file accesses/deletions, security system activation, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces RC script modification (a privileged config change) and its post-reboot effects as indicators of compromise.
- T1037.005detects — A.8.15 explicitly requires logging of boot-time events (system activities, privilege use, configuration changes, startup of security systems), log analysis with UEBA/SIEM/IDS rules to surface anomalous behaviour, and correlation of logs (including physical) to identify indicators of compromise such as unauthorized persistence mechanisms.
- T1037.005responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including changes to system configuration, use of privileges, file access/deletion, and alarms), which once the persistence technique has run enables containment/eradication via the incident management process; it is partial because the control is silent on the specific macOS boot-phase artifacts and the deprecated technique leaves a bounded remainder outside routine log coverage.
- T1039detects — A.8.15 explicitly requires logging and analysis of file/resource access attempts (including on network shares), privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation to surface indicators of compromise such as unusual data collection from shared drives.
- T1040detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, threat intel correlation, and specific monitoring (DNS logs for C2, physical logs, access attempts) to surface anomalous behaviour and indicators of compromise that include network sniffing and its artifacts.
- T1040responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. probing of firewalls, unusual activity) directly support responding to sniffing once underway by surfacing it as an event/incident for containment and eradication; the remainder is passive sniffing that produces no observable log anomaly.
- T1041detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of network activity (including DNS and outbound connections to malicious C2 servers) to surface indicators of compromise such as exfiltration over an existing channel.
- T1041responds — A.8.15 requires log analysis, monitoring for anomalous behaviour (including outbound C2 connections via DNS logs and UEBA), correlation, and identification of suspected incidents for further investigation under the incident management process, which directly enacts the `responds` verb once exfiltration is underway.
- T1046detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of network activity (including DNS logs for outbound C2, access attempts, and correlation) that surfaces the scanning/probing behavior described in T1046.
- T1046prevents — A.8.15 mandates logging of access attempts, privilege use, configuration changes, alarms from access-control/IDS systems, and anomalous behaviour analysis (including network patterns and threat intel), which can prevent some discovery techniques (e.g. noisy port scans triggering logged alarms or UEBA) but leaves the bulk of stealthy/local/Bonjour/mDNS/cloud methods untouched.
- T1046responds — A.8.15 requires log analysis and correlation (including of network, DNS, firewall, IDS, and physical events) to identify anomalous behaviour such as probing or scanning that can represent indicators of compromise, then routes suspected incidents to the incident management process (5.25) for response once underway; this matches the `responds` verb but is only a slice because the control is silent on containment/eradication actions themselves and many T1046 instances (e.g. local Bonjour/mDNS queries or unmonitored cloud port scans) fall outside the prescribed logging/analysis scope.
- T1047detects — A.8.15 explicitly requires logging of system activities, privilege use, process/application execution, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces WMI abuse (local/remote execution, wmic/PowerShell/COM) as an information security event or indicator of compromise.
- T1047responds — A.8.15 requires log analysis, anomaly detection, correlation, and explicit routing of suspected/actual incidents (including those from privileged tool use such as WMI) into the incident-management process (5.25), which is exactly the containment/eradication act that `responds` names once the technique is underway.
- T1048detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of logs (including network activity, DNS, file access, and outbound connections to malicious servers), and identification of indicators of compromise such as probing or unusual data transfers, which surfaces most instances of T1048 exfiltration over alternate protocols.
- T1048responds — A.8.15's log analysis, anomaly detection, correlation, and identification of suspected incidents (including outbound connections to malicious servers) directly supports containment/eradication once exfiltration is underway, with the named remainder being fully stealthy/obfuscated channels that produce no observable events.
- T1048.001detects — A.8.15 explicitly requires logging, protection, and analysis of network events, successful/rejected access attempts, anomalous behaviour via SIEM/UEBA/correlation/DNS monitoring, and indicators of compromise, which surfaces symmetric-exfiltration activity on supported platforms.
- T1048.001responds — A.8.15's log analysis, correlation, and identification of anomalous events (including outbound connections and unusual network activity) surfaces suspected exfiltration in flight for further incident response per 5.25, but does not itself contain or eradicate the ongoing technique.
- T1048.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of logs (including network events, DNS, and physical), and identification of indicators of compromise such as probing or outbound connections to malicious servers, which surfaces exfiltration over asymmetric encrypted protocols like HTTPS/TLS when it generates observable events.
- T1048.002responds — A.8.15 requires log analysis and correlation (including network/DNS/UEBA patterns and physical events) to identify suspected incidents such as probing or exfiltration, then feeds them into the incident management process (5.25) for response; this acts once the technique is underway but only on detectable slices, leaving encrypted non-C2 flows without clear indicators or physical correlation as a remainder.
- T1048.003detects — A.8.15 explicitly requires logging, protection, and analysis of network events, DNS logs, anomalous outbound connections, and correlation to identify indicators of compromise such as data exfiltration over unencrypted protocols (HTTP/FTP/DNS).
- T1048.003responds — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and incident identification explicitly surface and feed suspected exfiltration events (including over unencrypted protocols) into the incident management process (5.25) for response once underway.
- T1049detects — A.8.15 explicitly requires logging of network-related events (system activities, network addresses/protocols, resource access attempts, alarms from access control/IDS, physical monitoring) plus mandated analysis/SIEM/UEBA/correlation to surface anomalous behaviour and indicators of compromise such as discovery commands (netstat, lsof, who, show ip sockets, etc.) once they execute.
- T1049responds — A.8.15 requires log analysis and correlation (including of network, access, and anomalous events) to identify suspected incidents such as probing, which can surface T1049 in flight for further investigation under incident management, but does not contain/eradicate the running discovery action itself.
- T1052detects — A.8.15 explicitly requires logging and analysis of physical access events, device identities, successful/failed resource access attempts, and correlation with physical monitoring logs to surface anomalous behaviour that can represent indicators of compromise, which would surface T1052 use of removable media in many (but not all) cases.
- T1052.001detects — A.8.15 explicitly requires logging and analysis of events including USB/physical device access, file access/deletion, successful/failed resource attempts, and correlation with physical monitoring to surface anomalous exfiltration indicators; this is genuine detection but only a slice because it depends on what the organization chooses to log/analyze and does not mandate coverage of all USB exfil vectors or real-time detection.
- T1053detects — A.8.15 explicitly requires logging, protection, and analysis of events including use of privileges, system activities, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces scheduled task abuse both in creation and execution on covered platforms.
- T1053responds — A.8.15 requires log analysis and correlation (including of privilege use, config changes, scheduled tasks via system activities and alarms) to identify and investigate suspected incidents once underway, which is the core of `responds`; it is only partial because the clause stops at detection/analysis hand-off to incident management (5.25) and does not itself perform containment or eradication.
- T1053.002detects — A.8.15 explicitly requires logging of privilege use, system activities, scheduled-task-like events, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces at/abuse of the scheduler both in real time and during investigation.
- T1053.002prevents — A.8.15 mandates logging of privilege use, system activities, configuration changes, and access attempts (including those tied to at/scheduled jobs), plus analysis for anomalous behaviour; this surfaces the technique after it runs but does not stop adversaries from invoking at for persistence/execution/escalation.
- T1053.002responds — A.8.15 requires logging of privilege use, system activities, configuration changes, alarms, security system activation, and anomalous behaviour via SIEM/IDS/UEBA correlation; once the at-scheduled malicious task executes these produce detectable events that feed incident identification and response.
- T1053.003detects — A.8.15 explicitly requires logging of privilege use, system activities, configuration changes, scheduled tasks via utilities, and log analysis (with SIEM/UEBA/correlation) that surfaces anomalous scheduled execution as an indicator of compromise.
- T1053.005detects — A.8.15 explicitly requires logging and analysis of events including use of privileges, system activities, configuration changes, application transactions, anomalous behaviour via SIEM/UEBA/IDS rules, and correlation of logs (including physical), which surfaces scheduled task abuse for persistence, execution, or hiding as an information security event or indicator of compromise.
- T1053.005prevents — A.8.15 mandates logging of privilege use, system configuration changes, access attempts, and anomalous behaviour (with SIEM/UEBA correlation), which can block many abuse paths for task creation/execution by surfacing them before or during persistence/lateral movement; it does not stop the scheduler APIs or hidden-task techniques themselves.
- T1053.005responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. anomalous scheduled-task creation/use via reviewed access attempts, privilege use, configuration changes, alarms) for further investigation under incident management, but this is after the technique has run and only for the detectable non-hidden slice
- T1053.006detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, file access/deletion, security system activation, identity creation/modification, and anomalous behaviour via log analysis (SIEM/UEBA/IDS rules, correlation, trend analysis), which surfaces systemd timer installation and activation as suspicious scheduled/persistence activity on Linux.
- T1053.006responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of logs including system activities, privilege use, configuration changes, and security system activation) can surface systemd timer abuse once the .timer/.service files are created or executed, enabling incident response; this is a genuine but minority slice of the technique's full lifecycle (creation, remote activation, persistence).
- T1053.007detects — A.8.15 explicitly requires logging, analysis, and monitoring of events including system activities, privilege use, configuration changes, scheduled tasks/utility programs, anomalous behaviour via SIEM/UEBA/IDS rules, and correlation of logs (with time sync) to identify indicators of compromise such as malware or probing; this surfaces T1053.007 abuse of container orchestration jobs in monitored environments, though coverage depends on whether the specific container events fall inside the organization's defined logging scope.
- T1053.007responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. anomalous behaviour, malware, probing) for further investigation under incident management (5.25), which is the core of `responds`; it does not itself contain/eradicate the running job or its persistence.
- T1055detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, correlation, and monitoring of access attempts, privilege use, system changes, alarms, and physical events — all of which surface process injection in flight as anomalous behavior or an indicator of compromise, with the bounded remainder being injections into unmonitored processes or those that produce no observable events.
- T1055responds — A.8.15 requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and explicit identification of suspected incidents (e.g. probing or malware) for further investigation under the incident management process, which directly enacts the containment/eradication acts that `responds` names once the technique is underway.
- T1055.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of events (including process, privilege-use, system-activity and access logs), and identification of indicators of compromise such as malware or probing, which surfaces in-process DLL injection when the observable artifacts fall inside the monitored scope.
- T1055.001responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS correlation, and explicit tie-in to incident identification/investigation (5.25) enable containment and eradication once DLL injection is underway, with the named remainder being the pre-detection impact already realized.
- T1055.002detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, threat intel correlation, and specific monitoring of access attempts, alarms, privilege use, process activities, and anomalous behaviour — all of which surface PE injection in flight as an information security event or indicator of compromise.
- T1055.002responds — A.8.15 requires log analysis, monitoring for anomalous behaviour, correlation, and identification of suspected incidents (including via SIEM/IDS/UEBA) which can surface PE injection once underway as part of incident handling, but this is after-the-fact knowledge with no containment/eradication act asserted by the control itself.
- T1055.003detects — A.8.15 explicitly requires logging of process/thread activities, privilege use, system changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces Thread Execution Hijacking indicators (suspicious SuspendThread/WriteProcessMemory/SetThreadContext sequences under a legitimate process) post-execution.
- T1055.003responds — A.8.15 requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of events (including process, privilege-use, system-activity and security-system activation logs), and feeding of suspected incidents into the incident-management process (5.25); this surfaces and enables response to in-flight thread hijacking but does not itself contain or eradicate it.
- T1055.004detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection on process behavior, privilege use, system activities, and correlation to surface indicators of compromise such as APC injection masked under legitimate processes.
- T1055.004responds — A.8.15's log analysis and monitoring explicitly surface anomalous behaviour and suspected incidents (including malware and probing) once they occur, feeding into incident handling (5.25); this is the core of `responds` but remains partial because APC injection is often in-process, masked under legitimate processes, and not guaranteed to trigger the specific events or patterns the control logs/analyzes.
- T1055.005detects — A.8.15 explicitly requires logging, protection, and analysis of events including system activities, privilege use, process/resource access attempts, alarms from access control/IDS, anomalous behaviour via SIEM/UEBA/correlation, and indicators of compromise such as malware or probing, which surfaces TLS callback injection in flight as anomalous execution under a legitimate process.
- T1055.005responds — A.8.15's log analysis, correlation, SIEM/IDS/UEBA rules, and incident identification explicitly surface in-flight anomalous behaviour (including process-injection artifacts) for further investigation under the incident management process, which is the core of `responds`; it is only partial because the clause sets requirements for what is logged/analysed rather than mandating universal detection of every TLS-callback manipulation.
- T1055.008detects — A.8.15 explicitly requires logging of system activities, privilege use, process-relevant events, alarms from access-control/IDS systems, and log analysis (with UEBA, SIEM, IDS signatures, anomalous behaviour detection, and correlation) that surfaces ptrace-based injection as an indicator of compromise or anomalous process modification.
- T1055.008responds — A.8.15 requires log analysis, anomaly detection, correlation, and identification of suspected incidents (including probing or malware-like behavior) to feed the incident management process (5.25), which directly enacts the containment/eradication act that `responds` names once the ptrace injection is underway.
- T1055.009detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection on process/activity events, correlation across logs (including system, privilege use, and security-system activation), and identification of indicators of compromise such as probing or anomalous behaviour, which surfaces proc-memory injection in flight on Linux systems where those events are logged.
- T1055.009responds — A.8.15 requires log analysis, anomaly detection, correlation, and identification of suspected incidents (including probing or malware-like behavior) to feed incident response; this surfaces proc-memory injection once underway but does not contain or eradicate it.
- T1055.011detects — A.8.15 explicitly requires logging of security-relevant events (privilege use, system activities, process anomalies via SIEM/IDS/UEBA rules and monitoring of access attempts), analysis to surface indicators of compromise, and correlation that would flag EWM injection as anomalous behavior under a legitimate process, though some stealthy in-memory variants may evade basic log sources.
- T1055.011responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS correlation, and incident identification explicitly surface EWM injection once underway (as process anomalies or indicators of compromise), triggering the incident management process that contains and eradicates it.
- T1055.012detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, correlation of events (including process creation, privilege use, system activities, and security system activation/deactivation), and identification of indicators of compromise such as malware or probing, which surfaces process hollowing in flight as anomalous behavior under a legitimate process.
- T1055.012responds — A.8.15's log analysis, monitoring, and incident identification explicitly surface hollowing indicators (anomalous process behavior, memory changes, privilege use, alarms) once underway for further investigation under incident management, but this is limited to observable events rather than containment/eradication of the in-flight technique itself.
- T1055.013detects — A.8.15 explicitly requires logging of process-relevant events (system activities, privilege use, file access/deletion, alarms from access-control/IDS, creation of processes/identities), synchronized time sources, SIEM/UEBA/pattern analysis of anomalous behaviour, and correlation of logs (including physical) to identify indicators of compromise such as the anomalous memory-section creation and execution that process doppelgänging produces.
- T1055.013responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification directly support responding to an in-flight doppelganging execution once it produces observable events, but the control stops at detection/analysis and hands off to 5.25 incident handling rather than performing containment/eradication itself.
- T1055.014detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of events (including process, system, privilege-use and library-loading activity), and identification of indicators of compromise such as malware or probing, which surfaces VDSO hijacking in a live process; the bounded remainder is fully in-memory hijacks that produce no observable log events before execution.
- T1055.014responds — A.8.15's log analysis and monitoring activities (SIEM/IDS/UEBA correlation, anomalous behaviour detection, incident identification) can surface VDSO hijacking once underway as suspicious process behaviour or syscall anomalies, enabling response under the linked incident management process, but this is only a slice because the technique is designed to evade process-based detection and many events occur below typical log granularity.
- T1055.015detects — A.8.15 mandates log analysis, SIEM/IDS/UEBA rules, anomaly detection on access attempts, privilege use, configuration changes, alarms, and correlation of events (including physical), which can surface ListPlanting indicators when they trigger observable system or process anomalies, but the technique's in-memory, message-passing nature often evades standard logging and leaves many executions undetected.
- T1055.015responds — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of events (including process, privilege, system activity and access attempts), and incident identification explicitly enable containment/eradication once ListPlanting is underway as an in-process technique masked under a legitimate process.
- T1056detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, privilege use, configuration changes, and physical events to surface indicators of compromise such as input-capture malware or anomalous credential prompts.
- T1056.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, configuration changes, privilege use, and security system events, which surfaces keylogging behaviors (API hooks, driver installs, registry mods, anomalous input patterns) in most cases once they generate observable events.
- T1056.001responds — A.8.15 requires log analysis and correlation (including of access attempts, alarms, security system activation, and anomalous behaviour) to identify suspected incidents such as probing or malware, then feeds them into the incident management process (5.25) for response; this surfaces keylogging once it produces observable events but does not contain or eradicate an in-progress keylogger.
- T1056.002detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM/IDS rules, anomalous behaviour detection, and correlation of access attempts, privilege use, and application activity) that can surface GUI input capture as suspicious credential prompts or anomalous dialog behaviour; it is a genuine but minority slice because the control's scope is set by what the organization chooses to log/monitor and many mimicry variants (especially non-privileged or non-audited prompts) remain undetected.
- T1056.002responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and identification of suspected incidents (e.g. probing or malware) directly enables response once the GUI prompt technique runs and is observed in logs.
- T1056.003detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the web portal credential-capture technique (or its indicators) once installed and active.
- T1056.003responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. anomalous login activity or probing) once underway and feed them into the incident management process (5.25), which is the core of `responds`; it does not contain/eradicate the already-installed capture code itself.
- T1056.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of events (including process/activity/use-of-privileges and security-system alarms), and identification of indicators of compromise such as malware or probing, which surfaces credential API hooking when it triggers observable events or anomalous behavior on monitored systems.
- T1056.004responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS correlation, and explicit tie-in to incident identification/investigation (5.25) enable response once credential-hooking is underway and logged as anomalous API behavior or privilege use.
- T1057detects — A.8.15 explicitly requires logging of process-related events (use of utilities/applications, system activities, privilege use), log analysis with UEBA/SIEM/IDS rules to surface anomalous behaviour, and correlation of those logs to identify indicators of compromise such as process enumeration commands.
- T1057responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of process-related events such as privilege use or system activities) surface an in-progress Process Discovery technique once it runs, enabling identification as part of incident response, but this is only a slice of the broad technique rather than containment/eradication itself.
- T1059detects — Logging of command interpreters, utility programs, and user transactions provides visibility into interactive or scripted adversary commands.
- T1059prevents — A.8.15 mandates logging of interpreter use, privilege use, system activities, configuration changes and anomalous behaviour, which (when reviewed) can stop many abuse paths before or during execution; it does not remove or disable the interpreters themselves, which remain available on every listed platform.
- T1059responds — A.8.15's log analysis, anomaly detection, correlation, and identification of suspected incidents (e.g. via SIEM/IDS/UEBA rules on command execution, privilege use, or anomalous activity) directly supports containment/eradication once the interpreter-abuse event is underway, with the named remainder being impacts already realised before detection.
- T1059.001detects — A.8.15 explicitly requires logging of system activities, privilege use, command/script interpreter execution (via utility programs and application transactions), successful/rejected access attempts, and subsequent log analysis with SIEM/UEBA/threat-intel rules to surface anomalous behaviour and indicators of compromise such as PowerShell abuse.
- T1059.001responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. anomalous behaviour, malware, probing) for further investigation under incident management (5.25), which matches the `responds` verb once a T1059.001 execution event is underway; extent is partial because the clause sets requirements for what to log/analyse rather than mandating detection of every in-memory or non-powershell.exe invocation of the technique.
- T1059.002detects — A.8.15 explicitly requires logging of system activities, privilege use, command-line/script execution, application interactions, anomalous behaviour via SIEM/UEBA/IDS correlation, and analysis of events (including outbound connections and unusual patterns) that would surface AppleScript abuse such as osascript invocation, NSAppleScript calls, or scripted behaviors on macOS.
- T1059.002responds — A.8.15's log analysis, correlation, anomalous-behaviour detection (including privilege use, system changes, alarms, and physical events) and explicit tie-in to the incident-management process (5.25) let responders contain/eradicate an in-progress AppleScript execution once it is logged.
- T1059.003detects — A.8.15 explicitly requires logging of command/shell use, privilege use, system activities, successful/rejected access attempts, and log analysis (with SIEM/UEBA/threat intel) to surface anomalous behaviour and indicators of compromise such as cmd.exe abuse for execution.
- T1059.003responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. anomalous commands, probing) once underway for further investigation under incident management, which is the core of `responds`; it is partial because the clause stops at detection/analysis and does not itself perform containment or eradication.
- T1059.004detects — A.8.15 explicitly requires logging of shell-relevant events (command execution, privilege use, system activities, script-like transactions), synchronized time sources, and SIEM/UEBA/log analysis to surface anomalous behaviour and indicators of compromise such as shell abuse.
- T1059.004responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including shell abuse via commands, privilege use, or scripts), then routes them to incident management (5.25) for response, but does not itself perform containment or eradication.
- T1059.005detects — A.8.15 explicitly requires logging of system activities, privilege use, application/script execution, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces VB/VBA/VBScript abuse (e.g. macro execution, suspicious scripts) as security events or indicators of compromise.
- T1059.005responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and explicit tie to incident management (5.25) directly surface and trigger response once VB-based execution (macros, VBScript payloads) is underway.
- T1059.006detects — A.8.15 explicitly requires logging and analysis of events including use of applications/utilities, system activities, privilege use, and anomalous behaviour via SIEM/UEBA/IDS correlation, which surfaces Python-based execution as an indicator of compromise.
- T1059.006responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. anomalous behaviour, malware, probing) for further investigation under the incident management process, which is the core of `responds`; it does not itself contain or eradicate the Python execution once underway.
- T1059.007detects — A.8.15 explicitly requires logging of system activities, privilege use, application/script execution, successful/rejected access attempts, and anomalous behaviour via log analysis, SIEM, UEBA, and correlation, which surfaces JavaScript abuse (e.g. osascript, JScript, or script payloads) in most cases once it executes.
- T1059.007responds — A.8.15 requires log analysis, anomaly detection, correlation, and explicit identification of suspected incidents (e.g. malware or probing) for further investigation under the incident management process, which directly enacts the containment/eradication actions that `responds` names once the JS execution technique is underway.
- T1059.008detects — A.8.15 explicitly requires logging of CLI-relevant events (use of privileges, system activities, configuration changes, successful/rejected access attempts), synchronized time sources, and log analysis (including UEBA, SIEM/IDS rules, anomalous behaviour detection, and correlation) that surfaces abuse of network device CLI as an indicator of compromise.
- T1059.008prevents — A.8.15 mandates logging of CLI-relevant events (privilege use, config changes, access attempts, security system activation) plus protection against log tampering or disabling, which constrains the 'disable logging to avoid detection' and some configuration-abuse slices of T1059.008 but does not stop adversaries from executing arbitrary CLI commands or scripts on the device.
- T1059.008responds — A.8.15's log analysis, anomaly detection, correlation, and explicit tie to feeding the incident management process (5.25) directly enable containment/eradication once CLI abuse is underway on a network device.
- T1059.009detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, privilege use, configuration changes, and cloud-relevant events that surface abuse of cloud APIs when they occur.
- T1059.009prevents — A.8.15 mandates logging of access attempts, privilege use, configuration changes, and anomalous API-driven behaviour (via SIEM/UEBA rules and correlation), which can block many abuse paths before execution; it does not stop an already-authorized call.
- T1059.009responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomaly detection, correlation, incident identification) surface and feed into response once cloud API abuse is underway, but the clause itself performs no containment or eradication.
- T1059.010detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, and monitoring of anomalous activity (including successful/unsuccessful access attempts, privilege use, system changes, and application transactions) to surface indicators of compromise; this can catch AHK/AutoIT script execution or compiled payloads on Windows but only where the activity produces observable logged events inside the chosen scope and ruleset.
- T1059.010responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and explicit tie-in to incident identification/investigation (5.25) directly enable containment and eradication once an AutoHotKey/AutoIT execution is underway as an information security event.
- T1059.011detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/rules, correlation, and review of events including script/utility use, system access, and configuration changes — all of which surface Lua-based execution as anomalous behavior or an indicator of compromise.
- T1059.011responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/UEBA/IDS rules on executed commands, scripts, and anomalous behavior) directly enable containment/eradication once Lua-based execution is underway, with the named remainder being events that evade logging or pre-analysis detection.
- T1059.012detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA patterns, correlation, and monitoring of events including system activities, privilege use, configuration changes, and security system activation — which surfaces hypervisor CLI abuse on ESXi as anomalous behavior or an indicator of compromise, but only where such logs are collected, analyzed, and in scope.
- T1059.012responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/IDS/UEBA on events including privilege use, config changes, and security system activation) surface hypervisor CLI abuse once underway as an indicator of compromise, enabling response; this is bounded to what is logged and analyzed rather than full containment/eradication.
- T1059.013detects — A.8.15 explicitly requires logging, protection, and analysis of events including system activities, privilege use, configuration changes, resource access, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces T1059.013 CLI/API abuse in container environments as part of identifying security events and indicators of compromise.
- T1059.013responds — A.8.15's log analysis, correlation, and identification of suspected incidents (e.g. anomalous container CLI activity via reviewed logs of system access, privilege use, configuration changes) enables response once the technique is underway, but only as input to a separate incident management process (5.25) rather than performing containment/eradication itself.
- T1068detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, access attempts, alarms from access control/IDS, and log analysis (with SIEM/UEBA/IDS rules, anomaly detection, and correlation) that surfaces indicators of exploitation leading to privilege escalation.
- T1068responds — A.8.15's log analysis, anomaly detection, correlation, and identification of suspected incidents (e.g. via alarms, privilege use, config changes) enable response once T1068 exploitation is underway, but this is limited to detection feeding incident handling rather than direct containment/eradication actions.
- T1069detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/rules, correlation, and review of access attempts/privilege use/configuration changes to surface indicators of compromise such as permission-group discovery activity.
- T1069responds — A.8.15 requires log analysis and monitoring to identify anomalous activity, suspected incidents (including probing or privilege-related events), and further investigation via incident management, which responds to T1069 once the discovery technique is underway; partial because it depends on whether the specific discovery actions generate logged events that are analyzed and escalated.
- T1069.001detects — A.8.15 requires log analysis and monitoring (including of privilege use, system access attempts, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation) that can surface local group enumeration as an indicator of compromise, but this is only a slice of possible detections rather than a bounded remainder because the clause sets requirements by organisational policy rather than mandating universal instrumentation or coverage of all T1069.001 instances.
- T1069.001responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification directly surface the reconnaissance technique once it runs (e.g. via command-line group enumeration in logs), enabling response; mostly because physical/log review scope and de-identified vendor logs leave a bounded remainder
- T1069.002detects — A.8.15 explicitly requires logging and analysis of events including successful/rejected access attempts, privilege use, configuration changes, identity creation/modification/deletion, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the reconnaissance commands and their outputs as indicators of compromise
- T1069.002responds — A.8.15 requires logging of privilege use, access attempts, configuration changes and identity modifications plus real-time analysis/SIEM correlation that surfaces the reconnaissance commands (net group, ldapsearch, etc.) once they run, enabling incident response containment.
- T1069.003detects — A.8.15 explicitly requires logging of privilege use, access attempts, configuration changes, identity creation/modification/deletion, and log analysis (with SIEM/UEBA/threat-intel correlation) that surfaces anomalous permission-group enumeration by an authenticated adversary; the named remainder is activity that evades the chosen log sources or analysis rules.
- T1069.003responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of access attempts and privilege use) surface the reconnaissance technique once it runs, enabling identification as an information security event for incident handling.
- T1070prevents — Centralized, tamper-protected logs make it harder for an adversary to erase or alter evidence of their actions across multiple event types.
- T1070detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation, and review of access attempts, configuration changes, privilege use, and other events that directly surface selective log modification or deletion attempts by an adversary.
- T1070responds — A.8.15 requires log protection (no deletion by actors, append-only, hashing, integrity) and analysis to identify incidents once they occur, which directly supports containment/eradication response to selective log tampering under T1070, but only covers a slice (log artifacts) rather than the full breadth of indicators the technique can target.
- T1070.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, configuration changes, privilege use, and security system events, which can surface command-history clearing as anomalous activity on covered platforms, but the control's scope is limited to what the organization chooses to log/analyze and does not guarantee coverage of every command-history file or technique variant (e.g., in-memory PowerShell Clear-History or network-device CLI clears).
- T1070.003prevents — A.8.15 requires logging of specific events including use of privileges, system activities, and file accesses/deletions, plus protection against log deletion or alteration (append-only, hashing, no self-deletion by privileged users); this directly stops many T1070.003 variants that target bash_history, shell.log, or ConsoleHost_history.txt, but leaves a bounded remainder for in-memory session-only histories, network-device CLI clears, and non-logged interpreters.
- T1070.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and review of file-access/deletion events plus physical logs to surface indicators of compromise such as post-intrusion cleanup.
- T1070.004responds — A.8.15 requires log analysis and correlation (including of file-access/deletion events and alarms) to identify and investigate suspected incidents once underway, which is the core of `responds`; it does not itself contain/eradicate the deletion or actor foothold.
- T1070.005detects — A.8.15 explicitly requires logging, analysis, and monitoring of system activities, privilege use, configuration changes, resource access attempts, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces the net use /delete command or related share-removal events after they occur.
- T1070.006detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including file access/deletion, privilege use, configuration changes), and identification of indicators of compromise or incidents, which surfaces timestomping when it produces observable discrepancies or patterns in logs.
- T1070.006responds — A.8.15's log analysis and monitoring explicitly surface anomalous file activity (including via correlated logs, UEBA, and physical monitoring) once timestomping has occurred as part of an incident, enabling further investigation, but this is post-facto detection rather than containment/eradication of the technique itself.
- T1070.007detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including network and physical), and identification of suspected incidents such as probing, which surfaces the T1070.007 clearing activity when it touches logged artifacts or produces detectable anomalies.
- T1070.008detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including via SIEM, UEBA, DNS logs, usage reports, and correlation), which surfaces T1070.008 mailbox/mail-log clearing when it produces detectable artifacts in the required event types; it is only partial because the control's scope is limited to what the organization chooses to log/analyze and does not guarantee coverage of all adversary methods (e.g. silent API deletions with no logged event).
- T1070.008prevents — A.8.15's requirements to log specific events (including use of privileges, system configuration changes, and application transactions), protect logs against deletion/alteration by users (including via append-only mechanisms), and perform log analysis for anomalous activity directly stops many of the mailbox/mail-app data clearing actions described in T1070.008 from succeeding or from removing evidence; it does not reach every platform or every possible mailbox-export/deletion vector, leaving a genuine minority slice unreached.
- T1070.008responds — A.8.15 requires log analysis, anomaly detection, correlation, and identification of suspected incidents (including via SIEM/IDS/UEBA) to trigger further investigation under the incident management process; this surfaces and acts on realized T1070.008 mailbox-clearing events after they occur, but only for the subset that generates detectable log artifacts rather than all instances.
- T1070.009detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including privilege use, account changes, configuration changes, file deletions), and identification of suspected incidents, which surfaces most T1070.009 cleanup actions after they occur.
- T1070.009responds — A.8.15's log analysis, correlation, and identification of suspected incidents (including anomalous cleanup that could indicate prior persistence) supports detection and response once the T1070.009 technique has run, but the control's focus is on recording/analyzing events rather than active containment or eradication of the adversary's cleanup actions.
- T1070.010detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of events (including file access, creation/modification/deletion of identities, and privilege use), and identification of indicators of compromise such as malware infection, which surfaces relocated malware copies and related evasion artifacts after they occur.
- T1071detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log review for malicious C2, correlation of events, and identification of suspected incidents such as probing, which surfaces T1071 C2 blending in with legitimate application-layer traffic.
- T1071responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. probing of firewalls, anomalous outbound to C2, correlation for investigation) once T1071 C2 traffic is underway, feeding the incident management process, but this is only a slice of full response (containment/eradication) and does not address all protocol variants or non-log-visible cases.
- T1071.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log review for malicious C2, correlation of events, and identification of suspected incidents such as probing, all of which surface web-protocol C2 blending in with legitimate traffic.
- T1071.001responds — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and identification of suspected incidents (e.g. probing or C2) directly enable response once T1071.001 C2 traffic is underway, with the named remainder being fully stealthy or encrypted blends that evade the monitored patterns.
- T1071.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of network activity (including DNS, outbound connections, and correlated logs) that surfaces the use of file-transfer protocols for C2 blending or data concealment.
- T1071.002responds — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and identification of suspected incidents (e.g. probing or malware C2) directly enables response once T1071.002 C2 traffic is underway, with the named remainder being fully stealthy or encrypted concealment that evades the logged indicators.
- T1071.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and correlation of events (including network activity, DNS, and physical logs) to surface indicators of compromise such as anomalous outbound connections or unusual protocol behavior that would reveal hidden C2 in common mail protocols.
- T1071.003responds — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and identification of suspected incidents (e.g. probing or malware) directly enables response once T1071.003 C2 traffic is underway, with the named remainder being fully stealthy or encrypted mail-protocol blends that evade the monitored patterns.
- T1071.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log review for outbound connections to malicious C2 servers, and correlation to identify probing or indicators of compromise — directly surfacing DNS tunneling/beaconing that blends with normal traffic.
- T1071.004prevents — A.8.15 mandates logging of DNS-related events (outbound connections, anomalous patterns, SIEM/IDS rules) and analysis to identify indicators of compromise such as C2 beacons or tunneling, which can block the technique from proceeding undetected in monitored environments; however, it is a detection/logging practice that does not stop the adversary from initiating blended DNS traffic, especially infrequent or pre-authentication uses.
- T1071.004responds — A.8.15 requires log analysis (with SIEM/IDS/UEBA rules, anomaly detection, DNS log review for malicious C2, correlation) plus incident identification to trigger the incident management process (5.25) once the DNS-tunneling event is underway, which is exactly what `responds` names.
- T1071.005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of network traffic patterns (including outbound connections to malicious servers) to surface indicators of compromise; pub/sub C2 blends with normal broker traffic but is still observable in the mandated event logs, DNS checks, and correlation once the technique runs.
- T1071.005responds — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and incident identification directly support responding to pub/sub C2 once underway by surfacing the blended traffic as an indicator of compromise.
- T1072detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, successful/rejected access attempts, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces abuse of centralized deployment tools (especially by privileged accounts) as indicators of compromise.
- T1072responds — A.8.15 requires log analysis (including SIEM/IDS/UEBA rules, anomaly detection, correlation, and review of access attempts, privilege use, configuration changes, and alarms) to identify suspected incidents such as probing or malware, which directly supports the incident management process (5.25) that contains and eradicates an in-progress T1072 abuse of deployment tools.
- T1074detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts, file activity, configuration changes and privilege use — all of which surface the file-copy, archive and staging behaviors named in T1074 after they occur.
- T1074responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/UEBA reviewing access, file ops, and unusual activity) surface T1074 once the staging activity is underway, enabling response via the linked incident management process.
- T1074.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including file access, system activities, privilege use, and configuration changes), and identification of indicators of compromise, which surfaces local data staging activity in the great majority of cases.
- T1074.001responds — A.8.15's log analysis and monitoring explicitly surface anomalous file access, staging activity, and indicators of compromise (including correlation of events like file creation/modification/deletion), enabling response once the technique is underway; this is a genuine but minority slice of the broad staging behaviors described.
- T1074.002detects — A.8.15 explicitly requires logging of access attempts, privilege use, file access/deletion, configuration changes and alarms plus mandated analysis (SIEM/UEBA/rules/threat intel/correlation) that surfaces anomalous staging activity on endpoints, networks and cloud instances; the named remainder is fully stealthy or off-scope activity that evades the chosen monitoring set.
- T1074.002responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/UEBA reviewing access, file ops, and unusual activity) surface the staging technique once underway, enabling response and investigation per the incident management tie-in.
- T1078detects — Detailed logging of successful and failed access attempts, privilege use, and identity changes enables detection of unauthorized account usage.
- T1078prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes, identity creation/deletion and anomalous behaviour (with analysis, correlation and alerting), which can prevent many T1078 abuse paths by enabling timely detection and response before persistence/escalation; it does not stop credential compromise or initial abuse itself.
- T1078responds — A.8.15 requires log analysis, anomaly detection via SIEM/UEBA/IDS, correlation, and explicit routing of suspected/actual incidents (including those using valid accounts) into the incident management process (5.25), which is exactly the containment/eradication act that `responds` names once the technique is underway.
- T1078.001detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, identity changes, configuration changes and anomalous behaviour via SIEM/UEBA/correlation, which surfaces default-account abuse (including post-creation vpxuser-style accounts) as an indicator of compromise; the named remainder is default accounts used only via stolen keys on unmonitored remote services or appliances outside the logged scope.
- T1078.001responds — A.8.15's log analysis, anomaly detection, correlation, and identification of suspected incidents (including via SIEM/IDS/UEBA) directly enable response once default-account abuse is underway, with the named remainder being incidents that produce no observable events in the logged set.
- T1078.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, privilege use, configuration changes and alarms — all of which surface domain-account abuse after it occurs.
- T1078.002prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, identity changes, and anomalous behaviour analysis (with time sync and integrity protection), which can surface and deter abuse of compromised domain accounts in many scenarios but does not stop credential compromise itself (e.g. via dumping or reuse) nor block all initial access/persistence paths.
- T1078.002responds — A.8.15 requires log analysis and correlation (including of access attempts, privilege use, configuration changes, and alarms) to identify suspected incidents such as probing or anomalous behaviour, then feeds them into the incident management process (5.25) for response; this acts once the domain-account abuse is already underway but only on the detectable subset that generates observable events, leaving credential theft via dumping/reuse that evades logging as a clear remainder.
- T1078.003detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, identity creation/modification/deletion, and log analysis (with SIEM/UEBA/threat intel/correlation) that surfaces anomalous behaviour and indicators of compromise from local account abuse.
- T1078.003responds — A.8.15 requires log analysis, anomaly detection, correlation and explicit identification of suspected incidents (e.g. probing, malware) for further investigation under the incident management process, which directly enacts the `responds` verb once the local-account abuse technique is underway.
- T1078.004detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, identity creation/modification, and log analysis (with SIEM/UEBA/IDS rules, anomaly detection, and correlation) that surfaces indicators of compromise from cloud-account abuse such as anomalous logons, privilege escalations, or lateral movement.
- T1078.004responds — A.8.15's log analysis, anomaly detection, correlation, and explicit tie to identifying suspected incidents for the incident management process (5.25) directly enables response once T1078.004 account abuse is underway.
- T1080detects — A.8.15 explicitly requires logging and analysis of file access/deletion, configuration changes, privilege use, alarms, anomalous behaviour via SIEM/UEBA/threat intel, and correlation of logs (including physical), which surfaces most variants of shared-content tainting and directory-share pivots after they occur.
- T1080responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification directly support responding to (containing/eradicating) T1080 once the tainted content is accessed and executes, but the control stops at detection/analysis and hands off to 5.25 incident management without performing containment itself.
- T1082detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, configuration changes, and anomalous behaviour (including via SIEM/UEBA/correlation) to identify indicators of compromise such as reconnaissance commands that surface system information.
- T1082responds — A.8.15's log analysis, correlation, anomalous-behaviour detection (including privilege use, config changes, access attempts) and incident-identification steps directly surface T1082 once it runs, enabling containment under the linked incident-management process; mostly because the control's scope is limited to events the organization chose to log and analyse.
- T1083detects — A.8.15 explicitly requires logging and analysis of file-access events, privilege use, configuration changes, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces T1083 activity once it occurs.
- T1083responds — A.8.15 requires log analysis and correlation (including of file-access events, alarms, and anomalous behaviour) to identify suspected incidents such as probing or malware activity once underway, feeding into incident response per 5.25; this surfaces and supports response to T1083 but does not itself contain or eradicate it.
- T1087detects — A.8.15 explicitly requires logging of account-related events (user IDs, successful/rejected access attempts, privilege use, identity creation/modification/deletion) plus analysis and correlation to identify anomalous behaviour and indicators of compromise such as account enumeration.
- T1087responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/UEBA rules on account enumeration patterns or privilege-use events) directly supports containment/eradication once the discovery technique is underway, with the named remainder being stealthy or non-logged discovery methods.
- T1087.001detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, account creation/modification/deletion, and log analysis (with SIEM/UEBA/correlation) to identify anomalous behaviour and indicators of compromise such as account enumeration commands.
- T1087.001responds — A.8.15's log analysis, correlation, anomalous-behaviour detection (including privilege use, account changes, access attempts) and incident-identification steps surface the reconnaissance technique once it has run, enabling further investigation under the incident-management process.
- T1087.002detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, identity creation/modification/deletion, system configuration changes, and log analysis (with SIEM/UEBA/IDS rules, anomaly detection, and correlation) that surfaces domain account enumeration as anomalous behavior or an indicator of compromise.
- T1087.002prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, identity changes and configuration changes, which can be configured to log (and therefore block via policy+enforcement) many of the specific commands and tools used to enumerate domain accounts; this is a genuine but minority slice of the technique because the control does not reach all discovery vectors, all platforms, or all privilege levels, and the clause itself stops at recording rather than mandating enforcement.
- T1087.002responds — A.8.15's log analysis and monitoring explicitly surface anomalous account enumeration (e.g. via successful/rejected access attempts, privilege use, identity changes, and UEBA/SIEM correlation), enabling incident response once the technique is underway.
- T1087.003detects — A.8.15 explicitly requires log analysis and monitoring of events (including successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation) to identify indicators of compromise such as account enumeration; this surfaces T1087.003 when it generates observable logs, with the bounded remainder being stealthy or non-logged executions.
- T1087.003prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes, and identity creation/modification, plus protected analysis to surface anomalous behavior; this directly stops the authenticated PowerShell or directory-enumeration technique in many cases by creating detectable evidence that feeds incident response, but leaves a remainder where the adversary holds sufficient privileges or the logging scope/monitoring is not configured to catch the specific query.
- T1087.003responds — A.8.15 requires log analysis (including SIEM/UEBA rules, anomaly detection, correlation, and explicit review of access attempts and privilege use) to identify suspected incidents such as probing or reconnaissance that match T1087.003; once the technique is underway this surfaces it for the incident management process (5.25) to contain/eradicate, with the named remainder being stealthy or non-logged executions.
- T1087.004detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, identity creation/modification/deletion, configuration changes, and log analysis (with SIEM/UEBA/threat intel/correlation) that surfaces anomalous account enumeration activity, directly detecting the technique when it runs.
- T1087.004responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/UEBA reviewing access attempts, privilege use, identity changes) surfaces the account enumeration technique once it runs, enabling further investigation under incident management.
- T1090detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of network activity (including DNS logs for C2, correlating logs, and reviewing access attempts), which surfaces proxy-based C2 and traffic redirection as indicators of compromise.
- T1090responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including outbound connections to malicious C2), then feeds them into incident response (5.25); this acts on T1090 once underway but only surfaces a slice (observable proxy use in logs) rather than containing/eradication.
- T1090.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of logs (including network activity, system access, configuration changes, and physical events), and identification of indicators of compromise such as probing or unusual outbound connections, which surfaces internal proxy usage for C2 redirection in most cases.
- T1090.001responds — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and incident identification explicitly surface and feed into the incident management process (5.25) once internal proxy C2 redirection is underway, but this is limited to observable network/DNS/physical events rather than all proxy behaviors (e.g., SMB p2p blending or host-level redirection).
- T1090.002detects — A.8.15 explicitly requires log analysis, anomalous behaviour detection via SIEM/IDS/UEBA/threat intel, DNS log checks for malicious C2, correlation of events, and identification of probing or indicators of compromise, which surfaces external proxy usage in most cases.
- T1090.002responds — A.8.15's log analysis, correlation, and identification of anomalous events (e.g. unusual outbound connections, probing) can surface and trigger response to an already-underway external proxy C2 channel, but only for the observable slice that produces detectable log artifacts rather than the full technique.
- T1090.003detects — A.8.15 explicitly requires log analysis, correlation, UEBA, SIEM/IDS rules, DNS log checks for malicious C2, and anomaly detection on network activity to surface indicators of compromise, which directly surfaces multi-hop proxy traffic (last-hop identification, anomalous routing, onion/P2P patterns) in most cases.
- T1090.003responds — A.8.15's log analysis, correlation, anomalous-behaviour detection and explicit tie-in to the incident-management process (5.25) let responders see and contain multi-hop proxy traffic once it is underway, but the control stops at detection/analysis and does not itself perform containment or eradication.
- T1090.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log review for malicious outbound connections, and correlation of events (including network activity) to identify indicators of compromise and suspected incidents; domain fronting produces observable network artifacts (mismatched SNI/Host, anomalous CDN routing patterns) that fall inside those mechanisms, though the control does not guarantee every implementation will instrument or baseline the precise fields involved.
- T1091detects — A.8.15 explicitly requires logging of removable-media and device events (USB mounts, file access/deletion, alarms from access-control/IDS, physical monitoring), synchronized time sources, and log analysis with UEBA/SIEM/threat-intel to surface anomalous behaviour and indicators of compromise such as malware replication or autorun activity.
- T1091responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. malware infection) once underway and feed them into the incident management process (5.25), which is the core of `responds`; it is partial because the clause stops at detection/analysis/correlation and does not itself perform containment or eradication.
- T1092detects — A.8.15 explicitly requires logging, analysis, and correlation of events including system activities, privilege use, file access/deletion, configuration changes, and anomalous behaviour (with SIEM/UEBA/threat intel support), which surfaces the file drops, USB activity, and command relay patterns of T1092 after it runs.
- T1095detects — A.8.15 explicitly requires determining what to log (including network activity, system events, alarms from IDS/access controls), protecting log integrity, performing log analysis with SIEM/IDS/UEBA/threat intel, and monitoring for anomalous behaviour such as unusual outbound connections or probing — directly surfacing non-application-layer C2 (e.g. ICMP, VMCI) that is otherwise invisible to standard tools.
- T1095responds — A.8.15's log analysis, correlation, anomalous-behaviour detection and explicit tie-in to the incident-management process (5.25) let responders see and act on non-application-layer C2 once it is underway, but the clause stops at identification and hands off to incident handling; it neither contains nor eradicates the technique itself.
- T1098detects — A.8.15 explicitly requires logging of account-related events (creation/modification/deletion of identities, privilege use, configuration changes, successful/rejected access) plus analysis to surface anomalous behaviour and indicators of compromise, which directly detects T1098 manipulations once performed.
- T1098prevents — A.8.15 mandates logging of account/identity creation/modification/deletion, privilege use, configuration changes and anomalous behaviour, which surfaces many T1098 actions in time for detection and response before persistence solidifies; it does not stop the manipulation itself once the adversary already holds the necessary permissions.
- T1098responds — A.8.15 requires log analysis and correlation (including of account/identity changes, privilege use, and anomalous behaviour) to identify suspected incidents for further investigation under the incident management process; this surfaces and feeds response once manipulation is underway, but only for the detectable subset of actions that generate observable logs rather than all manipulation techniques.
- T1098.001detects — A.8.15 explicitly requires log analysis and monitoring of events (including privilege use, configuration changes, identity creation/modification, and anomalous behaviour via SIEM/UEBA/threat intel) to identify indicators of compromise such as unauthorized credential additions, which surfaces the T1098.001 technique post-execution.
- T1098.001responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification explicitly surface the addition of credentials as a suspicious event (e.g. privilege-use, identity changes, configuration changes) once it has occurred, enabling response; this is genuine but only a slice because the control stops at detection/analysis and hands off to incident handling rather than performing containment/eradication itself.
- T1098.002detects — A.8.15 explicitly requires logging of privilege use, configuration changes, identity creation/modification, resource access attempts, and log analysis (with SIEM/UEBA/threat intel) that surfaces anomalous permission grants such as mailbox delegation or folder ACL changes; the named remainder is stealthy or non-logged cases outside the monitored scope.
- T1098.002responds — A.8.15's log analysis, anomaly detection, correlation, and explicit tie to identifying suspected incidents (e.g. via SIEM/UEBA rules on privilege use, config changes, access attempts) for further investigation under incident management directly enacts the `responds` verb once the permission-granting technique is underway.
- T1098.003detects — A.8.15 explicitly requires logging of privilege use, configuration changes, identity creation/modification/deletion, and anomalous behaviour via SIEM/UEBA/threat-intelligence-driven analysis, which surfaces the addition of cloud roles or IAM policy updates as an indicator of compromise.
- T1098.003prevents — A.8.15 mandates logging of privilege use, configuration changes, identity modifications, and access attempts plus protected immutable logs and analysis that can surface the role-addition activity before or while it occurs, thereby preventing the technique in monitored environments; however this is only a slice because the control does not enforce any preventive guardrails on the IAM/policy modification APIs themselves.
- T1098.003responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and explicit tie-in to identifying suspected incidents for the incident management process (5.25) directly supports containment/eradication response once the role-addition technique is underway.
- T1098.004detects — A.8.15 explicitly requires logging of privilege use, configuration changes, file accesses/deletions, and anomalous behaviour via log analysis (SIEM/UEBA/IDS rules, correlation, trend analysis) which surfaces SSH authorized_keys modifications as indicators of compromise or privilege escalation.
- T1098.004prevents — A.8.15 mandates logging of privilege use, configuration changes, file accesses/deletions, and anomalous behaviour via analysis/SIEM/UEBA, which can surface unauthorized authorized_keys edits before persistence is fully leveraged, but does not stop the modification itself.
- T1098.004responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and explicit tie to identifying incidents for the incident management process (5.25) directly enable response once the authorized_keys modification has occurred and is logged.
- T1098.005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of events (including successful/rejected access, privilege use, configuration changes, identity creation), and identification of suspected incidents such as probing — which surfaces device registration as anomalous MFA/device-management activity after it occurs.
- T1098.005prevents — A.8.15 mandates logging of device/identity creation, privilege use, configuration changes, and anomalous registration-like events plus analysis to surface indicators of compromise; this can stop the technique from completing or persisting when the registration is detected and investigated in time, but the control only records/analyzes rather than blocking enrollment at the MFA/Intune boundary, leaving the bulk of the technique (credentialed self-enrollment) unreached.
- T1098.005responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of access/privilege/device events) can surface device registration as a suspicious event once underway, enabling incident response, but this is only a slice of the technique's surface (e.g. self-enrollment or Intune registration may not always trigger the logged events or rules described).
- T1098.006detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of events (including privilege use, account/role changes, configuration changes, and access attempts), and identification of suspected incidents, which surfaces T1098.006 activity in container environments when it triggers logged events.
- T1098.006responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of access/privilege/use events) surface the account/role modification once it has occurred as an indicator of compromise or incident, enabling response; this is bounded by the fact that the control only records/analyses and does not itself contain or eradicate.
- T1098.007detects — A.8.15 explicitly requires logging and analysis of privilege use, group membership changes, identity creation/modification, configuration changes and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces the addition of groups to an account as an indicator of compromise.
- T1098.007responds — A.8.15 requires log analysis and correlation (including of privilege-use, group changes, identity creation/modification and access attempts) to identify suspected incidents once underway and feed them into the incident management process (5.25), which is the core of `responds`; it is only partial because the control stops at detection/analysis hand-off and does not itself perform containment or eradication.
- T1102detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including network activity, DNS, and outbound connections to malicious infrastructure), and identification of indicators of compromise, which surfaces most Web-service C2 usage that deviates from baseline traffic.
- T1102responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/correlation, and identification of suspected incidents (e.g. probing or malware) can surface T1102 C2 traffic hidden in legitimate web service noise once underway, enabling response, but this is limited to observable patterns rather than reliably distinguishing or containing all blended legitimate C2 use.
- T1102.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log examination for malicious C2, and correlation to identify indicators of compromise, which surfaces dead-drop resolver usage in network traffic and logs.
- T1102.001responds — A.8.15's log analysis, correlation, anomaly detection (including outbound connections, UEBA, threat intel) and incident identification can surface dead-drop resolver activity once underway as part of response, but the technique's use of common/encrypted web services blends into expected noise and is not a primary target of the listed monitoring patterns.
- T1102.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including network activity, outbound connections, and unusual patterns), and identification of suspected incidents such as probing or C2-like behavior, which surfaces bidirectional Web-service C2 when it generates observable logs.
- T1102.002responds — A.8.15 requires log analysis, correlation, and identification of suspected incidents (including anomalous outbound connections and indicators of compromise) to feed the incident management process (5.25), which performs the containment/eradication act that `responds` names; this catches some but not most T1102.002 executions because the technique blends into expected web noise and many instances produce no detectable log anomaly.
- T1102.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including network activity to malicious C2-like servers), and identification of indicators of compromise such as probing or outbound connections, which surfaces one-way Web-service C2 in the noise.
- T1102.003responds — A.8.15's log analysis, correlation, SIEM/IDS/UEBA rules, and incident identification explicitly surface anomalous C2 beaconing or one-way web-service patterns once underway, feeding the incident management process, but this is only a slice of the technique's stealth (no-return, common-noise, TLS cover) rather than a bounded remainder.
- T1104detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation across event types (including network activity, system changes, privilege use, and outbound connections to malicious infrastructure), and identification of suspected incidents such as probing or malware, which surfaces the observable behaviors and infrastructure shifts of multi-stage C2.
- T1104responds — A.8.15's log analysis, correlation, anomaly detection (including network/DNS/UEBA/threat intel) and incident identification can surface and trigger response to multi-stage C2 once it is underway, but this is scoped to observable events rather than containment/eradication of the staged channels themselves.
- T1105detects — A.8.15 explicitly requires logging, analysis, and monitoring of events including successful/rejected access attempts, use of utilities/applications, network activity, anomalous behaviour, and indicators of compromise (with SIEM/UEBA/threat-intel support), which surfaces most T1105 ingress-tool-transfer activity (downloads via curl/wget/certutil/PowerShell/etc.) while the named remainder is activity on unmonitored or out-of-scope systems.
- T1105responds — A.8.15's log analysis, anomaly detection, and incident identification (e.g. via SIEM/UEBA/correlation of events including file access, privilege use, and network activity) surface the tool-transfer technique once underway, enabling response; this is bounded to observable events and does not cover all transfer vectors or platforms.
- T1106detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, correlation, and review of access attempts, privilege use, process activity, and configuration changes — all of which surface native API abuse (syscalls, process creation, tampering) once it occurs.
- T1106responds — A.8.15's log analysis, correlation, SIEM/IDS/UEBA rules, and identification of suspected incidents (e.g. anomalous behaviour, probing) directly enable response once T1106 is underway, with the named remainder being fully subverted/hooked sensors that evade the logging itself.
- T1110detects — Systematic logging of rejected access attempts and authentication events supports detection of password-guessing or spraying campaigns.
- T1110prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes and alarms, plus analysis to surface anomalous patterns (including brute-force attempts), which can trigger preventive controls or block further guessing; this stops some but not most instances of the technique (e.g. offline attacks, rate-limit bypasses, or non-logged vectors remain untouched).
- T1110responds — A.8.15 requires log analysis and monitoring to identify anomalous activity (including brute-force patterns such as repeated failed logons), flag suspected incidents, and feed them into the incident management process (5.25) for response once the technique is underway.
- T1110.001detects — A.8.15 explicitly requires logging of successful/rejected access attempts, use of privileges, alarms from access control systems, and log analysis (with SIEM/IDS/UEBA rules, anomaly detection, and correlation) that surfaces password-guessing patterns as indicators of compromise or incidents.
- T1110.001prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, alarms, and anomalous behaviour plus protected immutable logs and analysis that surfaces guessing in flight; this directly enables account lockouts, rate limiting and blocking after failed attempts (explicitly referenced in the T1110.001 description), stopping the technique from succeeding on most covered vectors while leaving a bounded remainder for exempted identities, legacy protocols and unmonitored services.
- T1110.001responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (e.g. probing of firewalls, unsuccessful access attempts) then subject them to further investigation as part of incident management (5.25), which is exactly the containment/eradication act that `responds` names once the guessing is underway.
- T1110.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and correlation of access attempts, privilege use, configuration changes and alarms to surface indicators of compromise such as password-cracking activity.
- T1110.002responds — A.8.15's log analysis, anomaly detection, and incident identification (e.g. via SIEM/UEBA/correlation) surface password-cracking indicators once underway, feeding the incident management process, but this is only a slice of the offline cracking technique that occurs outside the target network.
- T1110.003detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation rules, directly surfacing password-spraying patterns (many failed logins from one or few passwords across accounts) while the technique is in flight or shortly after.
- T1110.003prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes and anomalous behaviour plus protected immutable logs and analysis (SIEM/UEBA/threat intel), which surfaces many password-spraying attempts and can trigger account-lock or rate-limit responses that stop the technique; it does not stop the spraying itself from being attempted or succeeding on unmonitored vectors, throttled low-and-slow attempts, or non-logged services.
- T1110.003responds — A.8.15 requires log analysis, anomaly detection, correlation, and explicit hand-off of suspected/actual incidents (including probing or authentication anomalies) into the incident management process (5.25), which is exactly the containment/eradication act that `responds` names once the sprayed technique is underway.
- T1110.004detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, alarms from access control systems, and log analysis (with SIEM/IDS/UEBA rules, anomalous behaviour detection, and correlation) that surfaces credential-stuffing patterns such as repeated authentication failures across targeted services.
- T1110.004prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour via analysis/SIEM/UEBA, which surfaces credential-stuffing patterns (e.g. repeated failures) for blocking before success; it does not stop the technique from being attempted or guarantee enforcement of lockouts/rate limits.
- T1110.004responds — A.8.15 requires log analysis (with SIEM/IDS/UEBA rules, anomaly detection, correlation) and explicit identification of suspected incidents (e.g. probing of firewalls or auth failures) for further investigation under incident management, which directly enacts the containment/eradication act that `responds` names once credential-stuffing attempts are underway.
- T1111detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, privilege use, configuration changes, and physical events that surface MFA interception indicators (keyloggers, anomalous auth, SMS compromise, token replay patterns).
- T1111responds — A.8.15 requires log analysis and correlation (including of access attempts, alarms, security system activation, and anomalous behaviour) to identify suspected incidents such as probing or compromise for further investigation under incident management; this surfaces MFA-interception events once underway but does not contain/eradicate them.
- T1112detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, and resource access attempts, plus log analysis (with SIEM/UEBA/threat intel) to surface anomalous behaviour and indicators of compromise; registry modifications for evasion/persistence are observable in those events and detectable via the mandated analysis, with a bounded remainder for stealth techniques that evade the listed log sources.
- T1113detects — A.8.15 explicitly requires log analysis and monitoring of events (including system activities, privilege use, application execution, anomalous behaviour via SIEM/UEBA/IDS correlation, and physical logs) to identify indicators of compromise such as malware or probing; screen capture via native utilities or RAT features is observable in those logs and would surface as anomalous activity.
- T1114detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, configuration changes, privilege use, and physical events that surface email collection from servers/clients or related anomalous forwarding/behavior.
- T1114responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. anomalous behaviour, probing) for further investigation under incident management (5.25), which is the core of `responds`; it does not itself contain/eradicate the collection once underway.
- T1114.001detects — A.8.15 explicitly requires logging of file access/deletion, privilege use, system activities and anomalous behaviour, plus SIEM/UEBA/correlation analysis that surfaces local email file collection as an indicator of compromise.
- T1114.002detects — A.8.15 explicitly requires logging of access attempts, privilege use, resource access, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces credentialed Exchange/Office 365 email collection both during and after the fact.
- T1114.002responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (e.g. unusual access patterns, probing), which can surface remote email collection in flight for further incident response, but does not itself contain/eradicate the actor or technique once underway.
- T1114.003detects — A.8.15 explicitly requires log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of logs including successful/unsuccessful access and configuration changes) that surface creation or use of email forwarding rules as an information security event or indicator of compromise.
- T1114.003responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and explicit tie to feeding the incident management process (5.25) directly enable response once the forwarding rule is active and observable in logs or alerts.
- T1115detects — A.8.15 explicitly requires log analysis and monitoring of anomalous behaviour (including UEBA, SIEM/IDS rules, and correlation of access/usage logs) that can surface clipboard-access patterns as indicators of compromise, but this is scoped by what the organization chooses to log and monitor rather than a universal mechanism that guarantees detection of T1115.
- T1119detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts, file activity, configuration changes and privilege use — all of which surface automated collection once it runs.
- T1119responds — A.8.15's log analysis, anomaly detection, correlation, and identification of suspected incidents (e.g. via SIEM/UEBA/threat intel) directly enables response once automated collection is underway, with the named remainder being collection that evades logging or occurs outside monitored scopes.
- T1120detects — A.8.15 requires logging, protection, and analysis of events including system activities, device identities, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces T1120 when it triggers observable logs (e.g. device enumeration); it is not required for all peripheral-discovery methods or platforms and stops at knowledge generation.
- T1123detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of events including use of applications/utilities, privilege use, system activities, and physical monitoring to surface indicators of compromise such as malware invoking audio APIs or writing suspicious files.
- T1123responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (e.g. malware infection), which surfaces T1123 once underway for further investigation under incident management, but does not contain/eradicate the running capture itself.
- T1124detects — A.8.15 explicitly requires log analysis and monitoring activities (including correlation, UEBA, SIEM/IDS rules, and review of access/system events) to identify anomalous behaviour and indicators of compromise; this surfaces T1124 reconnaissance when it triggers logged events or patterns, but many local discovery methods (direct syscalls, GetTickCount, CLI queries on unmonitored devices) produce no observable event or fall outside the clause's scoped activities.
- T1124responds — A.8.15's log analysis, correlation, anomalous-behaviour detection (including time-related events and physical logs) and incident-identification steps act on the discovery technique once it has run, surfacing it as an indicator for further investigation.
- T1125detects — A.8.15 explicitly requires log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomalous behaviour detection, correlation of access/use logs, physical monitoring) that surface video-capture indicators such as unexpected device activation, API use, file writes of images/video, or outbound exfil — the core of the `detects` verb — with only a bounded remainder for fully stealthy in-memory capture that evades all logging.
- T1125responds — A.8.15's log analysis, anomaly detection, and incident identification (e.g. via SIEM/UEBA/correlation of access, device, and security system events) can surface video capture once underway as part of incident response, but this is a minority slice of the technique's execution (API interaction, file write, exfil) with most of it outside logging scope.
- T1127detects — A.8.15 explicitly requires logging, analysis, and correlation of events including use of applications/utilities, privilege use, system configuration changes, and anomalous behaviour via SIEM/UEBA/threat intel, which surfaces T1127's proxy execution through trusted signed developer tools as an indicator of compromise.
- T1127responds — A.8.15's log analysis and monitoring explicitly surface anomalous behaviour, indicators of compromise, and suspected incidents (including probing or malware-like activity that could accompany T1127 execution), feeding into incident management (5.25) for response, but does not itself contain or eradicate the technique once underway.
- T1127.001detects — A.8.15 explicitly requires logging, protection, and analysis of events including use of applications/utilities, system activities, privilege use, anomalous behaviour via SIEM/UEBA/IDS correlation, and indicators of compromise, which surfaces MSBuild abuse as a signed binary proxying arbitrary code.
- T1127.001responds — A.8.15's log analysis, monitoring, and incident identification explicitly surface anomalous behaviour (including trusted-binary proxy execution) once underway, feeding the incident management process that contains and eradicates it.
- T1127.002detects — A.8.15 explicitly requires logging and analysis of events including successful/rejected access attempts, privilege use, application execution, anomalous behaviour via SIEM/UEBA/IDS correlation, and indicators of compromise, which can surface ClickOnce abuse (e.g. unusual child processes of DFSVC.EXE, rundll32.dfshim.dll activity, or startup folder changes) but only where those events fall inside the organisation's chosen logging scope and analysis rules.
- T1127.002responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification directly support responding to (containing/eradication steps for) in-flight or realized ClickOnce abuse once it generates observable events.
- T1127.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, and correlation of events (including use of utilities, system activities, and application transactions) to surface indicators of compromise; this surfaces JamPlus abuse when it produces observable log artifacts, but the control's scope is limited to what is selected for logging and analysis rather than guaranteeing coverage of this specific build-tool proxy technique.
- T1129detects — A.8.15 explicitly requires logging of system activities, privilege use, process/resource access attempts, alarms from access-control/IDS systems, and SIEM/UEBA-driven analysis of anomalous behaviour, which surfaces shared-module loading (dlopen/LoadLibrary of malicious payloads) as an observable event or indicator of compromise.
- T1129responds — A.8.15's log analysis and monitoring explicitly surface anomalous behaviour, indicators of compromise, and suspected incidents (including malware execution and probing), which can include shared-module loading once it produces observable events; this is containment/eradication response once underway, but only a slice because the technique can be fileless/in-memory with no guaranteed log artifact.
- T1132detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log review for C2 indicators, and correlation to identify events like probing or malware that can surface encoded C2 traffic as anomalous.
- T1132.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log review for malicious C2, and correlation of events to identify indicators of compromise, which surfaces standard encoding in C2 traffic when it deviates from known patterns.
- T1132.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/pattern analysis, correlation of events (including network protocols and outbound connections), and identification of indicators of compromise or anomalous behaviour that would surface non-standard encoding in C2 traffic.
- T1133detects — A.8.15 explicitly requires logging of successful/rejected access attempts to remote services, privilege use, configuration changes, alarms from access-control systems, and subsequent log analysis (with SIEM/IDS/UEBA rules, anomaly detection, correlation, and threat intel) that surfaces indicators of compromise such as unauthorized external remote service use.
- T1133responds — A.8.15 requires log analysis, correlation, and identification of suspected incidents (e.g. probing of firewalls or anomalous access attempts) to feed the incident management process (5.25), which acts on an external-remote-service event once underway; this is genuine but only a slice because the control stops at detection/analysis and does not itself perform containment or eradication.
- T1134detects — A.8.15 explicitly requires logging of privilege use, system access attempts, configuration changes and anomalous behaviour, plus SIEM/UEBA/correlation analysis that surfaces token manipulation as an indicator of compromise or privilege escalation.
- T1134responds — A.8.15 requires log analysis (with SIEM/UEBA/IDS rules, anomaly detection, correlation, and explicit review of access attempts, privilege use, and security system activation) to identify suspected incidents such as this technique once it has run, then feeds them into incident management (5.25); this is the core of `responds`.
- T1134.001detects — A.8.15 explicitly requires logging of privilege use, system access attempts, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces token impersonation when it triggers observable events (e.g. unusual privilege use or access patterns); the named remainder is stealthy in-memory impersonation that evades the logged events or monitoring scope.
- T1134.001responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including privilege use and access attempts), which supports containment/eradication once token impersonation is underway, but does not itself perform the response actions.
- T1134.002detects — A.8.15 explicitly requires logging of privilege use, system access attempts, process/activity events and anomalous behaviour via SIEM/UEBA/correlation, which surfaces T1134.002 when it executes; the named remainder is events that evade the chosen log sources or analysis rules.
- T1134.002responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/UEBA/IDS rules on privilege use, access attempts, and config changes) surface T1134.002 once it runs, feeding the incident management process, but this is limited to observable events rather than full containment/eradication.
- T1134.003detects — A.8.15 explicitly requires logging of privilege use, successful/rejected access attempts, system activities, and log analysis (with SIEM/UEBA/IDS rules, anomalous behaviour detection, and correlation) that surfaces token creation and impersonation as indicators of compromise on Windows.
- T1134.003responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including privilege use and access attempts), which supports containment/eradication once token impersonation is underway, but does not itself perform the response actions.
- T1134.004detects — A.8.15 requires log analysis and monitoring of process-related events (system activities, privilege use, anomalous behaviour via UEBA/SIEM/IDS correlation) that can surface PPID spoofing as an IOC, but does not mandate the specific process-creation or parent-child telemetry needed to reliably catch it.
- T1134.004responds — A.8.15's log analysis, correlation, anomalous-behaviour detection (including process/activity patterns via SIEM/UEBA), and incident-identification steps act on the technique once it has run to surface and contain it as part of incident handling.
- T1134.005detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM rules, anomalous behaviour detection, privilege-use logging, and correlation) that can surface SID-History injection as a privileged-account anomaly or configuration change, but the control's scope is set by what the organization chooses to log/monitor and does not mandate coverage of this specific AD attribute manipulation.
- T1135detects — A.8.15 explicitly requires logging, analysis and correlation of events including successful/rejected resource access attempts, file shares accessed, network activity, alarms from access control systems, and anomalous behaviour via SIEM/UEBA/threat intel, which surfaces T1135's network share enumeration (SMB net view/share, sharing -l) as an indicator of compromise.
- T1135responds — A.8.15 requires logging of successful/rejected resource access attempts, privilege use, file accesses/deletions, configuration changes, and alarms, plus analysis/correlation to identify anomalous behaviour and suspected incidents (including probing), which surfaces T1135 once it runs and supports containment via incident management (5.25).
- T1136detects — A.8.15 explicitly requires logging of account creation/modification/deletion events, synchronized time sources, protected logs, and analysis (including SIEM/UEBA/threat intel correlation) that surfaces anomalous account creation as an indicator of compromise.
- T1136prevents — A.8.15 mandates logging of account creation/modification/deletion events plus protected analysis to surface them as indicators of compromise, which can stop the persistence technique from succeeding when the creation is detected and investigated before the account is leveraged; this is only a slice of the technique's surface (creation itself is not blocked, only some post-creation use on monitored platforms).
- T1136responds — A.8.15 requires logging of account creation events (including identity creation and privilege use), protects those logs from tampering, mandates analysis to surface anomalous account-related activity as indicators of compromise, and ties it to incident handling once an event is underway — exactly the `responds` act of containment/eradication after the technique has run.
- T1136.001detects — A.8.15 explicitly requires logging and analysis of identity creation, privilege use, configuration changes, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces the creation of a local account as an information security event or indicator of compromise.
- T1136.001prevents — A.8.15 mandates logging of identity creation events (item i), privilege use, configuration changes, and anomalous behaviour analysis via SIEM/UEBA/threat intel, which can surface the account creation in real time or shortly after and enable blocking response; this stops many but not all instances of the technique (e.g. stealthy or post-compromise creations outside monitored scopes, or on unlogged network devices/ESXi).
- T1136.002detects — A.8.15 explicitly requires logging and analysis of identity creation events, privilege use, configuration changes, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces domain account creation as a potential indicator of compromise.
- T1136.002prevents — A.8.15 mandates logging of identity creation events (including domain accounts) plus protected analysis to surface them as anomalies or IOCs, which can prevent the persistence technique from succeeding when caught early; it does not stop the account from being created in the first place.
- T1136.003detects — A.8.15 explicitly requires logging of identity creation/modification, privilege use, configuration changes and anomalous behaviour, plus SIEM/UEBA/correlation analysis that surfaces the creation of a cloud account as an information security event or indicator of compromise.
- T1136.003responds — A.8.15 requires log analysis and correlation (including of identity creation, privilege use, and configuration changes) to identify suspected incidents such as unauthorized account creation, then feeds them into the incident management process (5.25) for response; this acts once the technique is underway but only on detectable slices, not all stealthy or low-privilege cloud account creations.
- T1137detects — A.8.15 explicitly requires logging of application transactions, privilege use, configuration changes, identity creation/modification, and anomalous behaviour via log analysis (SIEM/UEBA/IDS rules, correlation, threat intel), which surfaces Office startup persistence mechanisms (macros, add-ins, Outlook rules/forms) as security events or IOCs once they execute.
- T1137responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation) can surface indicators of Office startup persistence mechanisms once they execute and trigger events, enabling incident response; this is a genuine but minority slice of the broad technique class rather than its bulk.
- T1137.001detects — A.8.15 explicitly requires logging of macro-related events (use of applications/utilities, privilege use, file access/deletion, configuration changes), log analysis with UEBA/SIEM/IDS rules to surface anomalous behaviour, and correlation of logs (including physical) to identify indicators of compromise such as malicious Office template macro execution on startup.
- T1137.001prevents — A.8.15 mandates logging of application transactions, privilege use, configuration changes, and anomalous behaviour (with analysis via SIEM/UEBA/threat intel), which can surface the macro insertion or registry hijack before it becomes persistent; this constrains the technique on systems where detection leads to blocking, but does not stop the adversary from modifying the template or enabling macros.
- T1137.001responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and explicit tie to feeding the incident management process (5.25) directly enable containment/eradication once the macro-persistence technique has executed on startup.
- T1137.002detects — A.8.15 explicitly requires log analysis and monitoring of events including changes to system configuration, use of privileges, and anomalous behaviour via SIEM/UEBA/threat intel to surface indicators of compromise; this can detect the Office Test registry addition and DLL execution on Windows/Office, but only where those specific events fall inside the organisation's chosen logging scope and analysis rules rather than being mandated universally.
- T1137.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, and correlation of events (including application transactions, privilege use, and configuration changes) to surface indicators of compromise such as the loading or execution triggered by a malicious Outlook form; this is genuine detection but only a slice because the control does not mandate instrumentation of the specific mailbox/form-loading events or email-triggered code execution.
- T1137.003responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification explicitly surface suspected persistence via malicious Outlook forms (e.g. via UEBA, SIEM rules, or email-related event logs), feeding the incident management process, but this is a minority slice of the technique's execution rather than containment/eradication once underway.
- T1137.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of logs (including application events and successful/failed access), and identification of suspected incidents such as probing or malware, which surfaces the addition and execution of a malicious Outlook Home Page URL as anomalous behavior in event logs.
- T1137.005detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including via SIEM, UEBA, correlation, and review of access attempts), which surfaces the creation/use of malicious Outlook rules as a suspicious event; it is not full because the control's scope is set by what the organization chooses to log/monitor and does not guarantee coverage of this specific mailbox-internal persistence artifact.
- T1137.006detects — A.8.15 explicitly requires logging and analysis of events including use of privileges, application transactions, changes to system configuration, and anomalous behaviour via SIEM/UEBA/IDS correlation, which surfaces Office add-in persistence when it triggers on application start; coverage is a chosen slice (implementation-dependent scope and rules) rather than a bounded remainder.
- T1140detects — A.8.15 explicitly requires logging of security-relevant events (access attempts, privilege use, configuration changes, alarms, system activations), log protection, and analysis (including SIEM/IDS/UEBA rules, anomalous patterns, and correlation) that surfaces deobfuscation activity when it triggers observable indicators such as certutil execution, file reassembly commands, or anomalous process behavior.
- T1140responds — A.8.15's log analysis and monitoring explicitly surface anomalous activity, indicators of compromise, and suspected incidents (including malware-related events) that can include deobfuscation steps once they have run, feeding into incident response; this is a genuine but minority slice of the technique's execution surface rather than the bulk.
- T1176detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of events such as privilege use, configuration changes, application transactions, and successful/failed access attempts — all of which surface malicious or abused extensions once installed and active.
- T1176.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of events such as privilege use, configuration changes, file access/deletion, and security system activation/deactivation — all of which surface the installation, persistence, and post-install actions (stealth, C2, data theft) of malicious browser extensions on Linux/Windows/macOS.
- T1176.001responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS correlation, and identification of suspected incidents (including those from malicious extensions as stealth/persistence) enable response once the technique is underway, but this is only a slice of the full T1176.001 surface (silent install, file manipulation, RAT installer) with heavy dependence on other processes like 5.25 incident handling.
- T1176.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of events (including application and privilege use), and identification of indicators of compromise or suspicious activity that can surface malicious IDE extensions once they execute or trigger logged events, but this is limited to post-install/runtime observables and does not cover silent/side-loaded extensions that produce no detectable log artifacts.
- T1185detects — A.8.15 explicitly requires logging of access attempts, privilege use, configuration changes, system activities and anomalous behaviour, plus SIEM/UEBA/correlation analysis that surfaces browser injection, proxy pivots and inherited-session anomalies as indicators of compromise.
- T1185prevents — A.8.15 mandates logging of access attempts, privilege use, configuration changes, and anomalous behaviour plus protected analysis that can surface browser-injection or pivoting indicators before or during execution, but the control only records and analyses — it does not stop the injection, proxy setup, or session inheritance itself.
- T1185responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (e.g. via SIEM, UEBA, correlation), which surfaces browser session hijacking once underway for further investigation under incident management, but only for observable events and without containment/eradication actions.
- T1187detects — A.8.15 explicitly requires logging of access attempts, privilege use, configuration changes, alarms, security system activation, and anomalous behaviour via SIEM/IDS/UEBA/correlation, which surfaces the forced SMB/WebDAV/EFSRPC authentication events and the resulting NTLM hash exfiltration as indicators of compromise.
- T1187responds — A.8.15's log analysis, correlation, anomalous-behaviour detection (including access attempts, alarms, and physical events) and incident-identification steps directly surface and feed the forced-authentication event into the incident-management process once it is underway, exactly what `responds` names; the named remainder is the slice occurring outside monitored scopes or before logging is enabled.
- T1189detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including successful/rejected access, configuration changes, privilege use, alarms from access control and security systems), and identification of suspected incidents such as malware infection or probing — which surfaces drive-by compromise in flight or post-exploitation on client endpoints.
- T1189responds — A.8.15 requires log analysis and correlation (including of alarms, access attempts, configuration changes, and anomalous behaviour via SIEM/IDS/UEBA) to identify suspected incidents such as probing or malware for further investigation under the incident management process; this bounds an in-progress drive-by once its artifacts reach observable logs, but does not contain/eradicate the actor's foothold or code execution itself.
- T1190detects — A.8.15 explicitly requires logging of access attempts, configuration changes, privilege use, alarms from access-control/IDS systems, and log analysis (with SIEM/IDS/UEBA rules, anomaly detection, and correlation) that surfaces indicators of compromise such as probing or exploitation attempts against public-facing applications.
- T1190responds — A.8.15 requires log analysis and correlation (including of alarms, access attempts, configuration changes, and anomalous behaviour) to identify suspected incidents such as probing of firewalls or malware, then feeds them into the incident management process (5.25) for response once the exploit technique is already underway; this is genuine but only a slice because the clause itself performs detection/analysis rather than containment/eradication.
- T1195detects — A.8.15's log analysis, anomaly detection via SIEM/UEBA/threat intel, and correlation of events (including from third-party apps, updates, and access attempts) can surface indicators of a supply-chain compromise after it has occurred, but this is limited to post-delivery observable artifacts on the consuming systems rather than the upstream manipulation stages themselves.
- T1195.001detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including via SIEM, UEBA, threat intel, and correlation of events such as configuration changes, privilege use, and third-party application transactions), which surfaces some supply-chain compromises after they occur but only for the subset observable in the victim's logs rather than the upstream manipulation itself.
- T1195.002detects — A.8.15 requires log analysis (with SIEM/IDS/UEBA/threat intel) and monitoring of events like config changes, privilege use, file access/deletion, and anomalous behaviour to surface supply-chain indicators such as unexpected modifications or malicious updates; this is genuine but only a slice, as the technique occurs pre-receipt and leaves no guaranteed observable footprint on the victim's systems.
- T1195.003detects — A.8.15 requires log analysis and monitoring (including SIEM/IDS/UEBA rules, anomalous behaviour detection, and correlation of events from systems, networks, and physical access) that can surface indicators of a hardware backdoor once it is present and active on a deployed system; this is genuine but only a minority slice because the technique occurs pre-deployment in the supply chain where most described logging and analysis has no visibility.
- T1197detects — A.8.15 explicitly requires logging of system activities, privilege use, process/application execution, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces BITS job abuse (PowerShell/BITSAdmin invocations, long-lived background transfers, post-reboot execution) as security events or indicators of compromise.
- T1197responds — A.8.15's log analysis, correlation, and identification of suspected incidents (including anomalous behavior or probing) can surface BITS abuse once it has begun, feeding into incident response, but the control itself performs no containment or eradication.
- T1199detects — A.8.15 requires determining, collecting, protecting, and analyzing logs (including access attempts, privilege use, configuration changes, third-party app transactions, anomalous behavior via SIEM/UEBA/correlation, and indicators of compromise) which surfaces T1199 activity that touches logged events, with the bounded remainder being stealthy or pre-compromise supply-chain access that evades the logs.
- T1199responds — A.8.15 requires log analysis, correlation, and identification of suspected incidents (including anomalous third-party access or privilege use) to feed the incident management process (5.25), which performs containment/eradication once the technique is underway; this is a genuine but minority slice of the broad technique (most vectors and supply-chain compromises go unlogged or undetected in time).
- T1200detects — A.8.15 requires log analysis, monitoring for anomalous behaviour, correlation of logs (incl. physical access events), and identification of indicators of compromise or incidents, which can surface some hardware additions (e.g. new devices, network changes, or anomalous traffic) but does not guarantee detection of stealthy or physical-only insertions like DMA or passive taps.
- T1201detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules, correlation, and review of access attempts (including privilege use and configuration changes) to surface indicators of compromise; this catches many T1201 discovery actions in logs, but leaves a bounded remainder for stealthy/local-only queries or unmonitored platforms that produce no observable events.
- T1202detects — A.8.15 explicitly requires logging of command-line and utility usage (including privilege use, system activities, and application transactions), log analysis with UEBA/SIEM/IDS rules to surface anomalous behaviour, and correlation to identify indicators of compromise such as indirect execution that subverts cmd restrictions.
- T1202responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/UEBA/IDS rules on executed commands, utilities, privilege use, and anomalous behavior) directly supports responding to T1202 once the stealthy indirect execution is underway.
- T1203detects — A.8.15 explicitly requires logging, protection, and analysis of events (including successful/rejected access, privilege use, configuration changes, alarms from IDS/AV, anomalous behaviour via SIEM/UEBA/threat intel, and correlation with physical logs) to identify indicators of compromise such as exploitation leading to client execution.
- T1203responds — A.8.15 requires log analysis, anomaly detection, correlation, and explicit identification of suspected incidents (e.g. malware or probing) for further investigation under the incident management process, which directly enacts the containment/eradication acts that `responds` names once T1203 exploitation is underway.
- T1204detects — A.8.15 explicitly requires logging of user actions, privilege use, application execution, file access/deletion, alarms, and anomalous behaviour via log analysis, SIEM, UEBA, and correlation, which surfaces the specific user actions that realise T1204 (opening malicious docs/links, running JS, enabling RATs, manual execution) after they occur.
- T1204responds — A.8.15 requires log analysis and correlation (including of access attempts, privilege use, alarms, and anomalous behaviour) to identify suspected incidents such as malware execution, then feeds them into the incident management process (5.25) for response; this acts once user execution is underway but only surfaces a slice of the technique (e.g. observable post-execution artifacts) rather than containing/eradication itself.
- T1204.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including access attempts, privilege use, configuration changes, and physical logs), and identification of suspected incidents such as probing or malware, which surfaces the user click and follow-on execution from a malicious link.
- T1204.001responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. probing, anomalous behavior) once the malicious-link click has occurred and produced observable events, enabling further investigation per the incident management process; this matches `responds` but is limited to detection-plus-investigation rather than containment/eradication of the technique itself.
- T1204.002detects — A.8.15 explicitly requires logging of file access/deletion, privilege use, application execution, alarms from access control/IDS, and log analysis (with UEBA, SIEM, pattern/trend analysis, and correlation) to identify anomalous behavior and indicators of compromise such as malware or probing, which surfaces T1204.002 execution; the named remainder is events on unmonitored systems or without sufficient analysis depth.
- T1204.002responds — A.8.15 requires log analysis and correlation (including of file-access events, alarms, and anomalous behaviour) to identify suspected incidents such as malware and feed them into the incident-management process (5.25); this is exactly the containment/eradication moment that `responds` names, but only after the file has already been opened and executed.
- T1204.003detects — A.8.15 requires log analysis and monitoring (including SIEM/IDS/UEBA rules, anomalous behaviour detection, and correlation of events such as resource access, configuration changes, privilege use, and alarms) that can surface indicators of a malicious image being deployed and executed, but this is scoped to what the organization chooses to log/monitor and does not guarantee detection of the image-based execution technique itself.
- T1204.003responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomaly detection, correlation of events including successful/failed access, configuration changes, privilege use, and alarms) can surface indicators once a malicious image is deployed and executes, enabling incident response; this is a genuine but minority slice of the technique's full surface (image acquisition, naming tricks, and initial execution in IaaS/containers).
- T1204.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of command/script interpreter use, privilege use, system access attempts, and application transactions — all of which surface the social-engineering-driven paste-and-execute event once it occurs.
- T1204.004responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification directly support containment/eradication once the executed command (and its effects) are underway, with the named remainder being pre-execution social engineering that leaves no observable event until paste/execution occurs.
- T1204.005detects — A.8.15's log analysis, anomaly detection via SIEM/UEBA/threat intel, and review of access/usage events can surface indicators of a malicious library after installation and execution, but this is limited to observable post-execution artifacts rather than the library upload, typosquatting, or install itself.
- T1205detects — A.8.15 explicitly requires logging of access attempts (successful/rejected), network activity, alarms from access-control/IDS systems, anomalous behaviour via SIEM/UEBA/correlation, and analysis of events against threat intelligence to surface indicators of compromise such as unusual packet sequences or port-knocking patterns.
- T1205responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (including probing of firewalls, unusual network patterns, and physical events) directly support responding to traffic signaling once underway by surfacing the magic packets or sequences as indicators of compromise for containment and eradication.
- T1205.001detects — A.8.15 explicitly requires logging of successful/rejected access attempts, network activity, alarms from access control systems, and analysis of logs (including via SIEM/IDS rules, UEBA, and correlation) to identify anomalous behaviour and indicators of compromise such as probing; this surfaces port-knocking sequences in the great majority of cases, with a bounded remainder for fully stealth implementations that generate no observable events at all.
- T1205.001prevents — A.8.15 mandates logging of access attempts, configuration changes, privilege use, alarms, and security system activation/deactivation plus analysis to surface anomalous behaviour; this can prevent the port-knocking sequence from successfully triggering a hidden port on systems where the firewall or custom listener is itself configured under the logged baseline and the knock packets are treated as rejected-access or anomalous events that are blocked before the port opens.
- T1205.001responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including probing of firewalls), which can surface port-knocking sequences once underway and feed the incident-response process, but does not itself contain or eradicate the actor or the opened port.
- T1205.002detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, DNS log checks for malicious C2, correlation of events, and identification of indicators like probing or anomalous behavior, which can surface socket filter installation or triggered backdoor activity in monitored environments, but the technique's passive/low-activity/raw-socket nature (as noted in the source prose) leaves substantial detection gaps on unmonitored interfaces or without specific raw packet/setsockopt visibility.
- T1205.002responds — A.8.15's log analysis, correlation, and monitoring of events (including network activity, alarms, anomalous behavior, and suspected incidents) can surface socket filter activation or related C2 once a matching packet triggers it, enabling response under the incident management process, but the technique's passive/low-activity nature and limited raw socket visibility leave a large detection gap
- T1207detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, correlation, and review of access attempts/config changes/privilege use to surface indicators of compromise; this can catch post-registration replication anomalies or metadata tampering, but the technique's explicit design to bypass system logging/SIEM (actions not reported to sensors) and delete metadata leaves a large, named gap in detection coverage.
- T1207responds — A.8.15 requires log analysis and correlation (including SIEM/IDS/UEBA rules, anomalous behaviour detection, and incident identification) that can surface DCShadow activity once it occurs, feeding the incident management process, but the technique's explicit bypass of logging/SIEM and metadata tampering create a large, named remainder where the response trigger is absent.
- T1210detects — A.8.15 explicitly requires logging, analysis, and monitoring of events including successful/rejected access attempts, privilege use, configuration changes, alarms from access control/IDS, anomalous behaviour via SIEM/UEBA/correlation, and identification of incidents such as probing of firewalls or malware, which surfaces most instances of remote service exploitation (T1210) after it occurs.
- T1210responds — A.8.15 requires log analysis (with SIEM/IDS/UEBA rules, anomaly detection, correlation, and explicit identification of suspected incidents such as probing of firewalls or malware) plus escalation to incident management (5.25), which surfaces and contains an in-progress remote service exploitation once it generates observable events.
- T1211detects — A.8.15 mandates determining what to log, protecting logs from tampering/deletion, requiring synchronized time sources, and performing log analysis (with SIEM/IDS/UEBA rules, anomaly detection, correlation, and review of access attempts/DNS/physical logs) to identify indicators of compromise and suspected incidents, which surfaces exploitation used to suppress logging or evade audit trails.
- T1212detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including access attempts, privilege use, configuration changes, and alarms), and identification of suspected incidents such as probing or malware that would surface exploitation activity aimed at credential mechanisms.
- T1212responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and explicit tie to identifying suspected incidents for the incident management process (5.25) directly enable response once T1212 exploitation is underway.
- T1213detects — A.8.15 requires log analysis and monitoring of events (including access attempts, configuration changes, privilege use, and anomalous behaviour via SIEM/UEBA/correlation) that can surface adversary mining of repositories, but only for events that generate observable logs and only where analysis is performed; the technique itself (leveraging a repository) is not inherently an auditable event and many repository accesses fall outside the clause's named logging scope.
- T1213.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and correlation of events (including access attempts, configuration changes, privilege use, and physical logs) to identify indicators of compromise such as probing or unauthorized access to repositories like Confluence.
- T1213.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and correlation of events (including access attempts, configuration changes, privilege use, and file access) to identify indicators of compromise such as probing or unusual repository activity, which surfaces SharePoint mining in flight.
- T1213.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts (including to resources like code repositories) to surface indicators of compromise such as unauthorized collection activity.
- T1213.003prevents — A.8.15 requires logging of access attempts, privilege use, configuration changes, and file accesses (including in applications and third-party services), plus protected immutable logs and analysis that can surface anomalous repository access before or during collection; this constrains the technique on monitored internal/SaaS repositories but leaves unmonitored public or external repos, incomplete coverage of credential extraction inside source, and post-breach collection after valid access fully outside its scope.
- T1213.004detects — A.8.15 requires log analysis and monitoring (including SIEM/UEBA rules, anomalous behaviour detection, and correlation of access/resource events) that can surface adversary mining of CRM data as unusual activity or an indicator of compromise once it occurs, but this is scoped only to events the organization chooses to log and analyse rather than a dedicated or guaranteed detection of this technique.
- T1213.004responds — A.8.15's log analysis and incident identification explicitly surface suspected/actual events (e.g. anomalous access to protected resources or data) for further investigation under incident management, which is the core of `responds` once the technique is underway; partial because it is scoped to detectable logging/monitoring slices rather than all CRM mining paths (especially SaaS with limited visibility).
- T1213.005detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM/IDS rules, anomalous behaviour detection, and correlation of events such as access attempts or configuration changes) that can surface adversary mining of messaging apps when it produces observable indicators, but the control's scope is limited to defined events and does not guarantee coverage of all chat-based exfiltration or reconnaissance on SaaS platforms.
- T1213.005responds — A.8.15's log analysis and monitoring explicitly target detection of anomalous behaviour and suspected incidents (including probing or data exfiltration patterns), then feeds them into incident response per 5.25; this acts on the technique once underway but only for the subset of messaging abuse that produces observable events rather than silent mining.
- T1213.006detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including access attempts, privilege use, configuration changes, and physical logs), and identification of suspected incidents such as probing — which surfaces database mining in real time or post-facto across the named platforms.
- T1213.006responds — A.8.15's log analysis, anomaly detection, correlation, and identification of suspected incidents (e.g. probing, unusual access) directly supports responding to an in-progress database mining event once underway, with the named remainder being stealthy exfiltration that evades detection before response.
- T1216detects — A.8.15 explicitly requires logging and analysis of events including use of applications/utilities, privilege use, system activities, anomalous behaviour via SIEM/UEBA/IDS correlation, and indicators of compromise, which surfaces proxy execution of malicious files through trusted signed scripts.
- T1216.001detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, application/script execution, configuration changes, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces PubPrn.vbs abuse as a signed script proxying remote execution; the named remainder is in-process or non-logged edge cases outside the monitored scope.
- T1216.001responds — A.8.15 requires log analysis (with SIEM/IDS/UEBA rules, anomaly detection, correlation, and explicit review of access attempts, privilege use, configuration changes, and alarms) to identify and investigate suspected incidents once the PubPrn abuse has executed, which is exactly what `responds` names.
- T1216.002detects — A.8.15 explicitly requires logging of system activities, privilege use, script/application execution, command-line details and anomalous behaviour, plus analysis via SIEM/UEBA/correlation to surface indicators of compromise such as living-off-the-land proxy execution of PowerShell via a signed VBS.
- T1216.002responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and identification of suspected incidents (e.g. probing or malware) directly enables response once the proxy execution technique is underway.
- T1217detects — A.8.15 requires log analysis and monitoring (including of file access, system activities, and anomalous behaviour via SIEM/UEBA/correlation) that can surface browser-enumeration activity after it occurs, but this is scoped by what the organization chooses to log/monitor and does not inherently cover all local-file reads or browser-specific artifacts.
- T1218detects — A.8.15 explicitly requires logging and analysis of events including use of privileges, utility programs, system activities, successful/rejected access attempts, and anomalous behaviour via SIEM/UEBA/IDS correlation, which surfaces proxy execution of malicious content through trusted binaries as an indicator of compromise.
- T1218responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification directly support responding to (containing/eradicating) T1218 once the proxy execution is underway via logged events like process use, privilege escalation, and anomalous behavior.
- T1218.001detects — A.8.15 explicitly requires logging and analysis of events including successful/rejected access attempts, use of applications/utilities, system configuration changes, alarms from access control/IDS, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces hh.exe execution of suspicious CHM payloads as an indicator of compromise.
- T1218.001responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification directly support responding to (containing/eradication path for) a realized T1218.001 execution once underway via logged events like process use, file access, and alarms.
- T1218.002detects — A.8.15 explicitly requires logging of system access attempts, privilege use, configuration changes, application execution, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces control.exe proxying of malicious CPL/DLL payloads as an information security event.
- T1218.002responds — A.8.15 requires logging of access attempts, privilege use, configuration changes, alarms, security system activation and anomalous behaviour, plus analysis to identify incidents (including malware or probing); this surfaces and enables response to T1218.002 execution once underway, with the named remainder being stealthy or non-logged variants that evade the listed events.
- T1218.003detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, application transactions, successful/rejected access attempts, and anomalous behaviour via SIEM/UEBA/IDS correlation plus physical logs; this surfaces CMSTP.exe abuse (a signed binary proxying DLL/SCT execution or UAC bypass) as an anomalous or suspicious event after it runs.
- T1218.003responds — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and identification of suspected incidents (e.g. probing or malware) directly enable response once the CMSTP abuse technique is underway.
- T1218.004detects — A.8.15 explicitly requires logging of system activities, privilege use, application execution, configuration changes and anomalous behaviour, plus SIEM/IDS/UEBA correlation and analysis that surfaces proxy execution through a signed utility such as InstallUtil.
- T1218.005detects — A.8.15 explicitly requires logging of system activities, privilege use, application/utility execution, successful/rejected access attempts, and anomalous behaviour via log analysis (SIEM/UEBA/IDS correlation), which surfaces mshta.exe abuse as an anomalous or suspicious process execution.
- T1218.005responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/IDS/UEBA rules on executed processes, scripts, network activity or privilege use) surface mshta.exe abuse once underway for containment under incident management, but this is only a slice of the technique's possible forms (e.g. inline scripts or non-logged executions) rather than a bounded remainder.
- T1218.007detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, application execution, configuration changes, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces msiexec.exe abuse as an indicator of compromise on Windows systems.
- T1218.008detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, application execution, configuration changes, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces the signed-binary proxy execution of a malicious DLL as an observable event.
- T1218.008responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/IDS/UEBA rules on process execution, DLL loads, or signed binary abuse) directly support containment/eradication once the T1218.008 proxy execution is underway.
- T1218.009detects — A.8.15 explicitly requires logging of system activities, privilege use, application execution, configuration changes and anomalous behaviour, then mandates analysis (SIEM/UEBA/rules/threat intel) that surfaces proxy-execution techniques such as Regsvcs/Regasm; the named remainder is events outside the chosen logging scope or before analysis occurs.
- T1218.010detects — A.8.15 explicitly requires logging of system activities, privilege use, application execution, successful/rejected access attempts, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces Regsvr32 abuse (especially network-loaded COM scriptlets or unusual process activity) as an indicator of compromise; the named remainder is stealthier in-memory or allowlisted invocations that produce no distinct log artifact.
- T1218.010responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (e.g. malware execution or probing), then subject them to further investigation as part of incident management; this directly enacts the containment/eradication steps that `responds` names once the Regsvr32 abuse is underway.
- T1218.011detects — A.8.15 explicitly requires logging of system activities, privilege use, process/application execution, successful/rejected access attempts, and anomalous behaviour via SIEM/UEBA/IDS correlation plus log analysis to surface indicators of compromise such as unusual rundll32.exe invocations proxying malicious code.
- T1218.011responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, suspected incidents (including malware execution or probing), and support further investigation under incident management, which matches the `responds` verb once the rundll32 abuse is underway; partial because the clause sets requirements for what to log/analyse rather than mandating universal detection of every proxying, masquerading or ordinal variant described.
- T1218.012detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, process execution, anomalous behaviour via SIEM/UEBA/IDS correlation, and indicators of compromise, which surfaces verclsid.exe abuse as a signed-binary proxy technique.
- T1218.012prevents — A.8.15 requires logging of system activities, privilege use, application execution, configuration changes and anomalous behaviour (with analysis via SIEM/UEBA), which can surface verclsid.exe abuse as an unusual process or COM activity before or during execution; however, it does not stop the binary from being invoked or the payload from running.
- T1218.012responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification directly support responding to (containing/eradication steps for) a realized verclsid.exe proxy execution once underway.
- T1218.013detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, threat intelligence, and correlation of events (including process activity, privilege use, and anomalous behaviour) to surface indicators of compromise such as suspicious mavinject.exe invocations; this is genuine detection but only a slice because the clause sets requirements rather than mandating universal host telemetry depth, leaving implementations that omit process-injection telemetry fully conformant.
- T1218.013responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/IDS/UEBA on process activity, privilege use, system changes) directly supports containment/eradication once the mavinject.exe abuse is underway, with the named remainder being fully stealthy injections that produce no observable events.
- T1218.014detects — A.8.15 explicitly requires logging and analysis of events including use of privileges, system activities, application transactions, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces MMC abuse (signed binary proxying malicious .msc/CLSID payloads) as an indicator of compromise.
- T1218.014responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification directly surface MMC abuse (e.g. anomalous .msc execution or wbadmin catalog deletion) once underway, enabling response per the linked 5.25 process; mostly because physical/endpoint coverage and exact technique signatures remain implementation-dependent.
- T1218.015detects — A.8.15 requires log analysis and monitoring (including of system activities, privilege use, application transactions, anomalous behaviour via UEBA/SIEM/IDS correlation, and physical events) that can surface Electron abuse indicators such as unusual child processes or JS execution, but the clause's scope is set by organisational requirements and does not mandate coverage of all Electron-specific mechanics or background disguised activity.
- T1218.015responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and identification of suspected incidents (e.g. malware or probing) directly supports responding to an in-progress Electron abuse event once underway.
- T1219detects — A.8.15 explicitly requires logging, protection, and analysis of events including system access attempts, privilege use, configuration changes, application transactions, anomalous behaviour via SIEM/UEBA/IDS correlation, and indicators of compromise, which surfaces post-compromise use or installation of remote access tools as described in T1219.
- T1219responds — A.8.15's log analysis, correlation, and identification of suspected incidents (including anomalous remote sessions or EDR-abuse patterns) directly supports the incident-handling response once a RAT technique is underway, but the clause itself performs no containment or eradication.
- T1219.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of network connections, successful/failed access, configuration changes, privilege use, and physical events — all of which surface IDE tunneling (network sessions, process/CLI activity, persistence, and anomalous developer-tool behavior) in most cases, with a bounded remainder for fully encrypted or out-of-scope sessions.
- T1219.001responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS correlation, and identification of suspected incidents (including probing or C2-like outbound activity) directly enable response once IDE tunneling is underway, with the named remainder being stealthy sessions that blend perfectly with developer workflows and produce no observable events.
- T1219.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, configuration changes, privilege use, and network activity that would surface unauthorized or anomalous use of remote desktop tools as indicators of compromise.
- T1219.002responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. anomalous remote access, probing, or C2 patterns) for further investigation under the incident management process, which is the core of `responds`; it is only partial because the clause stops at identification/analysis and does not itself perform containment or eradication.
- T1219.003detects — A.8.15 explicitly requires log analysis, anomalous behaviour detection via SIEM/IDS/UEBA/correlation, and monitoring of physical events (e.g. entrance/exit logs) plus successful/failed access attempts, which surfaces some post-install use of hardware KVM as an alternate C2 channel but leaves the bulk of stealthy physical installation and bypass of software solutions outside its scope.
- T1219.003responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA/correlation of access attempts, alarms, configuration changes, physical events) can surface anomalous hardware-based remote sessions once underway as an indicator of compromise, enabling incident response, but this is a minority slice given the technique's legitimate-hardware and physical-install nature that often evades software logging.
- T1220detects — A.8.15 explicitly requires logging of security-relevant events (access attempts, privilege use, configuration changes, alarms, security system activation), analysis for anomalous behaviour/IOC via SIEM/UEBA/threat intel, and correlation of logs (including from physical monitoring) to identify incidents such as probing or malware; this surfaces T1220's use of msxsl.exe/wmic with suspicious XSL files or anomalous script execution in most cases, though file-extension tricks and non-monitored processes remain a bounded remainder.
- T1220responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification directly support responding to (containing/eradication steps for) in-flight or realized XSL script processing once it generates observable events.
- T1221detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, unusual activity (including from external resources, DNS, and correlated events), which surfaces template-injection documents when they trigger fetches, authentication attempts, or other logged events; this is genuine but only a slice because the technique can be crafted to produce no observable events until after payload execution and many delivery vectors (e.g. phishing) fall outside the logging scope.
- T1221responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and identification of suspected incidents (e.g. probing or malware) can surface template injection once the document loads and triggers a fetch or auth attempt, enabling response; this is limited to observable post-execution effects rather than the concealment or modification itself.
- T1222detects — A.8.15 explicitly requires logging and analysis of events including privilege use, configuration changes, file access/deletion, alarms from access-control systems, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces T1222's permission/ACL modifications after they occur.
- T1222.001detects — A.8.15 explicitly requires logging of privilege use, configuration changes, file access/deletion, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces T1222.001's icacls/cacls/takeown/attrib/PowerShell DACL modifications as security events or indicators of compromise.
- T1222.001responds — A.8.15's log analysis and monitoring of access attempts, privilege use, configuration changes, and anomalous behaviour (including correlation to SIEM/IDS/UEBA) can surface a T1222.001 permission modification once it has occurred as an indicator of compromise, enabling response actions; this is limited to detection of observable events rather than containment or eradication of the technique itself.
- T1222.002detects — A.8.15 explicitly requires log analysis and monitoring of events including privilege use, configuration changes, file access/deletion, and anomalous behaviour (with SIEM/UEBA/correlation), which surfaces Linux/Mac permission modifications (chown/chmod) when they occur and are logged.
- T1480detects — A.8.15 mandates log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and explicit review of access attempts, configuration changes, privilege use, and alarms that can surface guardrail checks or environment-specific conditions when they produce observable events.
- T1480.001detects — A.8.15 mandates log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of events (including system activities, privilege use, configuration changes, and network behavior) that can surface indicators of environmental keying such as anomalous decryption, unusual file/system checks, or unexpected network/IP-derived behavior; this is genuine but only a slice because the technique is designed to evade detection, operates silently until triggered, and many of its environmental-value derivations (e.g., specific AD joins or physical-device checks) produce no observable event in the required logs.
- T1480.002detects — A.8.15 requires log analysis and monitoring (including SIEM/IDS/UEBA rules, anomalous behaviour detection, and correlation of events such as process activities or file locks) that can surface mutex-based single-instance checks as indicators of compromise, but this is only a slice of the technique's possible implementations and is not required to cover mutex acquisition itself.
- T1482detects — A.8.15 explicitly requires logging and analysis of system access attempts, privilege use, configuration changes, identity modifications, and anomalous behaviour via SIEM/UEBA/correlation to surface indicators of compromise, which directly catches domain trust enumeration activity (Nltest, LDAP, API calls) in monitored environments.
- T1482responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of access and configuration events) can surface domain-trust enumeration in flight as an indicator of compromise or precursor to lateral movement, which is the core of `responds`; it is only a slice because the clause does not mandate coverage of every LDAP/Nltest pattern or every environment.
- T1484detects — A.8.15 explicitly requires logging, protection, and analysis of events including changes to system configuration, use of privileges, and anomalous behaviour via SIEM/UEBA/threat intel correlation, which surfaces T1484's policy modifications (GPO, trust, federation) as security events or indicators of compromise.
- T1484responds — A.8.15's log analysis, anomaly detection, correlation, and explicit tie to feeding the incident management process (5.25) let it respond to T1484 once the modification is logged as a configuration change, privilege use, or anomalous event; partial because the control only surfaces the indicator and hands off to IR without performing containment or eradication itself.
- T1484.001detects — A.8.15 explicitly requires logging of privilege use, configuration changes, system access attempts, and security system activation/deactivation, plus log analysis with SIEM/UEBA/threat-intel rules to surface anomalous behaviour and indicators of compromise; GPO modification (especially of rights or scheduled tasks) produces observable events in those categories on Windows domain controllers, though some stealthy or post-compromise edits may evade the logged set.
- T1484.001prevents — A.8.15 mandates logging of privilege use, configuration changes, system access attempts, and protected-resource access (including GPO-related paths in SYSVOL), plus protected immutable logs and analysis that can surface anomalous GPO modifications before they fully succeed; this constrains the technique on monitored Windows domains but does not stop an adversary who already holds delegated write rights or bypasses the logging scope.
- T1484.001responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification explicitly surface GPO modifications as security events (config changes, privilege use, identity mods) for response under 5.25 once the technique is underway.
- T1484.002detects — A.8.15 explicitly requires logging, analysis, and monitoring of configuration changes, privilege use, system access attempts, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces trust modifications as security events or indicators of compromise in most covered environments.
- T1484.002responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (including configuration changes, privilege use, and anomalous behavior) for further investigation under the incident management process (5.25), which is the core of `responds`; it is only partial because the control stops at detection/analysis/hand-off and does not itself perform containment or eradication.
- T1485detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including file deletions, privilege use, configuration changes, and alarms), and identification of incidents such as malware or probing that match T1485's destructive actions.
- T1485recovers — A.8.15 requires determining logging purposes, protecting logs against deletion/alteration/overwriting, archiving for retention/evidence, and analysis to identify incidents, which supports forensic recovery and investigation after data destruction but does not itself restore destroyed data or availability.
- T1485.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of logs (including physical), and identification of suspected incidents such as probing or malware, which surfaces lifecycle-policy changes that delete log buckets as an indicator-removal action.
- T1485.001recovers — A.8.15 requires determining log purposes, protecting logs against deletion/overwriting (via append-only, hashing, archiving per 5.28), and retaining them for evidence/incident support; this directly enables recovery of deleted log objects via retained/archived copies after a lifecycle-triggered deletion.
- T1486detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including file access/deletion, privilege use, config changes, and physical logs), and identification of suspected incidents such as malware infection, which surfaces ransomware encryption activity after it begins.
- T1486recovers — A.8.15 requires determining what to log (including file access/deletion, configuration changes, privilege use), protecting logs against tampering or loss, and performing analysis/correlation to identify incidents; this directly supports post-encryption recovery investigations and evidence-based restoration per the control's stated purpose, with the named remainder being that it does not itself perform data restoration (that is A.8.13).
- T1486responds — A.8.15 requires log analysis and correlation (including of physical events, alarms, configuration changes, privilege use, and anomalous patterns via SIEM/UEBA/threat intel) to identify suspected/actual incidents such as ransomware encryption, then feeds them into the incident management process (5.25) for response; this directly supports containment/eradication once the technique is underway, with the named remainder being impact (already-encrypted data) that responding does not undo.
- T1489detects — A.8.15 explicitly requires logging, analysis, and monitoring of events including use of privileges, system configuration changes, alarms from access control/IDS, activation/deactivation of security systems, and anomalous behaviour via SIEM/UEBA/correlation to identify incidents, which surfaces T1489 (service stop/disable) in most cases as it triggers these logged indicators.
- T1489responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. service-stop alarms, anomalous behaviour, correlation for incident management per 5.25), which is the core of `responds` once the technique is underway; it is only partial because the clause stops at identification/analysis and does not itself perform containment or eradication.
- T1490detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of logs (including physical), and identification of suspected incidents such as probing or malware that commonly precede or accompany T1490 actions on recovery features.
- T1490responds — A.8.15's log analysis, correlation, anomaly detection (including physical logs), and explicit tie-in to feeding the incident management process (5.25) let responders see the T1490 actions (deletion of shadow copies, disabling recovery, backup policy changes) once they are underway, enabling containment/eradication.
- T1491detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including configuration changes, privilege use, file access/deletion, and alarms), and identification of suspected incidents such as probing or malware that commonly precede or accompany defacement.
- T1491.001detects — A.8.15 explicitly requires logging, protection, and analysis of events including system configuration changes, privilege use, file accesses/deletions, alarms, and anomalous behaviour via SIEM/UEBA/threat intel/correlation, which surfaces internal defacement (e.g. altered websites, login messages, desktop wallpaper) after it occurs.
- T1491.001responds — A.8.15's log analysis, anomaly detection, and incident identification (e.g. via SIEM/UEBA/correlation) surface defacement once performed, feeding the incident response process (5.25), but do not themselves contain or eradicate it.
- T1491.002detects — A.8.15 requires logging, analysis, and monitoring of events including system access attempts, configuration changes, alarms, security system activation, anomalous behaviour, and correlation with threat intelligence — all of which surface external defacement once it has occurred on web-facing assets.
- T1495detects — A.8.15 requires log analysis and monitoring (including of system activities, configuration changes, privilege use, security system activation, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface firmware corruption indicators post-event, but this is a minority slice — the control's focus is on OS/application/event logging rather than low-level firmware or non-volatile memory manipulation on the listed platforms.
- T1496detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and monitoring of resource-use indicators (privileged use, system changes, network activity, alarms) that surface cryptomining, proxying, or spam patterns as IOCs.
- T1496responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of logs including resource usage patterns) surface suspected resource hijacking once underway as an information security event, feeding into incident management (5.25) for response, but this is only a slice of the broad technique (e.g. does not address all forms like proxyjacking or SMS spam).
- T1496.001detects — A.8.15 explicitly requires logging, analysis, and monitoring of system activities, resource access, configuration changes, privilege use, anomalous behaviour via UEBA/SIEM/IDS, and correlation to identify indicators of compromise such as unexpected high CPU consumption from mining processes.
- T1496.001responds — A.8.15 requires log analysis and monitoring to identify anomalous resource consumption or indicators of compromise (e.g. via SIEM, UEBA, trend analysis, and correlation), which surfaces an in-progress compute hijacking for further investigation and incident response per 5.25, but does not itself contain or eradicate the technique once underway.
- T1496.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, DNS log checks for malicious C2, correlation of events, and identification of indicators like probing or malware that surface bandwidth hijacking, botnet activity, or scanning as security events.
- T1496.002responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS correlation, and explicit tie to incident management (5.25) enable response once bandwidth hijacking (botnet, proxyjacking, scanning) is underway, but this is only a detection-to-response slice with no containment or eradication mechanism in the control itself.
- T1496.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of logs (including from web forms, applications, and network activity), and identification of suspected incidents such as probing or anomalous behaviour that directly surfaces SMS-pumping patterns before or while availability and cost impacts occur.
- T1496.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and monitoring of access attempts, configuration changes, privilege use, and resource activity — all of which surface SaaS hijacking behaviors such as unexpected service enablement, bulk messaging, or anomalous AI proxying after the fact.
- T1496.004prevents — A.8.15's logging of access attempts, privilege use, configuration changes, identity creation and anomalous behaviour (via analysis, SIEM, UEBA, threat intel) can surface the initial compromise or service-enablement step that enables SaaS hijacking, thereby preventing the technique in some but not most cases; it does not stop already-compromised credential abuse or quota exhaustion itself.
- T1496.004responds — A.8.15 requires log analysis and correlation to identify suspected incidents (e.g. anomalous resource use or probing) for further investigation under incident management, which matches the `responds` verb once the hijacking technique is underway; partial because it surfaces knowledge but does not itself contain/eradicate the active abuse.
- T1497detects — A.8.15's log analysis and monitoring explicitly surface anomalous behavior, indicators of compromise, and events like security tool usage or unusual activity that map to T1497's detection of monitoring artifacts (e.g. Wireshark, Sysinternals) or sandbox checks, but only for executed techniques on monitored systems and not the pre-execution evasion itself.
- T1497.001detects — A.8.15 requires log analysis and monitoring of events (including system activities, configuration changes, privilege use, and anomalous behaviour via SIEM/UEBA/correlation) that can surface many of the discovery-oriented system checks and artifacts named in T1497.001, but does not mandate coverage of all possible VME checks (especially low-level hardware, memory, or non-event-based ones) nor guarantee detection before the technique completes.
- T1497.002detects — A.8.15's log analysis and monitoring explicitly surface anomalous user activity, UEBA patterns, and indicators of compromise that can include the specific user-interaction artifacts (mouse movements, browser history, file counts, interaction timing) this technique relies on or leaves behind
- T1497.003detects — A.8.15 requires synchronized time sources, log analysis for anomalous behaviour, and correlation of events (including physical monitoring and UEBA), which can surface time-based sandbox evasion as anomalous activity or an IOC; this is genuine but only a slice, as the control does not mandate instrumentation of the specific API calls or time-check patterns themselves.
- T1498detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of logs (including network/DNS/firewall/physical), and identification of suspected incidents such as probing of firewalls, which surfaces most forms of network DoS traffic or its precursors.
- T1498recovers — A.8.15's log analysis, correlation, and identification of incidents (including anomalous traffic or probing) can support post-DoS recovery by enabling faster investigation and restoration of availability, but the control itself performs no restoration of service or bandwidth.
- T1498responds — A.8.15 requires log analysis and correlation (including of network events, alarms, and anomalous traffic) to identify suspected incidents such as probing or bandwidth-exhausting attacks once underway, feeding the incident management process; this is the core of `responds` but stops at detection/analysis without mandating containment or eradication actions.
- T1498.001detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, DNS log checks for malicious outbound C2, correlation of events, and identification of indicators like probing of firewalls or anomalous traffic patterns, which surfaces Direct Network Flood (including botnet-driven volumetric attacks) once underway.
- T1498.001responds — A.8.15 requires log analysis and correlation (including network/DNS/IDS events and anomalous traffic patterns) to identify suspected incidents such as probing or flooding once underway, feeding the incident response process, but does not itself contain or eradicate the flood.
- T1498.002detects — A.8.15 explicitly requires logging, analysis, and monitoring of network events, anomalous behaviour, DNS logs for outbound connections to malicious servers, and correlation to identify indicators of compromise such as probing or high-volume traffic patterns that match reflection amplification DoS.
- T1498.002recovers — A.8.15's log analysis, correlation, and identification of incidents (including network anomalies like probing or high-volume traffic) supports post-DoS investigation and recovery activities, but does not itself restore availability or functionality of the targeted system(s) and network.
- T1498.002responds — A.8.15's log analysis, correlation, and identification of suspected incidents (e.g. probing of firewalls, anomalous outbound DNS) can surface an ongoing reflection amplification flood once underway for further incident handling, but this is limited to detection-plus-response workflow rather than containment/eradication itself.
- T1499detects — A.8.15 explicitly requires logging of access attempts, privilege use, configuration changes, alarms, security system activation, and anomalous behaviour via SIEM/IDS/UEBA/correlation, which surfaces the resource-exhaustion or crash symptoms of endpoint DoS (and many of its precursors) after the fact.
- T1499recovers — A.8.15's log analysis and correlation explicitly support incident investigation and identification of events leading to incidents, which aids recovery from the availability loss caused by Endpoint DoS once the attack has occurred.
- T1499responds — A.8.15 requires log analysis and correlation (including of alarms, access attempts, configuration changes, and anomalous behaviour via SIEM/IDS/UEBA) to identify suspected incidents such as probing or resource exhaustion, which feeds the incident management process (5.25) for containment/eradication once the DoS is underway; this is a genuine but minority slice of the broad technique that spans multiple unlogged layers and botnet-scale traffic.
- T1499.001detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, threat intelligence, and monitoring of network activity (including DNS, firewalls, and anomalous behaviour) to identify indicators of compromise such as probing or resource-exhaustion events; this surfaces the flood technique in flight for most cases, with the bounded remainder being fully stealthy or non-network floods outside configured scopes.
- T1499.001responds — A.8.15 requires log analysis and correlation (including of network events, alarms, and anomalous behaviour) to identify suspected incidents such as probing or resource-exhaustion patterns once underway, feeding the incident-management process; this is exactly `responds` but only partial because the clause stops at detection/analysis and does not itself perform containment or eradication.
- T1499.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of network events, resource access attempts, DNS logs for malicious outbound, and correlation to identify incidents such as probing or resource exhaustion that match the flood/renegotiation patterns in T1499.002.
- T1499.002responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, suspected incidents (e.g. probing or resource exhaustion patterns), and feed them into the incident management process (5.25) for response once the flood is underway.
- T1499.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of resource-related events (access attempts, configuration changes, alarms, application transactions, physical events) that surface application-exhaustion floods as indicators of compromise or anomalous behavior.
- T1499.003responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. anomalous resource usage, probing) for further investigation under the incident management process, which is the core of `responds`; it does not itself contain or eradicate the flood.
- T1499.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of crashes/restarts as security events or indicators of compromise, which surfaces the exploitation technique in flight or post-crash.
- T1499.004responds — A.8.15 requires log analysis and correlation (including of crashes, alarms, configuration changes, and anomalous behaviour) to identify suspected incidents for further investigation under the incident management process, which is the core of `responds`; it does not itself contain or eradicate the exploitation.
- T1505detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of events such as configuration changes, privilege use, application transactions, and alarms that would surface installation of a malicious server component.
- T1505responds — A.8.15's log analysis and monitoring explicitly surface indicators of compromise such as anomalous behaviour, malware infection or probing, which can represent the post-installation abuse of a malicious server component; this is containment/eradication once underway (responds) but only for the subset of T1505 activity that produces observable events rather than the installation itself.
- T1505.001detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, threat intelligence, and correlation of events (including configuration changes, privilege use, application transactions, and anomalous behaviour) that can surface malicious stored-procedure creation, modification, or invocation as an indicator of compromise.
- T1505.002detects — A.8.15 requires log analysis and monitoring of events (including system configuration changes, privilege use, application activity, and anomalous behaviour via SIEM/UEBA/correlation) that can surface registration and invocation of a malicious transport agent, but this is limited to observable logged events and does not guarantee detection of the technique itself (especially on Linux or when stealthily configured).
- T1505.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of events (including access attempts, configuration changes, privilege use, and web/application transactions), and identification of indicators like probing or malware that surface a deployed web shell after it is present.
- T1505.003responds — A.8.15 requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and feeding suspected incidents (e.g. probing or malware) into the incident management process (5.25), which directly enacts the containment/eradication steps that `responds` names once a web shell is present and active; it is only partial because the clause stops at identification/analysis/hand-off and does not itself perform the response actions.
- T1505.004detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, threat intelligence, and correlation of events (including changes to system configuration, use of privileges, alarms, and activation of security systems) to surface anomalous behaviour and indicators of compromise; this surfaces the installation and use of malicious IIS components in monitored environments but is scoped by what the organization chooses to log/monitor and does not guarantee coverage of all installation vectors or unmonitored systems.
- T1505.005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules, correlation of events (including privilege use, configuration changes, system access attempts, and security system activation), and identification of indicators of compromise such as malware or probing, which can surface Terminal Services DLL modification or replacement after it occurs; it is not full because the control's scope is set by organizational policy and does not mandate instrumentation of every Registry, file-integrity, or DLL-load event required to catch this technique in all cases.
- T1505.006detects — A.8.15 explicitly requires logging, analysis, and monitoring of events including system configuration changes, privilege use, utility program execution, alarms from access control and security systems (e.g. IDS), anomalous behaviour via SIEM/UEBA/threat intel, and correlation of logs to identify indicators of compromise such as malware or probing; this surfaces malicious VIB installation and boot-persistent changes on ESXi in a monitored environment but only for events inside the chosen scope and tooling, leaving gaps for unmonitored hypervisors or stealthy VIBs that avoid logged indicators.
- T1518detects — A.8.15 requires log analysis, anomaly detection via SIEM/UEBA/threat intel, and specific monitoring (e.g. of system activities, privilege use, configuration changes, and installed tools) that surfaces software enumeration as anomalous behavior or an indicator of compromise.
- T1518responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification directly surface Software Discovery in flight or post-execution as an information security event, enabling response under the linked incident management process (5.25).
- T1518.001detects — A.8.15 explicitly requires log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomalous behaviour detection, correlation of logs including security system alarms and AV/IDS activation) that surface the execution of discovery commands and the presence/behaviour of security software itself.
- T1518.001responds — A.8.15's log analysis and monitoring activities (SIEM/IDS/UEBA correlation, anomaly detection on access attempts, alarms, security system activation) can surface the discovery technique once it runs via observable indicators, enabling incident response, but this is limited to logged events and does not address all discovery methods (e.g., cloud API calls or unmonitored commands).
- T1518.002detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, file access/deletion, security system activation, and especially log analysis + correlation (SIEM/UEBA/threat intel) to surface anomalous behavior and indicators of compromise such as backup software discovery commands or processes.
- T1518.002responds — A.8.15's log analysis and monitoring of events (including system activities, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation) can surface the discovery commands or backup-software enumeration once they occur, enabling incident response; this is only a slice of the technique because the control is silent on containment/eradication steps and many discovery artifacts fall outside its prescribed event list.
- T1525detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of configuration changes, privilege use, file access/deletions, and security system events, which surfaces many (but not all) indicators of an internal image being implanted or modified in a registry.
- T1526detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, unusual activity (including via SIEM, UEBA, threat intel, and correlation of events such as access attempts, privilege use, configuration changes, and security system activation), which surfaces cloud service enumeration after initial access as an information security event.
- T1526responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification directly support responding to discovery once underway by surfacing the enumeration activity as an indicator of compromise for containment and investigation.
- T1528detects — A.8.15 mandates logging of access attempts, privilege use, configuration changes, identity creation/modification, alarms, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces token theft (especially post-compromise API calls, OAuth grants, or IMDS requests) as security events or indicators of compromise.
- T1528responds — A.8.15 requires log analysis and correlation (including of access attempts, privilege use, alarms, and anomalous behaviour) to identify suspected incidents such as probing or unauthorized access that can surface token theft once underway, feeding the incident management process, but does not itself contain or eradicate the adversary action.
- T1529detects — A.8.15 explicitly requires logging, analysis, and monitoring of events including system activities, privilege use, configuration changes, security system activation/deactivation, and anomalous behaviour via SIEM/UEBA/correlation to identify incidents or indicators of compromise; this surfaces T1529 (shutdown/reboot commands, privilege acquisition, or post-impact use) in most cases once executed.
- T1530detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of access logs (including successful/rejected resource access, privilege use, configuration changes), and identification of indicators of compromise such as probing or unauthorized access to protected resources, which surfaces T1530 when it triggers detectable logging events.
- T1530prevents — A.8.15 mandates logging of access attempts (successful/rejected), privilege use, configuration changes, and anomalous behaviour analysis (including via SIEM/UEBA/threat intel), which can surface misconfigurations or credential abuse leading to T1530 before the data is taken; this constrains some but not most vectors (e.g. public buckets, leaked creds from non-log sources, or direct API access without triggering logged events).
- T1530responds — A.8.15's log analysis and incident identification (e.g. anomalous access, alarms, configuration changes) plus linkage to 5.25 incident management enables response once T1530 data access is underway, but only for logged/observable cases rather than all stealthy or misconfig-driven exfiltration.
- T1531detects — A.8.15 explicitly requires logging of account-related events (creation/modification/deletion of identities, privilege use, access attempts, configuration changes) plus analysis to surface anomalous behaviour and indicators of compromise, which directly detects T1531 actions such as account deletion, locking or credential changes.
- T1531responds — A.8.15 requires log analysis and correlation (including of account changes, privilege use, identity creation/deletion, and access attempts) to identify suspected incidents for further investigation under the incident management process; this surfaces and enables response to T1531 once the account manipulation has occurred, but does not itself contain or eradicate it.
- T1534detects — A.8.15 mandates logging, protection, and analysis of events (including access attempts, privilege use, configuration changes, anomalous behaviour via SIEM/UEBA/correlation, and indicators of compromise) that directly surface internal spearphishing campaigns once they are underway.
- T1534responds — A.8.15's log analysis, correlation, anomaly detection (UEBA/SIEM/IDS), and explicit tie to feeding the incident management process (5.25) let responders contain/eradicate an ongoing internal spearphishing campaign once it is underway; it is not the primary response mechanism and does not address every vector (e.g. physical-device compromise or chat-app lures outside monitored logs).
- T1535detects — A.8.15's log analysis, correlation, UEBA, threat intel, and specific monitoring (including of successful/unsuccessful access attempts, configuration changes, privilege use, and anomalous behavior) can surface creation of resources in unused regions as an indicator of compromise, but only where those regions fall inside the organization's defined monitoring scope and logging policy; the control itself sets that scope rather than mandating universal coverage of all possible cloud regions.
- T1537detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/threat intel, correlation of events (including successful access, configuration changes, privilege use, file access/deletion, and backups), and identification of indicators of compromise, which surfaces T1537's internal cloud transfers, API calls, SAS links, or backup creation to another account as anomalous.
- T1537responds — A.8.15's log analysis, anomaly detection, correlation, and explicit tie to feeding the incident management process (5.25) let responders know an internal cloud transfer has occurred once it is underway, but the control only surfaces the event and does not itself contain or eradicate it.
- T1538detects — A.8.15 explicitly requires logging of access attempts, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces an adversary using stolen credentials in a cloud dashboard as an information security event or indicator of compromise.
- T1539detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection on access attempts, DNS, physical logs, and correlation to surface indicators of compromise including session-cookie theft vectors such as malware, JS injection, and anomalous authenticated behavior.
- T1539prevents — A.8.15 mandates logging of access attempts, privilege use, configuration changes, and anomalous behaviour plus protected immutable logs and analysis that can surface cookie theft (e.g. malware, JS injection, or anomalous auth), thereby stopping many realisations of T1539; it leaves the actual theft vectors (browser memory scraping, MitM proxies, local malware) untouched.
- T1539responds — A.8.15 requires log analysis and correlation (including of access attempts, alarms, and anomalous behaviour) to identify suspected incidents such as probing or malware, which feeds the incident management process (5.25) that performs containment/eradication once the cookie-theft event is underway; this is a genuine but minority slice because the clause stops at detection/analysis and does not itself contain or eradicate.
- T1542detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including boot-time security system activation/deactivation and configuration changes), and physical monitoring to surface indicators of compromise such as firmware tampering that could be logged at the pre-OS layer or via correlated events.
- T1542.001detects — A.8.15 requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and explicit review of physical monitoring logs plus correlation to identify incidents like probing; this surfaces some firmware modification (e.g. via boot-time events or anomalous system activity) but leaves the bulk of stealthy BIOS/UEFI overwrites (especially pre-boot or on network devices) outside typical event logging scope.
- T1542.002detects — A.8.15 requires log analysis and monitoring (including of system activities, configuration changes, privilege use, security system activation, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface indicators of component firmware modification after the fact, but this is a minority slice because the technique executes outside the OS with no guaranteed host-visible events or logs.
- T1542.002responds — A.8.15's log analysis and monitoring activities (including correlation, anomaly detection via SIEM/IDS/UEBA, and review of access/configuration changes) can surface indicators of component firmware modification once underway as part of incident identification, but this is a minority slice given the technique's execution outside the OS and typical evasion of host-based logging.
- T1542.003detects — A.8.15 requires log analysis and monitoring (including of system activities, configuration changes, privilege use, boot-related events where logged, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface indicators of a bootkit after the fact; it does not guarantee detection of pre-OS modifications that may produce no usable logs.
- T1542.004detects — A.8.15 explicitly requires logging of system configuration changes, privilege use, boot-time security system activation/deactivation, and log analysis (with SIEM/IDS/UEBA/threat intel) that can surface anomalous firmware/boot behavior as an indicator of compromise; this is genuine detection coverage for the technique but only a slice because ROMMONkit is a low-level, hard-to-observe persistence mechanism on network devices that may evade standard event sources and correlation.
- T1542.004responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, suspected incidents (including probing or configuration changes), and support investigation; this surfaces a ROMMONkit once the device restarts and logs the upgrade/reboot, but the technique's persistence is already realised and its boot-time nature limits what logs can be generated or analysed before impact.
- T1542.005detects — A.8.15 requires log analysis and monitoring (including of configuration changes, privilege use, system activities, network connections to malicious servers, and anomalous behaviour via SIEM/UEBA/correlation) that can surface indicators of a malicious TFTP server or unauthorized boot image, but this is limited to observable post-boot events on covered systems and does not guarantee detection of the configuration manipulation or netboot itself.
- T1543detects — Creation or modification of system services and processes is captured in configuration-change and privilege-use logs, exposing persistence mechanisms.
- T1543responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. anomalous service changes, privilege use, config alterations) for further investigation under incident management (5.25), which is the core of `responds`; it is only partial because the clause stops at identification/analysis and does not itself perform containment or eradication.
- T1543.001detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, file accesses, identity creation/modification/deletion, and anomalous behaviour via log analysis (SIEM/UEBA/threat intel/correlation), which surfaces the .plist placement, launchd loading, and login-time execution of a Launch Agent as an indicator of compromise.
- T1543.001responds — A.8.15's log analysis and monitoring activities (SIEM/IDS/UEBA correlation, anomalous behaviour detection, review of access attempts and system changes) can surface indicators of a running Launch Agent persistence technique once it has executed at login, but this is only a slice of the full technique surface (e.g. plist creation/modification itself is not guaranteed to be caught without specific rules).
- T1543.002detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, service/system activations, file accesses and anomalous behaviour, then mandates analysis (SIEM/UEBA/rules/threat intel/correlation) that surfaces indicators of a new or modified systemd service as an information security event
- T1543.002prevents — A.8.15 mandates logging of configuration changes, privilege use, system activities, and file accesses (including in /etc/systemd/system and related paths), which surfaces the creation or modification of a malicious .service file or generator; this constrains the persistence technique by enabling detection and response before it fully succeeds, but does not stop the adversary from creating or altering the unit file itself.
- T1543.002responds — A.8.15 requires log analysis and correlation (including of configuration changes, privilege use, service activation/deactivation, and anomalous behaviour) to identify suspected incidents once underway for further investigation under incident management; this surfaces and supports response to the technique but does not contain or eradicate it.
- T1543.003detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, service-related events (via alarms, utility/app use, and identity changes), plus SIEM/IDS-driven analysis, UEBA, and correlation to surface anomalous behavior and indicators of compromise such as new or modified Windows services.
- T1543.003responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification directly support responding to a realized T1543.003 service creation/modification once it has executed, but the clause stops at detection/analysis and hands off to 5.25 incident management rather than performing containment/eradication itself
- T1543.004detects — A.8.15 explicitly requires logging of system configuration changes, privilege use, file access/deletion, security system activation, and anomalous behaviour via log analysis (SIEM/UEBA/threat intel/correlation), which surfaces the plist creation, modification, or hijacking of a Launch Daemon as an indicator of compromise.
- T1543.004responds — A.8.15's log analysis and monitoring activities (SIEM/IDS correlation, anomalous behaviour detection, review of system changes/privilege use/access attempts) can surface a running Launch Daemon once it has executed at startup, enabling incident response; this is only a slice because the control is silent on containment/eradication steps and many Launch Daemon artifacts (plist edits, pre-login execution) occur before or outside routine log review.
- T1543.005detects — A.8.15 explicitly requires logging, protection, and analysis of events including system activities, privilege use, configuration changes, daemon/service starts, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces T1543.005 activity on container hosts; the remainder is activity on unmonitored or non-logged container platforms.
- T1543.005responds — A.8.15's log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomaly detection, correlation of events including privilege use, config changes, and service activations) can surface container-service modifications once they occur as indicators of compromise, enabling response; this is limited to what is logged and analyzed rather than direct containment/eradication of the technique.
- T1546detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of logs (including access attempts, privilege use, config changes, and security system events), and identification of suspected incidents, which surfaces T1546 triggers and their execution artifacts after they run.
- T1546responds — A.8.15 requires log analysis and correlation (including of access attempts, privilege use, config changes, alarms, and security system activation) to identify suspected incidents for further investigation under the incident management process; this surfaces and acts on T1546 once the triggered execution has already run and produced observable events, but only for the subset of triggers that generate detectable logs rather than all mechanisms or the creation/modification step itself.
- T1546.001detects — A.8.15 explicitly requires log analysis and monitoring of events including changes to system configuration, use of privileges, file access/deletion, alarms, and anomalous behaviour via SIEM/UEBA/correlation to identify indicators of compromise such as registry changes that realize T1546.001; this surfaces the technique after it runs but does not cover all instances (e.g. non-logged changes or pre-analysis gaps).
- T1546.002detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM/IDS rules, anomalous behaviour detection, and correlation of events such as privilege use, configuration changes, and application execution) that can surface screensaver-based persistence after it is set or runs, but this is scoped by what the organization chooses to log/monitor and does not guarantee coverage of this specific registry-manipulation or inactivity-triggered technique.
- T1546.002responds — A.8.15's log analysis and monitoring explicitly surface anomalous behaviour and suspected incidents (including via UEBA, SIEM, IDS, and correlation of access/configuration/use-of-privileges events), which can detect a screensaver persistence change once it has occurred and is executing, enabling response; this is not the control's primary purpose and does not contain/eradicate the technique itself.
- T1546.003detects — A.8.15 explicitly requires logging of events including successful/rejected access attempts, privilege use, system configuration changes, identity creation/modification/deletion, and anomalous behaviour via log analysis (SIEM/UEBA/IDS rules, correlation, threat intel); these directly surface WMI event subscriptions used for persistence/privilege escalation (e.g. via login, uptime, or config events), with the bounded remainder being stealthy or non-logged subscriptions outside monitored scope.
- T1546.003prevents — A.8.15 mandates logging of privilege use, system configuration changes, and security system activation/deactivation (including relevant WMI events), plus protected analysis to surface anomalies, which can stop many but not all WMI event subscriptions from being planted or persisting undetected.
- T1546.003responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including via SIEM/IDS/UEBA correlation), which can surface a running WMI event subscription once it triggers, but does not contain, eradicate or act on the adversary once underway.
- T1546.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including shell activity, privilege use, configuration changes, and file access), and identification of indicators of compromise such as suspicious commands or modifications, which surfaces T1546.004 post-execution on Linux/macOS systems.
- T1546.004responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and explicit tie to incident management (5.25) directly enable containment/eradication once the shell-triggered malicious command runs and is observed in events.
- T1546.005detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including via SIEM/IDS/UEBA rules and correlation), which can surface trap-based persistence when it triggers observable events, but the control's scope is limited to what is explicitly logged/analyzed per the organization's policy and does not guarantee coverage of trap registration or interrupt signals themselves.
- T1546.006detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of events (including process/file changes, privilege use, and system activities), and identification of indicators of compromise, which can surface LC_LOAD_DYLIB modifications on monitored macOS systems; however, the control's scope is set by organizational policy and does not mandate coverage of this specific low-level Mach-O binary tampering technique.
- T1546.007detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, configuration changes, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces the registry writes, netsh.exe invocations, and resulting DLL execution as security events or indicators of compromise.
- T1546.007responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/IDS/UEBA on events like privilege use, config changes, and system activities) enable response once the Netsh Helper DLL persistence technique has executed and produced observable artifacts.
- T1546.008detects — A.8.15 explicitly requires logging and analysis of events including successful/rejected access attempts, privilege use, configuration changes, alarms from access control/IDS, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the binary replacement, registry modification, or unexpected SYSTEM-level execution at the logon screen that characterises T1546.008; the named remainder is in-memory or non-logged variants that evade the listed event types.
- T1546.008responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/UEBA/IDS rules on access attempts, privilege use, config changes, alarms) surface the technique once it has executed at logon or via RDP, enabling response; the named remainder is pre-login or stealthy replacement that evades the listed event types.
- T1546.009detects — A.8.15 explicitly requires logging of system activities, privilege use, process creation events, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces AppCert DLL abuse as it triggers ubiquitous process-creation APIs and produces observable registry/process anomalies.
- T1546.009responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification directly surface the technique once it runs (e.g. via registry changes, privilege-use events, process-creation anomalies), enabling response under 5.25; mostly because physical/log-protection slices and incomplete coverage of every possible trigger leave a bounded remainder.
- T1546.010detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, process-start events, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces AppInit_DLLs abuse as a persistence or privilege-escalation indicator after it occurs.
- T1546.010responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification directly support responding to (containing/eradicating) an in-progress AppInit DLL persistence/elevation event once it triggers observable API/registry/activity patterns.
- T1546.011detects — A.8.15 explicitly requires logging and analysis of events including use of privileges, system configuration changes, alarms from access control/IDS, anomalous behaviour via SIEM/UEBA/threat intel, and correlation of logs (including physical), which surfaces application shimming as a persistence/elevation technique in most realistic cases.
- T1546.011responds — A.8.15's log analysis, anomaly detection, SIEM/IDS/UEBA correlation, and explicit tie to identifying suspected incidents for the incident management process (5.25) directly enable response once the shim-based persistence/elevation technique is underway.
- T1546.012detects — A.8.15 explicitly requires logging, analysis, and monitoring of events including successful/rejected access attempts, privilege use, system configuration changes, alarms from access control/IDS, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces IFEO registry abuse, debugger hijacks, and privilege-escalation/persistence activity as security events or indicators of compromise.
- T1546.012responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification directly support responding to (containing/eradicating) an in-progress IFEO-triggered persistence or defense-impairment event once it generates observable logs.
- T1546.013detects — A.8.15 explicitly requires logging of privilege use, system activities, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the profile modification and its triggered execution as an indicator of compromise.
- T1546.014detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules, correlation of events (including system startup, authentication, privilege use, and configuration changes), and identification of indicators of compromise or suspicious activity that can surface emond rule abuse after it occurs.
- T1546.015detects — A.8.15 explicitly requires logging of registry changes, privilege use, system configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces COM hijacking (a Registry-tampering persistence technique) after it occurs; the named remainder is stealthy or non-logged hijacks that evade the monitored event set.
- T1546.015responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification directly surface COM hijacking artifacts (registry changes, unexpected COM loads, anomalous execution) once the persistence is active, enabling response; mostly because physical logs and some third-party service logs sit outside the primary coverage.
- T1546.016detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, successful/rejected access attempts, and anomalous behaviour via log analysis (SIEM/UEBA/IDS rules, correlation, threat intel), which surfaces installer-script execution with elevated rights or post-install actions as indicators of compromise.
- T1546.016responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification explicitly surface and feed into the incident management process (5.25) once the installer-script execution has begun, which is the core of `responds`.
- T1546.017detects — A.8.15 explicitly requires log analysis, SIEM/IDS rule-based detection of exceptions, UEBA for anomalous behaviour, correlation of logs (including system config changes, privilege use, file access/deletion, and security system activation), and identification of suspected incidents such as probing; these surface udev rule abuse after the fact as anomalous activity, but only where the relevant events are both logged and fall inside the organisation's chosen monitoring scope.
- T1546.018detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, file accesses (including in application/script contexts), and log analysis with SIEM/UEBA/threat-intel correlation to surface anomalous behaviour and indicators of compromise; this catches Python startup-hook execution in most monitored environments, with the bounded remainder being unmonitored or non-logged Python invocations.
- T1547detects — A.8.15 explicitly requires logging of boot/logon-related events (successful/rejected access attempts, privilege use, configuration changes, identity creation/modification), synchronized time sources, and log analysis with UEBA/SIEM/IDS rules, trend analysis, and correlation to surface anomalous autostart behavior or indicators of compromise.
- T1547.001detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, file accesses/deletions, and alarms, plus analysis with SIEM/UEBA/rules/threat intel to surface anomalous behavior and indicators of compromise such as persistence mechanisms; this directly surfaces T1547.001 activity on Windows, with the bounded remainder being stealthy or non-logged variants (e.g., very early boot or fully masqueraded entries outside monitored events).
- T1547.001responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and explicit tie-in to identifying suspected incidents for the incident management process (5.25) directly enacts the `responds` verb once the persistence technique has executed and produced observable events.
- T1547.002detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, successful/rejected access attempts, and log analysis (with SIEM/UEBA/IDS rules, anomaly detection, and correlation) that surfaces LSA/registry autostart abuse at boot as anomalous behavior or an indicator of compromise.
- T1547.003detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, service activation/deactivation, and log analysis (including SIEM/IDS/UEBA rules, anomalous behaviour, and correlation) that surfaces time-provider registration and boot-time DLL loading as an indicator of compromise.
- T1547.003prevents — A.8.15 mandates logging of configuration changes, privilege use, system activities and alarms, which would surface the admin-level registry edit that registers a malicious time-provider DLL; this constrains the technique from completing undetected on systems under the logging regime, but the control only records rather than blocks the registration or boot-time load itself.
- T1547.003responds — A.8.15's log analysis and monitoring explicitly surface anomalous behaviour, privilege use, configuration changes, and security system events that can represent the registration and boot-time execution of a malicious time-provider DLL, enabling incident response once underway.
- T1547.004detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, system configuration changes, identity creation/modification/deletion, and log analysis (with SIEM/UEBA/correlation) that surfaces anomalous behavior and indicators of compromise such as malicious Winlogon registry modifications at logon time.
- T1547.004responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification explicitly surface Winlogon abuse (registry changes, unexpected DLL loads at logon) once the technique has run, feeding the incident response process.
- T1547.005detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, successful/rejected access attempts, and anomalous behaviour via SIEM/UEBA/IDS correlation plus physical logs, which surfaces SSP Registry modifications and LSA DLL loads as indicators of compromise.
- T1547.005responds — A.8.15's log analysis and monitoring explicitly surface anomalous behaviour, privilege use, configuration changes and indicators of compromise (including via SIEM/UEBA/correlation), which can detect SSP Registry abuse once it has occurred and feed the incident-handling process, but does not itself contain or eradicate the running SSP in LSA.
- T1547.006detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including privilege use, system changes, security system activation, and log tampering), and identification of indicators of compromise such as malware or probing, which surfaces LKM/kext rootkit behavior on Linux/macOS after it runs.
- T1547.006responds — A.8.15's log analysis, anomaly detection, correlation, and explicit tie to incident identification/investigation (5.25) surface a running kernel-module rootkit once its effects (tampering, hidden activity, privilege use) appear in logs, which is the core of `responds`; it is only partial because many LKM features are designed to evade or disable logging itself, and the control has no containment/eradication mechanism.
- T1547.007detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and security events (including changes to system configuration, use of privileges, and file access/deletion), which surfaces plist modifications for persistence on macOS; however, it is only a slice because the control's scope is set by organisational policy and does not mandate coverage of this specific low-level macOS ByHost plist technique.
- T1547.007responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of login/restart events, privilege-use and configuration-change logs) can surface the plist modification or the resulting malicious reopen-on-login as an indicator once the technique has run, but this is a minority slice of the persistence technique rather than its bulk.
- T1547.008detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, security system activation/deactivation, and anomalous behaviour via SIEM/IDS/UEBA/correlation, which surfaces LSASS driver tampering as a detectable indicator of persistence; the remainder is stealthy in-memory or pre-boot driver loads outside standard event sources.
- T1547.008responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification directly surface LSASS driver tampering once it has run (as a configuration change, privilege use, system activity or anomalous behaviour), feeding the incident response process; the named remainder is stealthy driver loads that produce no observable event.
- T1547.009detects — A.8.15 explicitly requires logging and analysis of events including successful/rejected access attempts, privilege use, configuration changes, file access/deletion, startup-related system activities, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces shortcut modifications used for persistence on Windows.
- T1547.010detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, successful/rejected access attempts, and anomalous behaviour via SIEM/UEBA/IDS correlation plus physical logs, which surfaces the boot-time DLL load or Registry modification under SYSTEM context as an indicator of compromise.
- T1547.010responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification directly surface the boot-time DLL load and privilege-escalation behavior once it occurs, feeding the incident-handling process that contains and eradicates it.
- T1547.012detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, service activation/deactivation, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the registry writes, spoolsv.exe restart, and elevated-DLL load that constitute this technique.
- T1547.012responds — A.8.15's log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomaly detection, correlation of events including privilege use, service changes, and alarms) can surface the anomalous boot-time DLL load or spoolsv behavior once the technique has executed, enabling incident response.
- T1547.013detects — A.8.15 explicitly requires log analysis and monitoring of events including successful/unsuccessful access attempts, configuration changes, use of privileges, file access/deletion, and anomalous behaviour via SIEM/UEBA/correlation to identify indicators of compromise such as persistence mechanisms; this surfaces XDG autostart abuse in logs but only where the relevant events are both generated and fall inside the scoped analysis (a slice, not a bounded remainder).
- T1547.013responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/UEBA rules on autostart file changes, privilege use, or anomalous login-time execution) directly supports responding to the technique once it has run and the persistence is active.
- T1547.014detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, system configuration changes, identity creation/modification, and log analysis (with SIEM/UEBA/threat intel) that surfaces anomalous registry or login-time execution; this covers the T1547.014 technique in flight or post-execution with a bounded remainder for stealthy or non-logged variants.
- T1547.014responds — A.8.15 requires log analysis and monitoring (including of configuration changes, privilege use, system activities, alarms, and anomalous behaviour via SIEM/UEBA/correlation) to identify suspected incidents such as this persistence technique once it has run, then feeds them into incident management (5.25) for response.
- T1547.015detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, system configuration changes, application execution, and log analysis (with SIEM/UEBA/threat intel) that surfaces anomalous login-item behavior as an indicator of compromise or incident.
- T1547.015responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of login-related events) can surface the addition or execution of a malicious login item once it has run at user login, enabling incident response; this is a genuine but minority slice of the technique's full scope (creation via AppleScript/Native API, persistence via launchd/shared lists, privilege escalation).
- T1548detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/rules, correlation of events (including privilege use, access attempts, config changes, and security system activation), and identification of suspected incidents, which surfaces most T1548 abuse of elevation mechanisms after the fact.
- T1548.001detects — A.8.15 explicitly requires logging and analysis of privilege use, system access attempts, configuration changes, file accesses/deletions, and anomalous behaviour via SIEM/UEBA/correlation to surface indicators of compromise, which directly catches both setting of setuid/setgid bits (chmod, permission changes) and their subsequent abuse on Linux/macOS.
- T1548.002detects — A.8.15 explicitly requires logging of privilege use, successful/rejected access attempts, system configuration changes, alarms from access control systems, and log analysis (with SIEM/IDS/UEBA rules, anomalous behaviour detection, and correlation) that surfaces UAC bypass indicators such as unexpected elevation, auto-elevation via eventvwr.exe, or injection into trusted processes.
- T1548.002responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (including privilege-related events such as use of privileges, access attempts, and anomalous behaviour) and subject them to further investigation as part of incident management, which matches the `responds` verb once the bypass technique is underway; the extent is only partial because the control is scoped to what is logged/analyzed per policy rather than guaranteeing containment or eradication of every UAC bypass method.
- T1548.003detects — A.8.15 explicitly requires logging of privilege use, successful/rejected access attempts, configuration changes (including to sudoers), and log analysis with SIEM/UEBA/IDS rules to surface anomalous behaviour and indicators of compromise such as sudo caching abuse or tty_tickets tampering; the bounded remainder is in-memory or non-logged sudo actions outside the monitored events.
- T1548.003responds — A.8.15 explicitly requires logging of privilege use, successful/rejected access attempts, configuration changes (including to sudoers), and alarms from access-control systems, then mandates analysis to surface anomalous behaviour and suspected incidents for further investigation under the incident-management process.
- T1548.004detects — A.8.15 explicitly requires logging of privilege use, successful/rejected access attempts, system configuration changes, and anomalous behaviour via log analysis (SIEM/UEBA/threat intel), which surfaces the API call, credential prompt, or post-escalation artifacts on macOS; it is a slice because the control's scope is set by the organization's topic-specific policy and does not mandate instrumentation of every possible macOS process or world-writable file load.
- T1548.004responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of access/privilege/use events) can surface the technique once it has begun running (e.g. unexpected privilege-use or configuration-change events), which is exactly what `responds` names, but only a minority slice of the technique's stealthy or masqueraded executions is guaranteed to be caught.
- T1548.005detects — A.8.15 explicitly requires logging of privilege use, access attempts, configuration changes, identity creation/modification, and log analysis (with SIEM/UEBA/threat intel) to identify anomalous behaviour and indicators of compromise, which surfaces most T1548.005 abuse of temporary elevation paths; the named remainder is stealthy impersonation cases where logs do not clarify the activity (per the technique note).
- T1548.005prevents — A.8.15 mandates logging of privilege use, access attempts, configuration changes, and identity modifications plus protected immutable analysis that can surface misconfigurations enabling temporary elevation; this constrains the technique in environments where detection leads to preemptive correction, but does not stop the permission structures or requests themselves from existing or being abused.
- T1548.005responds — A.8.15 requires log analysis and correlation (including of privilege use, access attempts, configuration changes, and alarms) to identify suspected incidents for further investigation under the incident management process, which is the core of `responds` once the technique is underway; partial because the control only surfaces the event and hands it off rather than performing containment or eradication itself.
- T1548.006detects — A.8.15 explicitly requires log analysis and monitoring of events (including privilege use, configuration changes, access attempts, and anomalous behaviour via SIEM/UEBA/correlation) that can surface TCC database manipulation or inherited elevated permissions after the fact, but this is scoped by what the organization chooses to log/monitor and does not guarantee coverage of macOS-specific TCC.db changes or SIP-disabled scenarios.
- T1550detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, identity creation/modification, and log analysis (with SIEM/UEBA/threat intel) to identify anomalous behaviour and indicators of compromise such as stolen alternate auth material (e.g. tickets/hashes/tokens) used for lateral movement.
- T1550responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. anomalous behaviour, indicators of compromise) and feed them into the incident management process (5.25); this surfaces and enables response to T1550 once the technique is underway, but only for observable instances and without containing/eradication itself.
- T1550.001detects — A.8.15 explicitly requires logging of access attempts, privilege use, configuration changes, identity creation/modification, and anomalous behaviour via SIEM/UEBA/threat-intel analysis plus correlation, which surfaces stolen-token abuse that appears in logs as legitimate-looking API activity; the named remainder is stealthy or non-logged token use that evades the prescribed events and analysis.
- T1550.001responds — A.8.15 requires log analysis, anomaly detection via SIEM/UEBA/IDS correlation, and feeding suspected incidents into the incident management process (5.25), which directly enacts containment/eradication once token abuse is underway.
- T1550.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of access attempts/privilege use/configuration changes, and identification of indicators of compromise, which surfaces PtH lateral movement after the fact in monitored environments.
- T1550.002responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/UEBA rules on access attempts, privilege use, and configuration changes) surface PtH once underway for further investigation under 5.25, but this is scoped to observable events rather than all PtH variants or the full lateral movement chain.
- T1550.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including successful/rejected access, privilege use, system changes), and identification of indicators of compromise such as probing or anomalous authentication patterns that would surface PtT lateral movement after the fact.
- T1550.003responds — A.8.15's log analysis, correlation, and identification of suspected incidents (including anomalous access and privilege use) enable response once PtT lateral movement is underway, but this is only a slice of the full incident response workflow (containment/eradication) owned by 5.25/5.26.
- T1550.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including successful access, privilege use, configuration changes, and physical events), and identification of indicators of compromise such as probing or malware, which surfaces use of a stolen session cookie once the adversary authenticates and acts.
- T1550.004responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, suspected incidents (e.g. probing or malware activity) and trigger further investigation under incident management, which directly enacts the `responds` verb once the cookie-theft technique is underway.
- T1552detects — A.8.15 requires log analysis (with SIEM/UEBA/threat intel/correlation) and specific monitoring of access attempts, configuration changes, privilege use, file access/deletion, alarms, and anomalous behaviour, which surfaces the search activity and indicators of credential theft on covered systems.
- T1552.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including file-access, configuration changes, privilege use, and container/deployment logs), and identification of indicators of compromise such as probing or malware that surfaces credential-search activity.
- T1552.002detects — A.8.15 explicitly requires log analysis (with SIEM/UEBA/rules/threat intel/correlation) and monitoring of access attempts, privilege use, configuration changes, and anomalous behaviour to surface indicators of compromise such as registry queries for credentials.
- T1552.002responds — A.8.15's log analysis and monitoring explicitly surface anomalous activity, indicators of compromise, and suspected incidents (including probing or credential-related access), enabling response once the Registry search technique is underway; it does not contain/eradicate the actor or artifact itself.
- T1552.003detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including via UEBA, SIEM, and correlation of events such as command execution or file access), which can surface use of the history file or related suspicious commands, but does not mandate coverage of this specific artifact or technique.
- T1552.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of logs (including successful/rejected access, privilege use, file access/deletion, and physical events), and identification of suspected incidents such as probing; this surfaces the search/export activity when it generates observable events, but only for the subset of T1552.004 actions that trigger logged events rather than silent file-system searches or offline passphrase attacks.
- T1552.005detects — A.8.15 mandates logging of access attempts, privilege use, configuration changes, alarms, and anomalous behaviour plus explicit SIEM/IDS/UEBA correlation that surfaces queries to the metadata API (or SSRF to it) as indicators of compromise.
- T1552.006detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, threat intelligence, and correlation of logs (including successful/failed access, configuration changes, privilege use, and file access on SYSVOL) to surface anomalous behaviour and indicators of compromise such as enumeration of XML files or GPP credential access.
- T1552.007detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation, and review of access attempts/DNS/physical logs to surface indicators of compromise such as credential-gathering API calls in container environments.
- T1552.008detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of events such as access attempts, privilege use, configuration changes, and application transactions that would surface credential sharing or extraction in chat services.
- T1552.008responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and explicit tie to incident identification/investigation (5.25) act on the technique once underway to contain/eradicate credential harvesting from chat services.
- T1553detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, configuration changes, privilege use, alarms, and security system activation/deactivation to identify indicators of compromise and suspected incidents; this surfaces many T1553 methods (e.g. registry/file permission mods, cert abuse) but not all variants or platforms uniformly, and detection depends on what the organization chooses to log/analyze.
- T1553.001detects — A.8.15 explicitly requires log analysis and monitoring of events (including access attempts, configuration changes, privilege use, alarms from access-control systems, and anomalous behaviour via SIEM/IDS/UEBA) to identify indicators of compromise such as probing or malware-like activity; this surfaces Gatekeeper bypass attempts when they trigger observable events, but many bypass vectors (e.g. USB/cURL/no-quarantine-flag, first-launch-only checks, or stealthy file-attribute edits) produce no logged event at all.
- T1553.002detects — A.8.15 requires log analysis and monitoring (including of system activities, privilege use, configuration changes, alarms, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface code-signing certificate misuse or suspicious signed binaries post-execution, but this is scoped by what the organization chooses to log/analyze and does not inherently cover all signing events or pre-execution certificate acquisition.
- T1553.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules, correlation, and review of access attempts/changes/privileges to surface indicators of compromise; this can catch the registry modifications, DLL loads, or anomalous signature-validation behaviour that result from SIP/trust-provider hijacking, but only where those events fall inside the chosen logging scope and analysis rules — the control does not mandate instrumentation of every possible hijack vector.
- T1553.003responds — A.8.15's log analysis and monitoring explicitly surface anomalous behaviour, indicators of compromise, and suspected incidents (including probing or tampering that could manifest in logs of system changes, privilege use, or security system activity), enabling response once the hijacking technique is underway; it does not itself contain or eradicate.
- T1553.004detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, threat intelligence, and correlation of events (including privilege use, config changes, system activities, and anomalous behaviour) to identify indicators of compromise such as root-certificate installation; this surfaces the technique on monitored systems but is scoped by what the organization chooses to log/monitor and does not guarantee detection of every installation vector or platform.
- T1553.005detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including via SIEM/IDS/UEBA rules, DNS checks, and correlation), which can surface MOTW-bypass activity when it triggers observable events such as suspicious file access, privilege use, or malware-like behaviour, but the control does not mandate detection of the specific technique itself and many bypasses (e.g. silent local execution of untagged containers) produce no distinct loggable event.
- T1553.006detects — A.8.15 explicitly requires log analysis and monitoring of events (including privilege use, configuration changes, security system activation/deactivation, and anomalous behaviour via SIEM/UEBA/IDS rules) that would surface many of the policy-modification commands, registry changes, and reboot artifacts described in T1553.006; it stops short of full coverage because the technique can also occur via kernel-memory alteration that may evade standard logging.
- T1554detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of events including binary changes, privilege use, configuration changes, and file access/deletion to surface indicators of compromise such as modified host binaries.
- T1554responds — A.8.15's log analysis and monitoring for anomalous behaviour, indicators of compromise, and suspected incidents (including via SIEM/UEBA/IDS correlation) can surface a binary modification once it triggers observable events such as file changes, privilege use, or execution anomalies, enabling response under the linked incident management process.
- T1555detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts (including to protected resources) to surface indicators of compromise such as credential access from password stores.
- T1555.001detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection on access attempts/privilege use/configuration changes, and correlation of logs (including physical) to surface indicators of compromise such as credential access; this catches T1555.001 when it triggers observable events, but many in-memory or direct file reads of Keychain can be silent or require specific monitoring not mandated by the clause.
- T1555.002detects — A.8.15 explicitly requires log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomalous behaviour detection, correlation of logs including successful/failed access and privilege use) that can surface indicators of a privileged process-memory read, but the control's scope is event logging rather than direct memory-access or process-injection telemetry, leaving a large slice of the technique unseen.
- T1555.003detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, correlation, and review of access attempts, privilege use, configuration changes, and process activity that surface browser credential theft (file reads of Login Data, SQL queries, memory searches, or related anomalies) in most cases.
- T1555.004detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, correlation of access/use-of-privilege/system events, and identification of indicators of compromise, which surfaces the enumeration, file reads, API abuse, backup extraction, and password-recovery actions described in T1555.004; the bounded remainder is fully stealthy in-memory or non-logged credential-manager access.
- T1555.004responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification explicitly surface credential-dumping activity (e.g. vaultcmd.exe, CredEnumerateA, file reads of .vcrd/.vpol) once underway, feeding the incident management process.
- T1555.005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and monitoring of access attempts, privilege use, configuration changes, and security system events, which surfaces password manager credential extraction or brute-force attempts in memory, files, or logs.
- T1555.006detects — A.8.15 explicitly requires logging of privilege use, successful/rejected access attempts, system activities, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the high-privileged access or API calls (get-secret-value, az key vault secret show, etc.) that realise T1555.006; the named remainder is stealthy or non-audited retrievals outside the chosen log scope.
- T1555.006responds — A.8.15 requires log analysis (including SIEM/IDS/UEBA rules, anomaly detection, correlation, and review of access attempts) to identify suspected incidents such as probing or privilege abuse that would surface T1555.006 in flight, then feeds them into the incident management process (5.25) for response.
- T1556detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including privilege use, config changes, access attempts, and security system activation), and identification of suspected incidents such as probing or malware that commonly accompany authentication process modification.
- T1556responds — A.8.15's log analysis, anomaly detection, correlation, and identification of suspected incidents (e.g. via SIEM/IDS/UEBA) directly supports responding to T1556 once the modification is underway by surfacing it for containment and eradication.
- T1556.001detects — A.8.15 explicitly requires logging of privilege use, system access attempts, configuration changes, security system activation, and log analysis (with SIEM/UEBA/IDS rules, anomalous behaviour detection, and correlation) that surfaces domain controller patching of LSASS as an indicator of compromise.
- T1556.001responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/IDS/UEBA rules on access attempts, privilege use, config changes, or alarms) surface the authentication bypass once it runs and triggers observable events, feeding into the incident management process for response.
- T1556.002detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, and correlation of events (including successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour) to surface indicators of compromise such as a malicious password filter DLL registering or receiving plaintext credentials.
- T1556.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/rules, correlation of events (including successful/rejected access, privilege use, configuration changes, and security system activation), and identification of indicators of compromise such as probing or malware, which surfaces PAM modifications or anomalous authentication behavior on Linux/macOS systems.
- T1556.003responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/UEBA/IDS rules on access attempts, config changes, privilege use, and alarms) surface PAM modifications once they trigger observable events, enabling response; this is bounded by stealthy patches that produce no detectable log events.
- T1556.004detects — A.8.15 requires log analysis and monitoring (including of system activities, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface indicators of a backdoored network device image or its use, but this is post-compromise detection of effects rather than guaranteed discovery of the image patch itself, and many network device events fall outside standard logging scope.
- T1556.005detects — A.8.15 explicitly requires logging of privilege use, configuration changes, identity creation/modification, and anomalous behaviour via SIEM/UEBA/threat-intelligence analysis, which surfaces the setting of AllowReversiblePasswordEncryption (a privileged config change) and the resulting credential artefacts.
- T1556.006detects — A.8.15 explicitly requires logging of privilege use, configuration changes, successful/rejected access attempts, security system activation/deactivation, and log analysis (with SIEM/IDS/UEBA rules, anomaly detection, and correlation) that surfaces MFA modifications or bypasses as indicators of compromise or anomalous behaviour.
- T1556.007detects — A.8.15 explicitly requires logging of access attempts, privilege use, configuration changes, identity creation/modification, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the on-prem/cloud modifications, DLL injections, config edits, and new PTA agent registrations described in T1556.007; the remainder is stealth modifications that evade the chosen log sources or analysis rules.
- T1556.007responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and identification of suspected incidents (e.g. probing or malware) directly supports containment/eradication once the backdoor modification or credential-harvesting is underway.
- T1556.008detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes and logon events, plus analysis (SIEM/UEBA/rules) that surfaces anomalous credential-related activity, directly enabling detection of the malicious DLL registration and NPLogonNotify behavior on Windows systems.
- T1556.008prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes, and identity creation/modification plus protected immutable analysis; this surfaces the Registry-based registration and anomalous logon-notify behavior on targeted systems (servers/DCs) but does not stop the malicious DLL from being registered or receiving credentials.
- T1556.008responds — A.8.15 explicitly requires log analysis (including SIEM/IDS/UEBA rules, anomaly detection, correlation of successful/failed access and privilege-use events) to identify suspected incidents such as credential capture during logon, then feeds them into the incident management process (5.25) for response once underway.
- T1556.009detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts/config changes/privilege use to surface indicators of compromise such as policy modifications, but this is scoped by what the organization chooses to log and monitor rather than mandating coverage of conditional-access policy changes on all identity-provider platforms.
- T1557detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, DNS log review for malicious C2, correlation of events, and identification of suspected incidents (including probing of firewalls), which surfaces many AiTM behaviors after they occur; it is limited to a slice because it depends on what is actually logged, has no view of purely passive ARP/LLMNR poisoning without observable events, and stops at detection rather than response.
- T1557responds — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and identification of suspected incidents (e.g. probing or malware) directly supports responding to an in-progress AiTM once underway, but only for detectable network/behavioral slices rather than the full technique (e.g. ARP poisoning or downgrade attacks may evade logging).
- T1557.001detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, DNS log checks for malicious C2, correlation of events, and identification of indicators like probing or anomalous activity, which surfaces LLMNR/NBT-NS/mDNS poisoning and relay attempts in network traffic.
- T1557.001prevents — A.8.15 mandates logging of network/resource access attempts, configuration changes, privilege use, alarms from access-control/IDS systems, and analysis of anomalous behaviour (including DNS logs and UEBA), which can surface LLMNR/NBT-NS/mDNS spoofing in flight or block some relay paths via timely detection and response; however, it does not stop the initial poisoning response or hash capture itself.
- T1557.001responds — A.8.15 requires log analysis (including correlation, SIEM/IDS rules, UEBA, and review of access attempts/DNS logs) plus identification of suspected incidents for further investigation under the incident management process; this surfaces and acts on the poisoning/relay once underway but does not contain/eradicate it or its artifacts.
- T1557.002detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, DNS log checks for malicious C2, correlation of network events, and review of access attempts to surface anomalous behaviour and indicators of compromise; ARP cache poisoning produces observable network anomalies (gratuitous replies, duplicate MACs, unexpected traffic redirection) that fall inside those detection mechanisms.
- T1557.002responds — A.8.15's log analysis, correlation, and identification of anomalous events (e.g. via SIEM/IDS rules, UEBA, or physical monitoring) can surface ARP poisoning once underway as an indicator of compromise for incident response, but this is limited to detection feeding response rather than containment/eradication itself.
- T1557.003detects — A.8.15 explicitly requires logging, analysis, and monitoring of network events, anomalous behavior, DNS queries to malicious servers, and correlation that surfaces rogue DHCP offers, unauthorized configuration changes, and AiTM indicators.
- T1557.003responds — A.8.15's log analysis and monitoring activities (SIEM/IDS/UEBA correlation, anomalous behaviour detection, review of access attempts and DNS logs) can surface DHCP spoofing once underway as an information security event or indicator of compromise, which then feeds incident handling; this is genuine but only a slice because the control is silent on containment/eradication steps that `responds` also requires and because many DHCP-spoofing artifacts sit outside the events it mandates logging.
- T1557.004detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, unusual network activity (including DNS, usage reports, physical logs, and correlation), which surfaces evil twin Wi-Fi deception and its follow-on effects after the fact; it is not full because the control's scope is set by organisational requirements and does not mandate instrumentation that would reliably catch all rogue-AP or probe-response tricks on every network segment or device.
- T1558detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, identity creation/modification/deletion, and log analysis (with SIEM/UEBA/threat intel/correlation) that surfaces anomalous Kerberos activity such as unusual ticket requests or klist usage as indicators of compromise.
- T1558responds — A.8.15's log analysis, anomaly detection, and incident identification (e.g. via SIEM/UEBA/correlation) surface Kerberos ticket theft or forgery once underway as an information security event, enabling response under 5.25; it does not contain/eradicate the actor or technique itself.
- T1558.001detects — A.8.15 explicitly requires logging, protection, and analysis of events including privilege use, system access attempts, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation to identify indicators of compromise such as forged Kerberos tickets or KDC interactions.
- T1558.001responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. anomalous behavior, probing) for further investigation under incident management, which responds once a golden ticket is used; it does not contain/eradicate the technique itself.
- T1558.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of logs (including successful/rejected access, privilege use, configuration changes), and identification of suspected incidents such as probing — which surfaces silver ticket use after the fact even without KDC interaction.
- T1558.002responds — A.8.15 requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and feeding suspected incidents (e.g. probing or anomalous access) into the incident management process (5.25), which directly enacts the containment/eradication steps that `responds` names once the silver-ticket technique is underway; the remainder is that silver tickets need no KDC interaction and produce no central authentication events, so many forgeries stay outside the logged events the clause actually analyzes.
- T1558.003detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, and alarms, plus log analysis (SIEM/UEBA/rules/threat intel) and monitoring of anomalous behaviour to identify indicators of compromise such as Kerberoasting ticket requests or unusual SPN activity.
- T1558.003responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification explicitly surface Kerberoasting indicators (e.g. anomalous TGS requests, unusual SPN activity, or brute-force patterns on captured hashes) once the technique is underway, feeding directly into the 5.25 incident response process.
- T1558.004detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, and security-system alarms plus SIEM/IDS/UEBA-driven analysis to surface anomalous behaviour and indicators of compromise; AS-REP roasting produces observable Kerberos AS-REQ/AS-REP traffic patterns, LDAP enumeration, and cracking artefacts that fall inside those logged and analysed events.
- T1558.005detects — A.8.15 explicitly requires log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of access/privilege/use events, DNS and physical logs) that surface the collection and use of stolen ccache tickets as indicators of compromise or anomalous activity.
- T1558.005responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification explicitly surface the theft of ccache files (or related Kerberos anomalies) once underway, feeding directly into the incident management process for containment/eradication.
- T1559detects — A.8.15 explicitly requires logging, protection, and analysis of events including system activities, privilege use, process/resource access attempts, configuration changes, alarms from IDS/AV, anomalous behaviour via SIEM/UEBA/correlation, and indicators of compromise, which surfaces most IPC abuse (local or remote) once it generates observable events.
- T1559responds — A.8.15's log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomaly detection, correlation) can surface IPC abuse as an information security event or indicator of compromise once underway, feeding into incident response, but this is only a slice of the broad technique rather than containment/eradication itself.
- T1559.001detects — A.8.15 explicitly requires logging of system activities, privilege use, process/resource access, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces COM abuse (DLL/EXE method calls, scheduled-task objects, etc.) as events or indicators of compromise; the named remainder is in-process COM activity that produces no observable log entry.
- T1559.001responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification directly support responding to (containing/eradication steps for) in-flight COM abuse once it generates observable events, with the named remainder being stealthy or non-logged COM executions.
- T1559.002detects — A.8.15 explicitly requires logging of system activities, privilege use, application transactions, configuration changes, and anomalous behaviour via SIEM/UEBA/IDS correlation plus specific monitoring of successful/failed resource access and DNS, which surfaces DDE-based command execution (including Office/CSV poisoning and DCOM invocation) as an information security event or indicator of compromise.
- T1559.002responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. anomalous behaviour, indicators of compromise) and feed them into the incident management process (5.25); this surfaces and enables response to realized DDE execution but does not itself contain or eradicate it.
- T1559.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules, correlation, and review of access attempts, privilege use, configuration changes, and security system events, which surfaces XPC abuse (esp. when it triggers observable indicators like anomalous root-level execution or privilege-escalation patterns); partial because the control's scope is set by what the organization chooses to log/monitor and many XPC service abuses (esp. those using proper client validation or not triggering logged events) remain invisible.
- T1559.003responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS correlation, and identification of suspected incidents (e.g. probing or malware) enable response once the XPC abuse technique is underway, but this is limited to detection feeding incident handling rather than direct containment/eradication of the local code execution.
- T1560detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and correlation of events (including file access, utility use, and outbound connections) that surface the pre-exfil compression/encryption step on monitored systems.
- T1560.001detects — A.8.15 explicitly requires logging and analysis of events including use of utilities/applications, file access/deletion, privilege use, and anomalous behaviour via SIEM/UEBA/threat intel/correlation, which surfaces the execution of archiving utilities (tar/zip/7-Zip/etc.) as indicators of compromise before or during exfil.
- T1560.002detects — A.8.15 requires log analysis and monitoring (including SIEM/IDS/UEBA rules, anomalous behaviour detection, and correlation of events such as file access/deletion, privilege use, and network activity) that can surface the use of archival libraries or resulting compressed/encrypted blobs when they produce observable artifacts, but this is limited to chosen monitoring scope and does not guarantee detection of in-process library calls themselves.
- T1560.003detects — A.8.15 mandates log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access/use patterns that can surface custom archival (e.g. unusual process behavior, file creation, or outbound prep activity) when it falls inside the monitored scope, but does not guarantee coverage of custom in-memory or non-logged implementations.
- T1561detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, file access/deletion, security system activation, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces disk-wipe indicators (MBR overwrites, mass file deletion, erase commands) after they occur.
- T1561recovers — A.8.15 requires determining logging purposes, recording events (incl. configuration changes, privilege use, file access/deletion), protecting logs against tampering/overwriting, and performing log analysis/correlation to identify incidents; this supports post-wipe recovery investigations and evidence gathering but does not itself restore wiped disk data or system availability.
- T1561responds — A.8.15's log analysis, correlation, anomaly detection (including physical logs), and explicit tie to feeding the incident management process (5.25) enable containment/eradication once disk-wipe activity is underway, with the named remainder being fully completed wipes that have already destroyed recoverability before response begins.
- T1561.001detects — A.8.15 explicitly requires logging, analysis, and monitoring of events including system activities, configuration changes, privilege use, file access/deletion, security system activation, and anomalous behaviour via SIEM/UEBA/correlation to identify incidents such as malware or destructive activity; this surfaces disk-wipe indicators post-execution across the named platforms with only bounded remainder for fully stealthed or pre-log events.
- T1561.001recovers — A.8.15 requires determining logging purposes, recording events (including system activities, configuration changes, privilege use, file access/deletion), protecting logs from tampering or loss, and performing analysis/correlation to identify incidents such as destructive malware; this directly supports post-wipe recovery investigations and evidence gathering per its stated purpose, though it does not itself restore wiped data (that is A.8.13).
- T1561.001responds — A.8.15's log analysis, correlation, and identification of suspected incidents (e.g. malware or probing) feeds the incident management process (5.25) for response once disk-wipe is underway, but does not itself contain or eradicate the active technique.
- T1561.002detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, file accesses/deletions, security system alarms, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces disk-structure-wipe indicators (MBR/partition overwrites, format commands, mass propagation) after they occur.
- T1561.002recovers — A.8.15 requires determining logging purposes, recording events (including system changes, privilege use, configuration changes, and security system activation/deactivation), protecting logs for integrity, and performing analysis to identify incidents; this supports post-wipe recovery investigations and evidence collection per its purpose and 5.28/5.25 references, but does not itself restore wiped disk structures or system availability.
- T1561.002responds — A.8.15's log analysis, correlation, and identification of suspected incidents (including anomalous behavior that can precede or accompany destructive wipers) enables response actions once the technique is underway, but the control itself performs only detection/analysis and does not contain or eradicate.
- T1563detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, session-related events (log-on/off, identity changes), and mandates analysis with SIEM/UEBA/correlation/threat intel to surface anomalous behaviour and indicators of compromise, which directly detects hijacking of preexisting remote sessions (SSH/RDP/telnet) after the fact.
- T1563responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (including anomalous remote access patterns) and feed them into the incident management process (5.25) for response, but does not itself perform containment or eradication of an active hijacking.
- T1563.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including successful/rejected access, privilege use, configuration changes, and physical logs), and identification of indicators of compromise such as probing or anomalous behaviour, which surfaces SSH session hijacking in flight or post-facto on Linux/macOS systems.
- T1563.001prevents — A.8.15 mandates logging of access attempts, privilege use, configuration changes, and security system activation/deactivation plus protected analysis that can surface anomalous SSH-agent or session behavior before lateral movement succeeds, but does not stop the hijack itself (especially root-level agent/socket compromise) and the control's focus is recording/review rather than enforcement.
- T1563.001responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (including anomalous behaviour and probing) for further investigation under incident management (5.25), which matches the `responds` verb once the hijack is underway; extent is partial because it surfaces the event for response but does not itself contain or eradicate the active session.
- T1563.002detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, system activities, alarms from access control systems, and log analysis (with SIEM/IDS/UEBA rules, anomalous behaviour detection, and correlation) that surfaces RDP session hijacking indicators such as tscon.exe use or unexpected session takeovers.
- T1563.002prevents — A.8.15 mandates logging of access attempts, privilege use, session events and configuration changes plus protected immutable analysis that can surface RDP hijacking (tscon.exe use, anomalous sessions) before or during execution, but does not stop the native technique from running.
- T1563.002responds — A.8.15 requires log analysis, anomaly detection, correlation, and identification of suspected incidents (including probing or unauthorized access patterns that can surface RDP hijacking), then feeds them into the incident management process (5.25) for response once the technique is underway.
- T1564detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts, configuration changes, privilege use, and physical events to surface hidden artifacts or isolated regions as indicators of compromise.
- T1564responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. probing, anomalous behavior, indicators of compromise) for further investigation under incident management (5.25), which is the core of `responds`; it does not contain/eradicate the hiding technique itself and coverage is limited to detectable artifacts rather than isolated regions or all evasion methods.
- T1564.001detects — A.8.15 explicitly requires log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of access and file events, physical logs) that surface hidden-file usage as an IOC when it triggers logged events, but the control does not mandate instrumentation that would reveal the hiding act itself when no other logged action occurs.
- T1564.001responds — A.8.15's log analysis and monitoring activities (including correlation, UEBA, anomalous behaviour detection, and review of access attempts) can surface the use of hidden files as an indicator once the technique has run, but this is a minority slice of the technique's evasion surface rather than containment/eradication of an in-progress incident.
- T1564.002detects — A.8.15 explicitly requires logging of user/account creation/modification/deletion, privilege use, system configuration changes, and log analysis (with SIEM/UEBA/correlation) that surfaces anomalous hidden-user artifacts after they are created.
- T1564.002responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/UEBA rules on account changes, privilege use, config changes, and login events) surface hidden-user creation or modification once it has occurred, enabling response as part of incident handling.
- T1564.003detects — A.8.15 explicitly requires log analysis and monitoring of events (including successful/unsuccessful access attempts, privilege use, system configuration changes, alarms, and anomalous behaviour via SIEM/UEBA/correlation) that can surface hidden-window techniques when they produce observable artifacts, but many variants (e.g. off-screen registry edits, plist flags, or hidden desktops with no user-visible events) leave no log trail and are outside the clause's scope.
- T1564.004detects — A.8.15 explicitly requires log analysis and monitoring for anomalous behaviour, indicators of compromise, and correlation of events (including file access/deletion and system activities), which can surface NTFS attribute abuse when it triggers observable artifacts, but this is limited to what is logged/analyzed and does not guarantee detection of stealthy or non-logged uses.
- T1564.004responds — A.8.15's log analysis and monitoring activities (including correlation, UEBA, anomaly detection on file access/deletion, and incident identification) can surface NTFS attribute abuse once it has occurred as part of an underway event, but this is limited to observable side-effects rather than the hidden data itself.
- T1564.005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of logs (including file access/deletion, system changes, and physical events), and identification of indicators of compromise or suspicious activity that can surface hidden file system usage when it produces observable events.
- T1564.005responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and incident identification explicitly surface hidden-file-system artifacts once present (e.g. unusual disk I/O, non-standard structures, or access patterns), feeding the incident response process; it does not contain/eradicate the adversary's VFS itself.
- T1564.006detects — A.8.15 requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and specific monitoring (e.g. DNS, access attempts, physical logs) that can surface virtualization artifacts, shared-folder activity, or anomalous VM behavior when inside monitored scope, but the technique's core evasion (hiding artifacts from tools unable to monitor inside the instance, plus hidden ESXi VMs) leaves substantial unmonitored residue.
- T1564.007detects — A.8.15 requires log analysis and monitoring for anomalous behaviour, indicators of compromise, and correlation of events (including file access, application transactions, and security system activity), which can surface VBA-stomping artifacts in Office documents when they trigger observable events, but the control does not mandate inspection of compiled p-code, module streams, or document internals where the hidden payload primarily resides.
- T1564.008detects — A.8.15 explicitly requires log analysis, SIEM/IDS rule-based detection of exceptions, UEBA for anomalous behaviour, correlation of logs (including from email systems), and identification of suspected incidents such as probing or malware; this surfaces the creation or effect of malicious email-hiding rules when they produce observable anomalies, but the control does not mandate instrumentation of mailbox-rule changes themselves and many stealthy rule variants leave no detectable log artifact.
- T1564.009detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspicious events (including via SIEM, UEBA, trend analysis, and correlation of logs from systems, applications, and physical access), which can surface resource-fork abuse when it produces observable artifacts in file activity, execution, or extended attributes; however, the control is silent on macOS-specific resource forks, does not mandate the particular sensors or commands needed to reliably catch hidden/obfuscated forks, and the technique can be crafted to avoid generating logged events.
- T1564.009responds — A.8.15's log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomalous behaviour detection, correlation of access/system events) can surface resource-fork abuse once it has executed and produced observable artifacts, but the control's scope is limited to events that generate logs and does not address the macOS-specific, file-system-level hiding technique itself.
- T1564.010detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, correlation of process-related events (including privilege use, system activities, and application transactions), and review of access attempts, which can surface many process-spoofing artifacts post-execution; however, the control is silent on in-memory PEB inspection or real-time process-memory monitoring that would catch the core overwrite technique itself.
- T1564.011detects — A.8.15 requires log analysis and monitoring (including of system activities, privilege use, process-altering events, alarms from security tools, and anomalous behaviour via SIEM/UEBA/correlation) that can surface the use of nohup, SilentlyContinue or similar commands when they appear in logs or deviate from baselines, but this is limited to observable events rather than the in-memory signal-ignoring technique itself and depends on which events an organization chooses to log/analyze.
- T1564.012detects — A.8.15 requires log analysis and monitoring (including of file access, alarms, security system activity, and anomalous behaviour via SIEM/IDS/UEBA) that can surface use of well-known AV exclusions or related discovery, but does not mandate coverage of all such artifacts or the specific technique itself.
- T1564.013detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspicious events (including via SIEM, UEBA, correlation, and review of access attempts, system activities, and physical logs), which can surface the use or effects of bind mounts as anomalous process or filesystem behaviour; however, the control does not mandate instrumentation that would reliably observe the mount command or kernel-level overlay itself, leaving a large slice of stealthy instances undetected.
- T1564.014detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including via SIEM, UEBA, trend/pattern analysis, and correlation of events such as file access, privilege use, and security system activity), which can surface xattr abuse when it triggers observable events, but does not mandate inspection of xattrs themselves and leaves many stealthy uses (no visible file change, no logged command) undetected.
- T1565detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access/configuration/privilege events to surface indicators of compromise including data manipulation that alters integrity or hides activity.
- T1565responds — A.8.15 requires log analysis and correlation to identify suspected incidents (including anomalous data changes that could be T1565) and routes them to incident management (5.25) for response, but the control itself stops at detection/analysis rather than performing containment or eradication.
- T1565.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and correlation of events (including file access/deletion, configuration changes, privilege use, and alarms) to surface indicators of compromise such as data manipulation at rest.
- T1565.001responds — A.8.15's log analysis and monitoring explicitly surface anomalous behaviour, indicators of compromise, and suspected incidents (including data manipulation that threatens integrity), feeding into incident management (5.25) for response once the technique is underway; this is genuine but only a slice because the control stops at detection/analysis and does not itself perform containment or eradication.
- T1565.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of logs (including network/DNS/physical), and identification of suspected incidents such as probing or malware that would surface T1565.002 activity; the remainder is stealthy manipulations that produce no observable event.
- T1565.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation, and review of access attempts, configuration changes, privilege use, and alarms to surface indicators of compromise including runtime manipulations that affect data integrity or business processes.
- T1566detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including access attempts, configuration changes, privilege use, and physical logs), and identification of suspected incidents such as malware or probing, which surfaces most phishing delivery and follow-on behaviors after they occur.
- T1566responds — A.8.15's log analysis and monitoring explicitly identify suspected phishing-driven incidents (e.g. malware from attachments/links, probing) for further investigation under incident management, which is the core of `responds`; it is bounded to post-delivery detection rather than containment/eradication actions themselves.
- T1566.001detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, correlation, and review of access attempts, DNS logs, and physical events to surface indicators of compromise such as malware or probing, which directly catches spearphishing attachment delivery and execution artifacts.
- T1566.001responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. malware infection from attachments) once underway for further investigation per incident management, which is the core of `responds`; partial because it surfaces the event but does not itself contain or eradicate the technique or actor.
- T1566.002detects — A.8.15 explicitly requires logging of access attempts, privilege use, configuration changes, alarms, security system activation, and anomalous behaviour via SIEM/IDS/UEBA/correlation, which surfaces spearphishing link delivery, clicks, downloads, and consent-phishing indicators as security events or IOCs.
- T1566.002responds — A.8.15 requires log analysis and correlation (including of email, access, and anomalous events) to identify suspected incidents such as probing or malware, then feeds them into the incident management process (5.25) for response; this surfaces and acts on realized spearphishing once underway but does not contain/eradicate the actor's foothold or the delivered payload itself.
- T1566.003detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM/IDS rules, anomalous behaviour detection, and correlation of events such as access attempts or unusual activity) that can surface indicators of spearphishing via service when those indicators appear in enterprise logs, but the technique occurs on third-party/non-enterprise services outside organizational visibility and control.
- T1566.003responds — A.8.15 requires log analysis and correlation (including of application, network, physical, and third-party service events) to identify suspected incidents such as probing or malware delivery, then feeds them into the incident management process (5.25) for response; this acts on the technique once underway but only after delivery and only where observable in the logged channels, leaving the social-engineering rapport-building and personal-service vectors largely unseen.
- T1566.004detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM/IDS rules, anomalous behaviour detection, and correlation of events such as access attempts or alarms) that can surface indicators of vishing-driven compromise after the call, but the control's scope is limited to system/application logs and does not address voice-channel events themselves.
- T1566.004responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (including anomalous behaviour, alarms, and indicators of compromise) and feed them into the incident management process (5.25), which is the core of `responds`; it is partial because voice phishing is primarily a social-engineering/pre-compromise technique whose key indicators often sit outside technical logs (phone calls, urgency, impersonation) and the clause's coverage is therefore a slice rather than the bulk with a bounded remainder.
- T1567detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/threat intel, correlation of events (including network activity, DNS, and outbound connections to malicious servers), and identification of indicators of compromise, which surfaces T1567 exfiltration over common web services when it deviates from baseline patterns.
- T1567responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/correlation, and explicit tie to incident identification/investigation (5.25) enable response once exfiltration is underway, but only for the detectable slice that produces observable events rather than the full technique (covert use of legitimate SSL/TLS web services may leave no distinct indicator).
- T1567.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/threat intel, correlation of logs (including network activity, DNS, and successful/failed resource access), and identification of suspected incidents such as probing or outbound connections to malicious infrastructure; this surfaces the HTTPS API calls and data exfiltration to a code repo as anomalous behavior in most cases, though coverage depends on whether the specific repo domain or patterns are in the monitored scope or threat intel.
- T1567.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/threat intel, and monitoring of outbound connections (including to cloud services) plus correlation of events to identify exfiltration as an information security incident.
- T1567.002responds — A.8.15's log analysis, anomaly detection, SIEM/IDS/UEBA correlation and explicit identification of suspected incidents (including outbound connections to malicious servers) directly enable response once exfiltration to cloud storage is underway
- T1567.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/threat intel, correlation of logs (including network activity and outbound connections to suspicious domains), and identification of suspected incidents such as probing or data exfiltration patterns, which surfaces use of text storage sites for outbound exfil on covered platforms.
- T1567.003responds — A.8.15's log analysis, correlation, anomalous-behaviour detection (including outbound connections, UEBA, SIEM/IDS rules) and incident-identification steps act on an exfiltration event once underway to surface it for containment and eradication.
- T1567.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of logs (including network, DNS, application, and physical events), and identification of suspected incidents such as probing or outbound connections to malicious servers, which surfaces webhook-based exfiltration when it produces observable events in the listed log categories.
- T1567.004responds — A.8.15 requires log analysis and correlation (including of network, application, and physical events) plus identification of suspected incidents for further investigation under the incident management process; this surfaces webhook exfiltration when it produces detectable anomalies in logs but does not itself contain or eradicate the actor once the technique is underway.
- T1568detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log review for malicious C2 connections, and correlation to identify indicators of compromise, which surfaces dynamic resolution behaviors such as unusual domain/IP patterns.
- T1568responds — A.8.15's log analysis and monitoring explicitly surface anomalous C2-related activity (DNS queries to suspicious domains, outbound connections, UEBA patterns, threat intel correlation) once the dynamic resolution technique is underway, feeding into incident response (5.25); this is genuine response support but only a slice, as the control stops at detection/analysis and does not itself contain or eradicate the running C2 channel.
- T1568.001detects — A.8.15 explicitly requires log analysis and monitoring of DNS logs to identify outbound connections to malicious C2 servers (including flux patterns via anomalous behaviour, UEBA, threat intel and correlation), which surfaces the technique in flight.
- T1568.001prevents — A.8.15 requires logging of DNS-related events, successful/rejected access attempts, network activity, and analysis (including DNS logs for outbound connections to malicious servers) which can surface and thereby block the use of fast-flux domains before C2 succeeds, but does not stop adversaries from registering/rotating the flux itself.
- T1568.001responds — A.8.15's log analysis, correlation, SIEM/IDS/UEBA rules, and explicit DNS-log review for outbound C2 directly surface and trigger response to fast-flux indicators once the technique is running.
- T1568.002detects — A.8.15 explicitly requires log analysis, anomaly detection via UEBA/SIEM/IDS rules, DNS log examination for outbound C2 connections to malicious domains, and correlation to identify indicators of compromise such as probing or malware callbacks, which surfaces DGA-driven C2 traffic in practice.
- T1568.002responds — A.8.15's log analysis, correlation, anomaly detection (e.g. DNS logs to malicious C2), and incident identification explicitly surface and feed into response for realized DGA C2 events once underway, but this is only one slice of full incident response (containment/eradication lives in 5.25/5.26).
- T1568.003detects — A.8.15 explicitly requires log analysis and monitoring (including DNS logs for outbound connections to malicious C2, correlation, UEBA, and anomaly detection) that surfaces the unusual DNS responses and calculated C2 traffic this technique produces.
- T1568.003responds — A.8.15's log analysis, correlation, SIEM/IDS/UEBA rules, and incident identification explicitly surface anomalous DNS/C2 patterns (including calculated ports or outbound connections to malicious infrastructure) once the technique is underway, feeding the incident management process.
- T1569detects — Logging service-creation events and the execution of system utilities reveals attempts to abuse legitimate services for code execution.
- T1569responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation) can surface service-abuse events once underway as indicators of compromise, enabling response, but this is only a slice of the technique's execution surface rather than containment/eradication itself.
- T1569.001detects — A.8.15 explicitly requires logging of system activities, privilege use, process launches, configuration changes and anomalous behaviour, then mandates analysis (SIEM/UEBA/rules) that surfaces launchctl abuse as an indicator of compromise; the named remainder is events on unmonitored macOS endpoints or before logging is enabled.
- T1569.001responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including via SIEM/IDS/UEBA rules and correlation), which surfaces launchctl abuse once underway for further investigation under incident management, but does not itself contain or eradicate it.
- T1569.002detects — A.8.15 explicitly requires logging and analysis of service-related events (use of privileges, system activities, configuration changes, alarms from access control/IDS, anomalous behaviour via SIEM/UEBA/correlation) that surface abuse of the service control manager, with the named remainder being events outside the chosen monitoring scope or before analysis occurs.
- T1569.002prevents — A.8.15 mandates logging of privilege use, system configuration changes, service-related events and anomalous behaviour, which can prevent some abuse of the service control manager by increasing the chance of detection before or during execution; however, it does not stop the technique from running.
- T1569.002responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/IDS rules, UEBA, and review of access/system changes) surface service execution as a suspected incident for further handling, but this is after the fact with no containment/eradication act asserted by the control itself
- T1569.003detects — A.8.15 explicitly requires logging, analysis, and monitoring of system activities, privilege use, configuration changes, service activation/deactivation, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces systemctl abuse when it triggers those logged events.
- T1569.003prevents — A.8.15's logging of privilege use, system activities, configuration changes, and security system activation (plus analysis for anomalous behaviour) can surface or deter some systemctl abuse patterns but does not stop the technique from executing.
- T1569.003responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including privilege use, system configuration changes, and service activations), which surfaces an in-progress systemctl abuse for containment under the incident management process, but does not itself perform containment/eradication.
- T1570detects — A.8.15 explicitly requires logging, protection, and analysis of events including file access/deletion, privilege use, system activities, network connections, anomalous behaviour via SIEM/UEBA/correlation, and indicators of compromise, which surfaces lateral tool/file transfers once they occur.
- T1570responds — A.8.15's log analysis, anomaly detection, and incident identification (e.g. via SIEM/UEBA/correlation of file-access and privilege-use events) enable response once lateral tool transfer is underway, but this is only a slice of the full technique (many transfers use native tools or protocols that may not trigger logged anomalies).
- T1571detects — A.8.15 explicitly requires logging of network addresses/protocols, access attempts, configuration changes, and anomalous behaviour via log analysis (SIEM/UEBA/threat intel/correlation), which surfaces non-standard port usage as an indicator of compromise; the named remainder is fully encrypted/obfuscated C2 that evades the logging facility itself.
- T1571responds — A.8.15's log analysis and monitoring explicitly surface anomalous network activity (including non-standard ports via DNS, firewall, UEBA and correlation), feeding incident identification and response per 5.25, but this is detection feeding response rather than the containment/eradication act itself.
- T1572detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, DNS log examination for malicious C2, correlation of events, and identification of probing or indicators of compromise, which surfaces protocol tunneling (including SSH, DoH) when it generates observable network or system events.
- T1572prevents — A.8.15 mandates logging of access attempts, configuration changes, privilege use, network activity and alarms plus analysis to surface anomalous behaviour; this can prevent some tunneling (e.g. by catching unusual SSH/DoH flows or privilege escalation for tunnel setup) but leaves the bulk of encapsulation, blending and routing techniques untouched.
- T1572responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including network anomalies, probing, or C2 patterns that protocol tunneling produces), then subjects them to further investigation as part of incident handling; this is the core of `responds` once the technique is underway, but remains partial because the clause stops at detection/analysis/hand-off and does not itself perform containment or eradication.
- T1573detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log review for malicious C2, and correlation to identify indicators of compromise, which surfaces encrypted C2 channels when they produce observable events or patterns.
- T1573responds — A.8.15's log analysis and monitoring explicitly surface anomalous C2 patterns (e.g. outbound to malicious servers, UEBA, correlation) once the encrypted channel is in use, enabling incident response, but this is only a slice of the technique's full scope (reverse engineering of keys, non-network indicators, non-anomalous encrypted flows).
- T1573.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and correlation of events (including network activity, outbound connections to malicious infrastructure, and physical logs) to surface indicators of compromise such as concealed C2 traffic.
- T1573.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including network activity and outbound connections to malicious infrastructure), and identification of indicators of compromise, which surfaces C2 traffic using asymmetric crypto in the listed events and monitoring activities.
- T1573.002responds — A.8.15's log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomaly detection, correlation) can surface C2 traffic that uses asymmetric crypto once it is already underway, enabling response and investigation per the incident management cross-reference.
- T1574detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including privilege use, config changes, process/file activity, and alarms), and identification of indicators of compromise or incidents, which surfaces most hijack-execution-flow techniques once they produce observable artifacts.
- T1574responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (e.g. via SIEM, UEBA, correlating logs of access attempts, privilege use, configuration changes), which surfaces T1574 once it has begun running; this is the act `responds` names, but only a slice because the clause stops at identification/analysis and hands off to incident management rather than performing containment/eradication itself.
- T1574.001detects — A.8.15 explicitly requires logging of security-relevant events (privilege use, config changes, system access attempts, alarms from IDS/AV, anomalous behaviour via SIEM/UEBA/correlation) plus dedicated log analysis to surface indicators of compromise; this directly surfaces most DLL sideloading/hijacking/substitution behaviours once they execute, though some fully in-memory or pre-execution variants remain outside log visibility.
- T1574.001responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification directly support responding to a realized DLL-hijacking event once underway, but the clause stops at detection/analysis and hands off to 5.25 incident handling for containment/eradication.
- T1574.004detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, threat intelligence, and monitoring of access attempts, configuration changes, privilege use, alarms, and anomalous behaviour to surface indicators of compromise; this surfaces dylib hijacking when it triggers observable events (e.g. unexpected library loads, privilege use, or anomalous process behaviour) but leaves a large remainder of stealthy cases that inherit the legitimate process and produce no distinct log signature.
- T1574.004responds — A.8.15 requires log analysis and monitoring (including of system activities, privilege use, file access, alarms, security system activation, and anomalous behaviour via SIEM/IDS/UEBA) to identify suspected incidents such as malware infection once underway, which directly supports containment and eradication under the linked incident management process (5.25).
- T1574.005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules, correlation of events (including privilege use, file access/deletion, system changes, and alarms), and identification of indicators of compromise such as malware or probing, which surfaces the file-permission abuse and unauthorized binary replacement once it triggers logged events.
- T1574.005responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification directly surface the hijack once the malicious binary executes or the installer runs, enabling the incident response process (5.25) to contain and eradicate it.
- T1574.006detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules, correlation, and monitoring of access attempts, privilege use, configuration changes, and security system events, which can surface dynamic linker hijacking (e.g. LD_PRELOAD anomalies or hooked execve behavior) as an indicator of compromise; it is a genuine but minority slice because the control's scope is set by what the organization chooses to log/analyze and does not mandate coverage of all linker environment variable or library preload artifacts.
- T1574.007detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of events (including privilege use, configuration changes, process execution via command interpreters, and file access), and identification of indicators of compromise such as probing or malware, which surfaces most PATH hijacking attempts once they trigger observable events.
- T1574.008detects — A.8.15 explicitly requires logging and analysis of events including successful/rejected access attempts, privilege use, system configuration changes, application transactions, anomalous behaviour via SIEM/UEBA/threat intel, and correlation of logs (including physical), which surfaces search-order hijacking artifacts such as unexpected executables, anomalous process execution, and indicators of compromise.
- T1574.008responds — A.8.15's log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomalous behaviour detection, correlation of access/system events) can surface indicators once a hijacked executable runs and triggers logged events, enabling response; this is a genuine but minority slice of the technique's execution surface.
- T1574.009detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, configuration changes, file access/deletion, alarms, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces the registry/service/shortcut writes, anomalous executable placement, and resulting execution that realise T1574.009; the named remainder is events outside the chosen logging scope or before analysis occurs.
- T1574.010detects — A.8.15 explicitly requires logging and analysis of events including use of privileges, system configuration changes, file access/deletion, alarms from access control, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the hijacking of service binaries as an indicator of compromise after it occurs.
- T1574.010responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of access/configuration/use-of-privileges events) can surface the hijack once the malicious binary runs and triggers observable indicators, which is the core of `responds`; it does not contain/eradicate the already-executing payload or the permission flaw itself.
- T1574.011detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules, correlation, and review of access attempts/changes/privileges to surface indicators of compromise such as unauthorized Registry modifications that enable this technique.
- T1574.011responds — A.8.15's log analysis and monitoring explicitly surface anomalous activity, privilege use, configuration changes, and suspected incidents (including those from registry tampering that trigger service starts or alarms), enabling response once the technique is underway; partial because it depends on the specific events being logged/analyzed and does not itself contain or eradicate.
- T1574.012detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, threat intelligence, and correlation of events (including process, privilege use, system configuration changes, and anomalous behaviour) to surface indicators of compromise such as a malicious COR_PROFILER DLL load or registry modification.
- T1574.012responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of events including privilege use, process activity and configuration changes) can surface COR_PROFILER abuse once it is underway as an indicator of compromise, but this is only a slice of the technique's possible forms (in-memory, non-registry, non-privileged) and does not itself contain or eradicate the actor's foothold.
- T1574.013detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of events (including process, system, privilege-use and application activity), and identification of indicators of compromise such as malware or probing, which surfaces the in-memory hijack when it produces observable execution, Windows messages or related artifacts under a legitimate process.
- T1574.013responds — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and incident identification explicitly feed the incident management process (5.25) that contains and eradicates an in-progress hijack once its indicators appear in logs.
- T1574.014detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of events (including process, configuration changes, privilege use, and application activity), and identification of indicators of compromise such as malware or probing, which surfaces AppDomainManager hijacking when it generates observable events.
- T1574.014responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and identification of suspected incidents (e.g. malware or probing) directly supports responding to an in-progress AppDomainManager injection once it has executed and generated observable events.
- T1578detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including config changes, privilege use, resource access, and security system activation), and identification of suspected incidents such as probing — which surfaces T1578's modifications to cloud compute infrastructure (create/delete/modify instances, VMs, snapshots) after they occur.
- T1578responds — A.8.15 requires log analysis and correlation (including of privileged use, config changes, and security system events) to identify suspected incidents for further investigation under the incident management process, which is the core of `responds`; it is only partial because the clause stops at identification/analysis and does not itself perform containment or eradication.
- T1578.001detects — A.8.15 requires log analysis and monitoring (including of configuration changes, privilege use, resource access attempts, and anomalous behaviour via SIEM/UEBA/correlation) that can surface snapshot creation as suspicious activity or an indicator of compromise, but this is scoped by what the organization chooses to log/monitor and does not guarantee detection of the technique itself.
- T1578.002detects — A.8.15 explicitly requires logging, analysis, and monitoring of events including system activities, configuration changes, privilege use, resource access, and anomalous behaviour (with SIEM/UEBA/threat intel correlation), which surfaces creation of a new cloud instance as a detectable deviation from baseline.
- T1578.003detects — A.8.15 requires log analysis, anomaly detection via SIEM/UEBA/threat intel, and correlation of events (including system activities, privilege use, configuration changes, and physical monitoring) to surface indicators of compromise such as instance deletion; this catches the technique in many IaaS environments but only where deletion events are both logged and fall inside the scoped analysis rules, leaving a large slice of unmonitored or post-deletion cloud activity unreached.
- T1578.003recovers — A.8.15 requires determining what to log (including system activities, privilege use, configuration changes, and resource access/deletion), protecting logs against deletion or overwrite, archiving for retention/evidence, and analyzing for incidents; this enables recovery of forensic evidence and correlation for post-deletion investigation in many but not all cases (e.g., fully ephemeral or unlogged instances leave no recoverable artifacts).
- T1578.003responds — A.8.15's log analysis, correlation, and identification of suspected incidents (including anomalous behavior or probing) enables response once deletion is underway or complete, but does not contain/eradicate the actor or address non-recoverable evidence loss itself.
- T1578.004detects — A.8.15's log analysis, correlation, UEBA, SIEM/IDS rules, and review of access/configuration/privilege events can surface anomalous reversion activity (e.g. snapshot restore or ephemeral reset) after it occurs, but only where those events are both logged and fall inside the chosen analysis scope; many cloud snapshot/API calls sit outside that scope or lack the required attributes.
- T1578.005detects — A.8.15 requires log analysis and monitoring (including of configuration changes, privilege use, and anomalous behaviour via SIEM/UEBA/correlation) that can surface T1578.005 modifications after they occur, but only for events that generate detectable logs within the organization's chosen scope and does not guarantee coverage of all cloud-specific quota/policy/region changes.
- T1580detects — A.8.15 explicitly requires logging of access attempts, privilege use, configuration changes, resource access, and anomalous behaviour, plus analysis (SIEM/UEBA/correlation) that surfaces cloud API calls such as DescribeInstances or ListBuckets as indicators of discovery; the named remainder is stealthy or non-audited discovery that evades the chosen log scope.
- T1580responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of access attempts and configuration changes) can surface T1580 once the discovery API calls or enumeration are underway, enabling identification as part of incident handling; it is not the primary response mechanism and coverage is limited to observable events within scoped monitoring.
- T1583detects — A.8.15 requires log analysis and monitoring (including DNS logs, UEBA, trend analysis, threat intel, and correlation) that can surface anomalous acquisition or use of infrastructure as an indicator of compromise, but this is limited to post-acquisition observable activity rather than the acquisition act itself on PRE platforms.
- T1583.001detects — A.8.15 requires log analysis and monitoring (including DNS logs, anomalous outbound connections, UEBA, threat intel correlation) that can surface adversary domain acquisition or use as an indicator of compromise, but this is limited to post-acquisition observable activity rather than the acquisition act itself on PRE platforms.
- T1583.002detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise, including checking DNS logs for outbound connections to malicious C2 servers and correlating events; this surfaces adversary setup/use of their own DNS servers for C2 in the post-compromise phase, though pre-compromise setup on PRE platform is a bounded remainder.
- T1583.003detects — A.8.15 requires log analysis and monitoring (including DNS, network connections to malicious servers, anomalous behaviour, UEBA, threat intel) that can surface adversary acquisition and use of VPS infrastructure in the PRE phase, but this is limited to observable post-acquisition activity rather than the rental transaction itself and depends on what the organization chooses to monitor.
- T1583.004detects — A.8.15 requires log analysis and monitoring (including DNS logs, anomalous outbound connections, UEBA, threat intel, and correlation) that can surface adversary acquisition and use of servers for C2, phishing, or watering-hole staging as indicators of compromise, but this is limited to observable post-acquisition network/behavioral artifacts on the defender's systems rather than the adversary's pre-compromise server acquisition itself.
- T1583.005detects — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, DNS log checks for C2, and correlation of events can surface indicators of botnet activity (e.g. outbound C2, anomalous traffic from compromised IoT/edge devices), but this is limited to observable post-compromise behavior on monitored systems and does not broadly detect the adversary's acquisition or rental of the botnet itself.
- T1583.005responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. probing, malware, botnet C2) surface an in-flight botnet technique for response under 5.25, but only after acquisition/use and without containment/eradication mechanisms.
- T1583.006detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM/IDS rules, DNS logs, trend analysis, and correlation) that can surface anomalous registration or use of web services as indicators of compromise or unusual activity, but this is scoped to post-registration events on owned systems and does not broadly detect adversary account creation on external public platforms like GitHub or Twitter.
- T1583.007detects — A.8.15 requires log analysis and monitoring (including DNS, network traffic patterns, UEBA, threat intel, and correlation) that can surface anomalous serverless C2/proxy traffic appearing as ordinary cloud provider subdomains, but this is a minority slice dependent on scope and rules rather than a broad or guaranteed finder of the infrastructure acquisition itself.
- T1583.008detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM/IDS rules, anomalous behaviour detection, DNS logs, and correlation) that can surface malvertising indicators such as suspicious ad-driven traffic or domains, but the control's scope is limited to events inside the organization's own systems and does not reach the adversary's pre-compromise ad purchase or the ad network's external evasion techniques.
- T1584detects — A.8.15 requires log analysis and monitoring (SIEM/IDS/UEBA/correlation) that surfaces anomalous behavior, indicators of compromise, and suspected incidents including probing, botnet C2, and infrastructure misuse, but only for events that reach the organization's own logged systems and networks.
- T1584.001detects — A.8.15 requires log analysis and monitoring (including DNS logs, anomalous outbound connections, UEBA, trend/pattern analysis, and correlation) that can surface domain hijacking, subdomain takeovers, or shadowing as indicators of compromise or anomalous behavior, but this is scoped by what the organization chooses to log/monitor and does not guarantee detection of all registration or DNS hijacks (especially pre-compromise or external ones).
- T1584.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, DNS log review for outbound connections to malicious C2 servers, and correlation to identify suspected incidents such as probing or malware, which surfaces post-compromise use or alteration of a compromised third-party DNS server; it is only partial because the control's scope is set by organizational requirements and does not mandate universal DNS-specific instrumentation or detection of silent pre-compromise subdomain creation.
- T1584.003detects — A.8.15 requires log analysis and monitoring (including of system access attempts, configuration changes, privilege use, network activity, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface indicators of a third-party VPS compromise, but this is scoped by what the organization logs/monitors and does not inherently cover adversary-acquired external VPSes used in PRE.
- T1584.004detects — A.8.15 requires log analysis and monitoring (SIEM/IDS/UEBA/correlation) that surfaces anomalous activity, indicators of compromise, and events such as configuration changes, privilege use, or outbound connections to malicious infrastructure, which can reveal third-party server compromise in post-exploitation or C2 scenarios; it is partial because the control's scope is limited to what the organization logs/monitors in its own environment and does not inherently detect adversary compromise of external third-party servers used in pre-compromise targeting.
- T1584.005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log checks for C2/botnet connections, and correlation to identify indicators of compromise such as probing or malware that match botnet formation and takeover.
- T1584.005responds — A.8.15's log analysis, anomaly detection (e.g. outbound C2, botnet patterns via UEBA/threat intel), and incident identification explicitly feed into the 5.25 incident management process that contains and eradicates an active botnet once underway.
- T1584.006detects — A.8.15 requires log analysis and monitoring (SIEM/UEBA/IDS correlation, anomalous behaviour review, DNS logs, physical logs) that can surface indicators of web-service compromise or abuse in expected noise, but this is scoped to what the organization logs/monitors and does not guarantee detection of pre-positioning on third-party PRE platforms.
- T1584.007detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspicious events (including outbound connections, unusual activity, and correlation), which can surface serverless compromise or its use for C2/proxying when those behaviours are logged and fall inside the analysis scope; it is not guaranteed to catch stealthy or novel serverless abuse that blends with legitimate cloud traffic.
- T1584.008detects — A.8.15 requires log analysis and monitoring (including of network appliances, configuration changes, privilege use, alarms, and anomalous outbound connections) that can surface compromise of third-party network devices or their downstream use in C2/proxy activity, but this is scoped by what the organization logs/analyzes and does not inherently cover unmanaged third-party edge devices lacking host defenses.
- T1585detects — A.8.15 requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts plus physical events that can surface creation of accounts or personas when those actions generate observable events on monitored systems or services.
- T1585.001detects — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of access and network events) can surface indicators once a cultivated social-media persona begins interacting with targets or systems, but the core PRE technique of account creation and persona development itself occurs off-organizational systems and leaves no logged events until later phases.
- T1585.002detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM rules, anomalous behaviour detection, and correlation of access/identity events) that can surface creation of accounts or related suspicious patterns, but this is scoped to organizational systems and does not inherently cover adversary-created external disposable email accounts on PRE platforms.
- T1585.003detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including unusual account activity or resource use), which can surface cloud account creation when it triggers observable events in monitored logs; this is limited to a slice because the technique occurs in external/pre-attack cloud provider environments outside organizational logging scope, with no guarantee of detection for stealthy or unmonitored creations.
- T1586detects — A.8.15 requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts and events that can surface indicators of account compromise (e.g. brute-force, anomalous logons, privilege use), but this is scoped to what the organization chooses to log/monitor and does not inherently detect pre-compromise reconnaissance, credential purchases, or third-party persona development on external services.
- T1586.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of events (including access attempts, privilege use, configuration changes, and physical logs), and identification of suspected incidents such as probing; this surfaces T1586.001 when its compromise methods (phishing, brute-force, credential use) or downstream effects produce observable logs, but the control's scope is limited to what the organization logs/monitors and does not guarantee detection of all pre-compromise reconnaissance or third-party account activity.
- T1586.002detects — A.8.15 requires log analysis and monitoring (including of access attempts, privilege use, configuration changes, anomalous behaviour via SIEM/UEBA/threat intel, and correlation) that can surface indicators of email account compromise such as suspicious logons or outbound activity, but this is scoped by what the organization chooses to log/monitor and does not inherently cover pre-compromise reconnaissance, credential purchases, or the PRE platform itself.
- T1586.003detects — A.8.15's log analysis, monitoring activities, anomaly detection via SIEM/UEBA/IDS rules, and correlation of events (including access attempts, privilege use, configuration changes, and outbound connections) can surface indicators of cloud-account compromise or its downstream use, but this is scoped to what the organization chooses to log/monitor and does not inherently cover pre-compromise reconnaissance, credential theft, or third-party cloud-provider logs.
- T1587.001detects — A.8.15's log analysis and monitoring explicitly surface indicators of compromise, anomalous behaviour and suspected incidents (including malware-related events such as probing or infections), but this is post-development/pre-targeting detection of the malware's use rather than detection of the PRE technique of developing the malware itself.
- T1587.002detects — A.8.15 requires log analysis and monitoring (including SIEM/IDS/UEBA rules, anomalous behaviour detection, and correlation of events such as privilege use, configuration changes, and security system activation) that can surface creation or use of a self-signed code-signing certificate as an indicator of compromise, but this is limited to observable post-creation events on monitored systems and does not address the PRE phase or certificate development itself.
- T1587.003detects — A.8.15 requires log analysis and monitoring (including of system activities, privilege use, configuration changes, alarms, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface creation or use of a self-signed certificate as an indicator, but this is limited to post-creation observable events on monitored systems and does not address the PRE technique's offline creation step.
- T1587.004detects — A.8.15's log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomaly detection, correlation of access/config/privilege events) can surface indicators that an exploit was developed or is in use downstream, but do not observe the adversary's pre-compromise exploit-development activity itself on PRE platforms.
- T1588detects — A.8.15 requires log analysis and monitoring to identify unusual activity, anomalous behaviour, indicators of compromise, and suspected incidents (including malware or probing), which can surface adversary acquisition of capabilities when it produces observable artifacts in the monitored environment; this is a genuine but minority slice of the pre-attack technique whose core (purchase, download, or theft) is often invisible to the organization's logs.
- T1588.001detects — A.8.15 requires log analysis and monitoring (SIEM/IDS/UEBA/threat intel/correlation) that surfaces indicators of compromise including malware-related activity, but this is scoped to post-acquisition operational use on victim systems rather than the pre-compromise acquisition activity itself on adversary infrastructure.
- T1588.002detects — A.8.15's log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomalous behaviour detection, correlation of access/use/privilege events) can surface acquisition or testing of tools when those actions produce observable logs, but the pre-compromise acquisition step itself (buy/steal/download outside monitored systems) is largely outside the logging scope.
- T1588.003detects — A.8.15 requires log analysis and monitoring (including of privilege use, configuration changes, alarms, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface acquisition or use of stolen certificates as an indicator, but this is limited to post-compromise observable events on covered systems and does not address pre-targeting purchase or third-party theft outside monitored scope.
- T1588.004detects — A.8.15 requires log analysis and monitoring (SIEM/IDS/UEBA rules, anomalous behaviour detection, DNS logs, correlation) that can surface certificate acquisition, domain hijacking or suspicious CA interactions as indicators of compromise; this is genuine but only a slice because the technique is pre-compromise, external, and often leaves no detectable log on the victim's systems until later stages.
- T1588.005detects — A.8.15 requires log analysis and monitoring (SIEM/IDS/UEBA/threat intel/correlation) that can surface indicators of exploit acquisition, forum monitoring, or related anomalous behavior as an information security event, but this is indirect, post-facto, and depends on what the organization chooses to log/analyze rather than a dedicated mechanism for the pre-attack technique itself.
- T1588.006detects — A.8.15 requires log analysis and monitoring (SIEM/IDS/UEBA rules, anomalous behaviour detection, correlation) that can surface adversary activity such as scanning vulnerability databases or targeting research systems, but only when that activity produces observable events inside the monitored scope; the pre-compromise reconnaissance itself is not instrumented by default.
- T1588.007detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including via SIEM, UEBA, threat intel, and correlation), which can surface AI-assisted reconnaissance, phishing content generation, or anomalous script/payload activity when it produces observable events in logs; it does not guarantee detection of all pre-compromise or non-logged uses of public LLMs.
- T1589detects — A.8.15 requires log analysis and monitoring (SIEM/UEBA/IDS correlation, anomalous login/access patterns, successful/rejected access attempts) that can surface T1589 indicators such as probing of auth services or unusual credential-enumeration behavior, but only after the fact and only for the subset of T1589 that touches monitored systems rather than purely external OSINT or phishing-for-info.
- T1589.001detects — A.8.15's log analysis and monitoring requirements surface anomalous credential-gathering behaviors (e.g. phishing attempts, unusual access patterns, or leaked credential indicators in logs) as potential IOCs, but this is limited to observable events within the organization's monitored scope and does not address pre-compromise external gathering like dark web purchases or site compromises.
- T1589.002detects — A.8.15 requires log analysis and monitoring (SIEM/UEBA/IDS correlation, anomalous behaviour review, DNS logs, physical logs) that can surface reconnaissance indicators such as probing of auth services or unusual API queries, but the control's scope is post-event log review rather than real-time detection of all passive OSINT or public-data harvesting on PRE platforms.
- T1589.003detects — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of access and network events) can surface reconnaissance patterns that expose employee-name gathering, but this is limited to detectable post-gathering signals on owned systems rather than the external/pre-platform OSINT activity itself.
- T1590detects — A.8.15 requires log analysis and monitoring (including DNS logs, network patterns, UEBA, SIEM/IDS rules, and correlation) that can surface anomalous reconnaissance activity such as active scanning or unusual queries indicative of T1590, but this is scoped by what the organization chooses to log/monitor and does not guarantee detection of all passive or external data-set methods on the PRE platform.
- T1590.001detects — A.8.15 requires log analysis and monitoring (including DNS logs, anomalous outbound connections, UEBA, SIEM/IDS rules, and correlation) that can surface domain reconnaissance activity such as WHOIS lookups, passive DNS queries, or probing of name servers, but this is scoped to what the organization has chosen to log/monitor and does not inherently cover all external/pre-compromise discovery methods on the PRE platform.
- T1590.002detects — A.8.15 requires log analysis and monitoring (including DNS logs for outbound connections to malicious infrastructure, correlation, UEBA, and anomaly detection) that can surface reconnaissance activity such as DNS queries or zone transfers, but this is scoped by what the organization chooses to log/monitor and does not guarantee detection of passive or external open-source DNS gathering.
- T1590.003detects — A.8.15 requires log analysis and monitoring (including correlation, UEBA, DNS logs, anomalous access patterns, and physical events) that can surface reconnaissance activity aimed at discovering network trust dependencies, but only for the subset that produces observable events inside the monitored scope rather than purely passive OSINT or pre-compromise elicitation.
- T1590.004detects — A.8.15's log analysis and monitoring activities (SIEM/IDS rules, UEBA, DNS log review for malicious C2, correlating logs from network/physical events) surface anomalous reconnaissance behaviors that can reveal network topology gathering, but this is scoped to what is logged/monitored rather than all possible collection methods (e.g. passive web searches).
- T1590.005detects — A.8.15 requires log analysis and monitoring (including DNS logs, network patterns, UEBA, SIEM/IDS rules, and correlation) that can surface anomalous activity tied to IP reconnaissance such as scanning or outbound connections, but this is scoped by what the organization chooses to log/monitor and does not systematically detect passive/public data-set gathering of IP blocks.
- T1590.006detects — A.8.15 requires log analysis and monitoring (including of alarms from access control/IDS, anomalous behaviour, DNS logs, and correlation) that can surface reconnaissance activity such as active scanning or exposed appliance details, but this is scoped to chosen events and does not guarantee detection of all T1590.006 vectors such as passive website searches or phishing for information.
- T1591detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including via correlation, UEBA, threat intel, and specific checks like DNS or physical logs), which can surface T1591 reconnaissance activity such as phishing or unusual data access patterns, but only for events that generate observable logs rather than all passive public-data gathering.
- T1591.002detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM, DNS logs, usage reports, physical logs, and correlation) that can surface anomalous reconnaissance activity such as unusual queries, phishing responses, or third-party data exposures, but this is limited to observable post-gathering events on owned systems and does not broadly detect passive open-source or elicitation methods in the PRE phase.
- T1591.003detects — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of access/DNS/physical logs) can surface reconnaissance indicators such as unusual probing, phishing responses, or anomalous access patterns that reveal business-tempo gathering, but this is limited to detectable post-compromise signals on monitored systems and does not address the bulk of passive PRE public-data or elicitation methods.
- T1591.004detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including via UEBA, SIEM, IDS, and correlation of access/identity events), which can surface reconnaissance activity that reveals roles, but the control is scoped to logged events on organizational systems and does not address external OSINT, social media, or phishing-for-information channels where much of T1591.004 occurs.
- T1592detects — A.8.15 requires log analysis and monitoring of events (including access attempts, configuration changes, alarms, and anomalous behaviour via SIEM/UEBA/correlation) that can surface T1592 indicators such as scanning, probing, or unusual user-agent patterns, but only after the fact and only for the subset of collection methods that produce observable logs rather than passive OSINT or pre-compromise exposure.
- T1592.001detects — A.8.15 requires log analysis and monitoring (including of system activities, configuration changes, privilege use, alarms, security system activation, and anomalous behaviour via SIEM/UEBA/correlation) that can surface reconnaissance for hardware details when it triggers logged events or patterns, but the control's scope is limited to post-event logs on the victim and does not address pre-compromise external sources or the PRE platform.
- T1592.002detects — A.8.15 requires log analysis and monitoring (including SIEM/IDS/UEBA correlation of events such as access attempts, configuration changes, privilege use, security system activation, and anomalous behaviour) that can surface reconnaissance activity aimed at discovering host software and defensive components, but only for the subset of T1592.002 that produces observable events inside the logged scope; passive collection from public data, metadata, or pre-compromise phishing leaves no detectable log trail.
- T1592.003detects — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of access/config/change events) can surface reconnaissance indicators that expose firmware details in logs or related data sets, but this is limited to post-exposure or internal-system slices while the technique is primarily PRE and often uses external/public sources outside logging scope.
- T1592.004detects — A.8.15 requires log analysis and monitoring (including correlation, UEBA, DNS logs, physical events, and anomaly detection) that can surface reconnaissance activity such as active scanning, phishing responses, or exposed config data in logs, but only for the subset of T1592.004 collection methods that produce observable events inside the monitored scope; many pre-compromise or external data-set methods leave no detectable log trail.
- T1593detects — A.8.15 requires log analysis and monitoring (including correlation, UEBA, threat intel, and review of access attempts/DNS logs) to identify anomalous behavior and suspected incidents, which can surface T1593 activity when it triggers observable indicators such as unusual queries or patterns, but this is limited to what is logged/analyzed and does not inherently cover all open-web searches.
- T1593.001detects — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of events including outbound connections and unusual activity) can surface indicators that a reconnaissance campaign is underway once social-media-derived information appears in other observable events, but the passive PRE social-media search itself produces no logs on the victim side and is therefore only a minority slice of the technique.
- T1593.002detects — A.8.15's log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomalous behaviour detection, DNS logs, physical logs, correlation) can surface reconnaissance indicators such as unusual search-engine-driven leaks or spillage patterns when those queries produce observable events in monitored logs, but the technique is primarily external/pre-attack and often leaves no internal log footprint.
- T1593.003detects — A.8.15 requires log analysis and monitoring (including of successful/unsuccessful access attempts, configuration changes, alarms, and anomalous behaviour via SIEM/UEBA/correlation) that can surface reconnaissance activity against public code repositories when it triggers observable events on monitored systems, but the control's scope is limited to an organization's own logs and does not inherently observe adversary searches of third-party public repositories.
- T1594detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including via web-related logs like DNS, access attempts, and physical monitoring), which can surface T1594 reconnaissance after or during its occurrence on victim web assets, but only for the monitored slice rather than the technique universally.
- T1595detects — A.8.15 explicitly requires logging, analysis, and monitoring of network events including alarms from intrusion detection, outbound connections to malicious servers, anomalous patterns, and correlation of logs to identify probing of firewalls and other indicators of active scanning reconnaissance.
- T1595responds — A.8.15 requires log analysis and monitoring (including of alarms, access attempts, network activity, IDS, and correlation) to identify probing of firewalls or other scanning indicators as suspected incidents, then subjects them to further investigation and incident response per 5.25, which is the core of `responds` once the technique is underway.
- T1595.001detects — A.8.15 explicitly requires logging, analysis, and monitoring of network events including successful/rejected access attempts, alarms from access control/IDS, outbound connections to malicious infrastructure, anomalous behaviour via SIEM/UEBA/correlation, and physical logs; this surfaces scanning of IP blocks (especially when it triggers IDS rules, firewall probes, or unusual patterns) in most cases, with the bounded remainder being entirely stealthy/pre-policy scans that produce no observable event.
- T1595.001responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. probing of firewalls) directly enable response once scanning is underway, with the named remainder being pre-attack or non-probing scans that fall outside monitored events.
- T1595.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of logs (including network, DNS, access attempts, and alarms), and identification of suspected incidents such as probing of firewalls, which directly surfaces vulnerability scanning activity on the network.
- T1595.003detects — A.8.15 explicitly requires logging, protection, and analysis of events including access attempts (successful/rejected), resource access, alarms, network activity, anomalous behaviour, and correlation against threat intel/UEBA/SIEM/IDS rules, which surfaces wordlist-driven probing and directory-enumeration attempts in flight or post-facto.
- T1595.003responds — A.8.15 requires log analysis and monitoring (including of access attempts, alarms, anomalous behaviour, and correlation) that surfaces suspected probing or scanning events once underway so they can be identified and handed to incident management (5.25) for containment/eradication; this is the core of `responds` with a named remainder of stealthy/pre-filtered scans that evade the configured rulesets.
- T1596detects — A.8.15 requires log analysis and monitoring (including DNS logs, network patterns, UEBA, threat intel correlation) that can surface anomalous reconnaissance activity such as unusual queries to open technical databases, but this is limited to observable network or system events within the monitored scope rather than directly detecting all passive/open-source searches.
- T1596.001detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, DNS log review for outbound connections to malicious infrastructure, and correlation to identify anomalous behaviour and suspected incidents; this surfaces passive DNS reconnaissance when it triggers observable patterns or misconfigs, but only for the subset of activity that reaches monitored logs rather than all external passive DNS queries.
- T1596.002detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including via DNS logs, UEBA, threat intel correlation, and outbound connections to malicious infrastructure), which can surface WHOIS-driven reconnaissance as part of broader pre-attack activity; it is not scoped specifically to public WHOIS queries themselves.
- T1596.004detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including probing), which can surface CDN reconnaissance or misconfiguration leaks when they trigger observable events in logs; this is a genuine but minority slice because most of T1596.004 is passive external search that never touches the victim's logging surface.
- T1596.005detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and information security events (including via correlation, UEBA, threat intel and specific checks such as DNS or physical logs), which can surface reconnaissance activity like database scanning when it triggers observable indicators, but the control is scoped to an organisation's own systems and does not inherently monitor or analyse public third-party scan databases themselves.
- T1597.001detects — A.8.15 requires log analysis and monitoring (including correlation, UEBA, threat intelligence use, and review of access attempts/alarms) to identify anomalous behavior and suspected incidents, which can surface adversary searches of threat-intel vendor data when those searches produce observable events in monitored logs; this is a genuine but minority slice because the technique is primarily reconnaissance performed externally/pre-compromise with no guaranteed logged footprint inside the organization's systems.
- T1598detects — A.8.15 requires log analysis and monitoring (including of access attempts, alarms, anomalous behaviour, DNS logs, UEBA, and correlation) that can surface phishing-for-information activity once it has reached the target environment, but this is scoped by what the organization chooses to log/monitor and does not inherently cover pre-delivery social engineering, spoofing, or callback channels on the PRE platform.
- T1598.001detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM/IDS rules, anomalous behaviour detection, and correlation of events such as access attempts or unusual activity) that can surface spearphishing messages or related indicators when they trigger observable logs, but this is limited to events inside the monitored scope and does not inherently cover third-party/non-enterprise services or pre-compromise social engineering lures.
- T1598.002detects — A.8.15 requires log analysis and monitoring (including SIEM/IDS/UEBA rules, anomalous behaviour detection, DNS logs, and correlation) that can surface spearphishing indicators such as suspicious attachments, unusual email patterns or outbound connections, but does not guarantee coverage of all social-engineering lures or pre-delivery reconnaissance on PRE platforms.
- T1598.003detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, correlation, and review of access attempts/DNS logs/physical events to surface indicators of compromise such as phishing-related probing or anomalous behavior, but does not guarantee detection of all delivery vectors (e.g. QR codes on mobile, tracking pixels, or BitB spoofing outside monitored scopes).
- T1598.003responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and explicit tie to identifying suspected incidents for the incident management process (5.25) directly enable containment/eradication once a spearphishing delivery or credential-harvest attempt is underway.
- T1598.004detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM/IDS rules, anomalous behaviour detection, and correlation of events such as access attempts or alarms) that can surface vishing indicators like spoofed calls, urgent pretexts, or anomalous voice-related activity when those events reach logged systems or networks, but the control is silent on voice channels themselves and most vishing occurs outside monitored digital logs.
- T1599detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of boundary-relevant events (access attempts, config changes, privilege use, security system activation, network activity) that surface perimeter device compromise and unauthorized boundary bridging.
- T1599responds — A.8.15's log analysis and monitoring of events (including alarms, configuration changes, privilege use, and anomalous behaviour) can surface indicators of a boundary device compromise once underway, feeding into incident response per 5.25, but does not itself contain or eradicate the active bridging.
- T1599.001detects — A.8.15 explicitly requires logging of configuration changes, privilege use, system activities, network addresses/protocols, and anomalous behaviour via log analysis, SIEM, UEBA, and correlation; these surface malicious NAT modifications on boundary devices as events or indicators of compromise, though some stealthy or post-patching changes may evade detection.
- T1599.001responds — A.8.15's log analysis, correlation, and monitoring activities (including alarms, configuration changes, privilege use, and anomalous behaviour via SIEM/UEBA) can surface the NAT modification as a suspected incident for response, but the control stops at identification/investigation and does not itself contain or eradicate the active technique.
- T1600detects — A.8.15 requires log analysis and monitoring (including anomalous behaviour, configuration changes, privilege use, alarms from IDS/access control, and correlation with threat intelligence) that can surface indicators of device compromise or weakening of encryption, but does not mandate coverage of network-device firmware, hardware crypto, or the specific sub-techniques, leaving a large unscoped remainder.
- T1600.001detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspicious events (including configuration changes and use of privileges), which can surface the CLI commands or image modifications that reduce key space, but only where those actions produce observable logs within the monitored scope.
- T1600.002detects — A.8.15 requires log analysis and monitoring (including of configuration changes, privilege use, system activities, alarms, and anomalous behaviour via SIEM/UEBA/correlation) that can surface the disabling of crypto hardware as an indicator of compromise, but this is scoped by what the organization chooses to log/monitor and does not guarantee coverage of network device firmware or hardware-specific events.
- T1601detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and security events (including configuration changes, privilege use, and system activities), which surfaces T1601 modifications to a device OS image when those actions produce observable loggable events; the coverage is partial because many embedded network-device modifications (especially in-memory or on unmonitored boot images) leave no log trail at all.
- T1601.001detects — A.8.15 requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and review of access/configuration/privilege events that can surface indicators of a network-device OS patch (e.g. config changes, privilege use, file modifications, or anomalous commands), but this is limited to observable events on monitored systems and does not guarantee detection of in-memory patches or stealthy bootloader-based modifications on network devices.
- T1601.002detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspicious events (including configuration changes, use of privileges, and system activities), which can surface a downgrade but only where it produces observable artifacts in the defined log scope; the technique's core act (replacing boot image on an embedded/network device) is not guaranteed to be logged or flagged.
- T1602detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, configuration changes, privilege use, and network activity that would surface an adversary querying or exfiltrating from a configuration repository.
- T1602.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules, correlation of logs (including network events and configuration changes), and identification of indicators like probing, which surfaces SNMP MIB queries as anomalous network or access activity on managed devices.
- T1602.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of configuration changes, privilege use, access attempts, and network activity that would surface a configuration dump via management protocols.
- T1606detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of events (including privilege use, configuration changes, access attempts, and identity creation/modification), and identification of indicators of compromise or suspicious activity that would surface forged web credential generation and use.
- T1606responds — A.8.15's log analysis, anomaly detection, SIEM/UEBA correlation, and incident identification explicitly surface forged-credential use once the access event occurs, enabling response under 5.25; the named remainder is purely offline forging that leaves no observable event.
- T1606.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, privilege use, configuration changes, and correlated events that surface forged-cookie authentication bypasses post-facto.
- T1606.001responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and identification of suspected incidents (e.g. probing or anomalous access) directly supports responding to a forged-cookie authentication bypass once underway.
- T1606.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation across synchronized logs (including successful/rejected access, privilege use, configuration changes, and identity creation/modification), and identification of indicators of compromise such as probing or anomalous authentication patterns that would surface forged SAML tokens used for access.
- T1606.002responds — A.8.15's log analysis, anomaly detection, correlation, and explicit direction to identify suspected incidents (e.g. probing) and feed them into the incident management process (5.25) directly enacts the `responds` verb once the forgery technique is underway.
- T1608detects — A.8.15 mandates log generation, protection, and analysis (including SIEM/UEBA/threat-intel correlation) that can surface anomalous staging activity on monitored infrastructure or outbound transfers, but the control's scope is limited to events the organization can observe and does not reach adversary-controlled external staging infrastructure (PRE platform).
- T1608.001detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including via SIEM, UEBA, threat intel, and correlation of events such as file uploads or changes to third-party repositories), which can surface T1608.001 activity when it occurs on monitored infrastructure; this is only a slice because the control's scope is limited to the organization's own systems/logs and does not inherently cover adversary-controlled or decentralized staging infrastructure (e.g. IPFS, blockchain, or external repos) where most of the technique occurs.
- T1608.002detects — A.8.15 requires log analysis and monitoring (SIEM/IDS/UEBA/threat intel/correlation) that can surface anomalous uploads or staging activity on adversary-controlled infrastructure when it intersects monitored systems, networks or logs, but this is limited to observable post-facto events on the victim side or within organizational scope rather than the adversary's pre-targeting upload on external/pre infrastructure.
- T1608.003detects — A.8.15 requires log analysis and monitoring (including of configuration changes, privilege use, system activities, alarms, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface certificate installation on adversary infrastructure or C2-related activity, but this is limited to post-installation observables on monitored systems and does not address pre-targeting installation on acquired/compromised infrastructure outside the organization's visibility.
- T1608.004detects — A.8.15 requires log analysis, anomaly detection via SIEM/IDS/UEBA, DNS log checks for malicious C2, correlation, and identification of suspected incidents (e.g. probing), which surfaces drive-by staging and delivery activity when it triggers observable events on monitored systems; this is a genuine but minority slice because the technique is pre-compromise infrastructure preparation on adversary-controlled assets outside the organization's visibility.
- T1608.005detects — A.8.15 requires log analysis and monitoring (SIEM/IDS/UEBA rules, anomalous behaviour detection, DNS logs, correlation) that can surface indicators of link-target setup such as phishing infrastructure or cloned sites, but this is limited to observable post-setup events on owned systems and does not systematically detect all pre-phish infrastructure (e.g. IPFS, external shortening services, or domain purchases).
- T1608.006detects — A.8.15 requires log analysis and monitoring (including UEBA, trend/pattern analysis, threat intel, DNS logs, and correlation) to surface anomalous activity and indicators of compromise; this can catch post-poisoning artifacts such as unusual inbound traffic, cloaking behavior in logs, or suspicious search referrals, but the core SEO manipulation (keyword stuffing, planted links, in-site gaming on PRE platforms) occurs outside monitored systems and leaves no guaranteed detectable event.
- T1609detects — A.8.15 explicitly requires logging, analysis, and monitoring of system activities, privilege use, configuration changes, resource access attempts, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces container admin commands such as docker exec or kubectl exec when they occur within the monitored scope.
- T1609responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification directly surface container admin command execution (e.g. docker exec, kubectl exec) once underway as an information security event, feeding the incident management process; this is the core of `responds` but remains partial because the clause stops at detection/analysis and does not itself perform containment or eradication.
- T1610detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including system config changes, privilege use, container-relevant alarms, and physical monitoring), and identification of suspected incidents such as probing or malware, which surfaces most forms of container deployment in monitored environments.
- T1610responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification directly support responding to a container deployment once it has occurred and is observable in logs, but only for the subset of deployments that produce detectable events rather than fully stealthy or out-of-scope ones.
- T1611detects — A.8.15 requires log analysis and monitoring (including SIEM/IDS/UEBA rules, anomalous behaviour detection, correlation of events such as privilege use, configuration changes, and access attempts) that can surface many container/host escape indicators post-facto, but does not mandate coverage of all listed vectors (e.g. kernel module loads, unshare/keyctl syscalls, docker.sock abuse, or hypervisor escapes in ESXi) and stops at identification rather than guaranteeing detection of every instance.
- T1612detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/rules, correlation of events (including system activities, privilege use, file access, configuration changes, and network activity), and identification of indicators of compromise or suspicious behavior that can surface a local container image build containing malware.
- T1613detects — A.8.15 requires log analysis and monitoring (including correlation, UEBA, SIEM/IDS rules, and review of access attempts, DNS, and physical events) to identify anomalous behavior and suspected incidents, which can surface container/resource discovery activity when it triggers logged events or patterns, but the clause does not mandate instrumentation of container-specific APIs, Kubernetes dashboards, or Docker log content that the technique explicitly leverages.
- T1614detects — A.8.15 requires log analysis and monitoring (including of system activities, configuration changes, network connections, anomalous behaviour, and correlation with threat intelligence) that can surface the execution of location-discovery techniques such as locale queries, metadata access, or outbound geolocation lookups, but only where those actions produce observable events inside the chosen logging and analysis scope.
- T1614.001detects — A.8.15 explicitly requires log analysis and monitoring of events (including system activities, configuration changes, privilege use, and anomalous behaviour via SIEM/UEBA/correlation) that can surface the registry/API/locale queries used by T1614.001, but only when those queries produce observable events inside the chosen logging scope; many language-discovery actions (especially in-process or non-audited) remain unseen.
- T1615detects — A.8.15 requires log analysis and monitoring (including of system activities, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation) that can surface Group Policy discovery commands or related anomalies, but this is scoped by what the organization chooses to log/monitor and does not guarantee coverage of all discovery methods or post-collection analysis.
- T1619detects — A.8.15 explicitly requires log analysis and monitoring of events including successful/rejected resource access attempts, privilege use, configuration changes, and anomalous behaviour (with SIEM/UEBA/threat intel correlation) which surfaces cloud storage enumeration via APIs as an indicator of compromise.
- T1619responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and identification of suspected incidents (e.g. probing) directly supports containment/eradication once T1619 enumeration is underway as part of incident response.
- T1620detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, unusual activity (including via UEBA, SIEM, IDS, DNS logs, and correlation), which surfaces in-memory reflective loading when it produces observable process or system anomalies; the named remainder is fully fileless cases that leave no detectable footprint in the listed events.
- T1620responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS correlation, and incident identification explicitly surface reflective loading once it has executed in a benign process (as an in-memory IOC or anomalous behavior), feeding the incident response process; it does not contain or eradicate the running payload itself.
- T1621detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, alarms from access control systems, and log analysis (with SIEM/IDS/UEBA/threat intel) to identify anomalous behaviour and indicators of compromise such as repeated login attempts or MFA fatigue patterns.
- T1621prevents — A.8.15 requires logging of access attempts (successful/rejected), privilege use, alarms from access-control systems, and analysis to surface anomalous patterns such as repeated MFA requests that signal fatigue attacks; this constrains the technique on monitored systems but does not stop the generation of MFA prompts themselves.
- T1621responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/IDS/UEBA rules on repeated login attempts or suspicious MFA patterns) enable response once the MFA fatigue or push-generation technique is underway, but this is scoped only to observable events within the logging policy rather than universal containment/eradication.
- T1622detects — A.8.15's log analysis and monitoring explicitly surface anomalous behaviour, indicators of compromise, and events such as privilege use or process anomalies that can include debugger-evasion artifacts (e.g. OutputDebugStringW flooding, SEH exceptions, or unusual API calls), but the control does not mandate instrumentation of the specific low-level debugger checks or PEB/TracerPID reads themselves.
- T1647detects — A.8.15 explicitly requires logging of configuration changes, privilege use, file accesses/deletions, security system events, and log analysis (with SIEM/UEBA/correlation) that surfaces anomalous plist modifications as indicators of compromise or incidents.
- T1647responds — A.8.15 requires logging of configuration changes, privilege use, file accesses/deletions, security system events, and anomalous behaviour via analysis (SIEM/UEBA/correlation), which surfaces plist modifications once they occur as part of incident response.
- T1648detects — A.8.15 requires log analysis and monitoring of events (including system activities, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation) that can surface serverless function creation/invocation and related cloud events, but this is scoped by what the organization chooses to log/monitor and does not guarantee coverage of all serverless abuse vectors or platforms.
- T1648responds — A.8.15 requires log analysis and correlation (including of cloud/application events, alarms, configuration changes, privilege use, and anomalous behaviour via SIEM/UEBA) to identify suspected incidents for further investigation under incident management, which matches the `responds` verb once the serverless abuse is underway; it is only partial because the control is silent on containment/eradication steps and many T1648 invocations (e.g. stealthy persistence via event triggers in SaaS/Office Suite) leave no detectable log trail within its listed events.
- T1649detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including access attempts, privilege use, configuration changes, and security system events), and identification of suspected incidents such as probing or malware that would surface certificate theft or anomalous enrollment/CA activity.
- T1649responds — A.8.15's log analysis, anomaly detection, correlation, and explicit direction to identify suspected incidents (e.g. probing) and feed them into the incident management process (5.25) directly enacts the `responds` verb once certificate theft/forgery is underway.
- T1650detects — A.8.15 requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts plus physical logs to surface indicators of compromise, which can reveal acquired footholds (e.g. unexpected backdoors, external remote services, or anomalous privileged use) after they exist; it is scoped to what the organization chooses to log/monitor so only a slice of broker-acquired access is surfaced.
- T1651detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including privileged use, configuration changes, system access attempts, and cloud-relevant admin actions), and identification of indicators of compromise or incidents, which surfaces T1651 abuse of cloud management services when logged.
- T1651responds — A.8.15's log analysis, anomaly detection, correlation, and identification of suspected incidents (e.g. via SIEM/IDS/UEBA) enable response once the cloud admin command execution is underway, but this is limited to detection feeding incident handling rather than containment/eradication itself.
- T1652detects — A.8.15 requires logging of system activities, privilege use, configuration changes, and anomalous behaviour plus explicit SIEM/UEBA/correlation analysis that can surface driver-enumeration commands or registry/driver-file accesses as indicators of compromise; this is genuine detection but only a slice because the clause's scope is set by what the organisation chooses to log/monitor and many of the cited discovery utilities produce no observable event unless those exact items are deliberately instrumented.
- T1652responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/UEBA/IDS rules on system activities, privilege use, configuration changes, and security system events) surfaces T1652 once it runs, enabling response via the linked incident management process.
- T1653detects — A.8.15 explicitly requires log analysis and monitoring of events (including system configuration changes, use of utilities, alarms, and anomalous behaviour via SIEM/UEBA/correlation) that can surface abuse of powercfg, timeout settings, or related utilities, but this is scoped by what the organization chooses to log/monitor and does not guarantee detection of all T1653 variants (e.g. file deletion of shutdown binaries or unmonitored platforms).
- T1654detects — A.8.15 mandates log analysis (including SIEM/IDS/UEBA rules, anomaly detection, correlation, and review of access attempts, alarms, and physical events) that surfaces log enumeration and related anomalous behavior in real time or post-facto.
- T1654responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification directly support responding to (and containing/eradicate) the real-time monitoring and adjustment of techniques that T1654 describes once the enumeration is underway.
- T1657detects — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access/financial-relevant events (e.g. privilege use, config changes, resource access) can surface indicators of financial theft campaigns (ransomware extortion, BEC transfers, unauthorized movements), but this is scoped to observable events within the logging policy and does not cover non-logged social engineering, external cryptocurrency exploits, or unmonitored platforms.
- T1657responds — A.8.15's log analysis, anomaly detection, and explicit direction to treat suspected incidents (e.g. probing, malware) as part of incident management (5.25) enables response once financial theft techniques are underway, but only for the detectable subset that produces observable events rather than the full technique surface (social engineering, BEC, extortion demands).
- T1659detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including network/DNS/physical logs), and identification of suspected incidents such as probing or malware, which surfaces T1659-style content injection from upstream or ISP channels as anomalous behavior.
- T1659responds — A.8.15's log analysis, anomaly detection, correlation, and explicit tie to feeding the incident management process (5.25) let it respond to realized content-injection events once underway, but only for the detectable slice observable in the listed events and not the upstream ISP-level channel compromise itself.
- T1665detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including network/DNS/physical logs), and identification of suspected incidents such as probing of firewalls or outbound connections to malicious C2-like servers, which surfaces T1665's traffic manipulation, filtering, and hiding artifacts.
- T1665responds — A.8.15's log analysis, correlation, and identification of suspected incidents (including anomalous network behaviour and probing) enable response actions once T1665 is underway, but the control stops at detection/analysis and does not itself perform containment or eradication.
- T1666detects — A.8.15 explicitly requires logging of configuration changes, privilege use, identity creation/modification/deletion, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the API calls and hierarchy modifications (e.g. CreateAccount, LeaveOrganization, new subscriptions) after they occur.
- T1666responds — A.8.15 requires log analysis and correlation (including of configuration changes, privilege use, and security-system activation/deactivation) to identify suspected incidents for further investigation under the incident-management process; this surfaces and enables response to hierarchy-modification events once they have occurred, but only for those that generate detectable logs and only up to the point of identification rather than containment/eradication itself.
- T1667detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including email-related events such as access attempts, alarms, and unusual activity patterns), and identification of suspected incidents such as probing; this surfaces email bombing as anomalous volume or spam patterns in most cases, though coverage depends on whether email-specific logs are in scope.
- T1667responds — A.8.15 requires log analysis and correlation (including of email-related events, alarms, and anomalous patterns) to identify suspected incidents such as probing or overload, which feeds the incident management process (5.25) for response once the bombing is underway; it does not itself contain or eradicate the flood.
- T1668detects — A.8.15's log analysis and monitoring explicitly surface anomalous activity, indicators of compromise, and events such as configuration changes, privilege use, malware-related alarms, and suspicious access that can reveal an adversary performing exclusive-control actions (e.g. patching, disabling services, or removing other malware).
- T1669detects — A.8.15 requires log analysis and monitoring (including of network activity, access attempts, configuration changes, alarms, and anomalous behaviour via SIEM/IDS/UEBA/correlation) that can surface Wi-Fi connection events or follow-on sniffing/AiTM, but this is scoped by what the organization chooses to log/monitor and does not guarantee detection of proximity-based or bridged wireless access itself.
- T1671detects — A.8.15 explicitly requires logging of privilege use, configuration changes, identity creation/modification/deletion, access attempts, and anomalous behaviour via SIEM/UEBA/threat-intelligence-driven analysis, which surfaces the creation, consent-granting, or co-opting of malicious OAuth integrations as indicators of compromise.
- T1671responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and identification of suspected incidents (e.g. probing or malware) directly supports responding to and containing an active T1671 persistence technique once the OAuth integration or related events are logged.
- T1673detects — A.8.15 requires log analysis and monitoring of events (including system activities, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation) that can surface VM enumeration commands or GUI access after the fact; this is genuine but only a slice, as the control's scope is set by what the organization chooses to log/monitor and does not mandate coverage of hypervisor-specific discovery like esxcli on ESXi.
- T1673responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification explicitly surface VM-enumeration activity (e.g. privilege use, hypervisor CLI, config changes) once it has begun, feeding the incident-management process, but only where the specific events are selected for logging and the analysis scope includes them.
- T1674detects — A.8.15 explicitly requires logging and analysis of events including successful/rejected access attempts, privilege use, system configuration changes, alarms from access control/IDS, anomalous behaviour via SIEM/UEBA/correlation, and indicators of compromise such as malware or probing, which surfaces most forms of input injection (keystroke simulation, HID, PowerShell launch) once executed.
- T1674responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of access/system events) can surface input-injection techniques once underway as indicators of compromise or anomalous activity, enabling incident response, but this is limited to observable logged events and does not address physical HID or all preprogrammed cases.
- T1675detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, resource access attempts, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the ESXi admin APIs and guest command execution as security events or indicators of compromise.
- T1675responds — A.8.15's log analysis, anomaly detection, correlation, and identification of suspected incidents (e.g. via SIEM/IDS/UEBA rules on privileged use, system changes, or anomalous guest commands) directly supports containment/eradication once the ESXi abuse technique is underway, with the named remainder being pre-analysis impact already realized on guest VMs.
- T1677detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and correlation of events (including config changes, privilege use, file access/deletion, and security system activation) to surface indicators of compromise; this catches many poisoning indicators post-execution but is silent on build-specific pipeline telemetry or pre-execution detection of malicious PRs/forks, leaving a large slice of the SaaS technique unreached.
- T1677responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomaly detection, correlation of events including config changes, privilege use, and access attempts) can surface a pipeline poisoning once the malicious code executes and triggers observable events, enabling identification as part of incident response; this is a genuine but minority slice of the technique's stealthy injection vectors (especially indirect/public scenarios that may not produce immediate detectable events).
- T1678detects — A.8.15 requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and specific monitoring (e.g. of system activities, scheduled tasks, privilege use, and network behavior) that can surface many time-based delay techniques once they execute, but this is scoped by what the organization chooses to log/monitor and does not guarantee coverage of all variants (e.g. API hammering or sandbox-specific sleeps).
- T1679detects — A.8.15 explicitly requires log analysis, anomaly/behaviour detection, SIEM/IDS/UEBA rules, correlation, and review of access attempts plus physical events to surface indicators of compromise such as selective ransomware activity that leaves system files untouched.
- T1680detects — A.8.15 explicitly requires logging of system activities, privilege use, resource access attempts, configuration changes, and file operations, plus log analysis (with SIEM/UEBA/correlation/threat intel) to surface anomalous behaviour and indicators of compromise; this directly catches the reconnaissance commands and API calls of T1680 in most covered environments, with the bounded remainder being unmonitored IaaS hypervisor or physical-layer discovery outside the log scope.
- T1680responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/UEBA rules on file/system access, privilege use, configuration changes) surface T1680 execution in flight as an information security event, enabling response per the linked incident management process.
- T1681detects — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and review of events (including outbound connections, unusual activity, and indicators of compromise) can surface an adversary querying threat vendor data or related IOCs when that activity produces observable logs, but this is limited to what the organization's own monitored logs actually capture and is not inherent to the technique's PRE platform reconnaissance nature.
- T1682detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise, which can surface T1682 queries to public AI services when they produce observable network, application or usage anomalies inside the monitored scope; the remainder is that most such queries are indistinguishable from legitimate traffic and fall outside the clause's predetermined rules or UEBA patterns.
- T1683detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including unusual activity that can support social engineering or phishing campaigns), but this surfaces the downstream use of generated content rather than the content-generation act itself on a PRE platform.
- T1683.001detects — A.8.15's log analysis and monitoring activities surface anomalous written content (e.g. phishing lures, fabricated documents, or suspicious patterns in emails/social media) when it reaches systems or triggers events, but this is limited to post-creation detection on the target side and does not cover pre-delivery creation on PRE platforms.
- T1683.002detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including via UEBA, SIEM, IDS, and correlation), which can surface use of synthetic audio-visual content when it produces observable artifacts in supported techniques such as phishing or social engineering; this is limited to a slice because the control is silent on media authenticity detection and most T1683.002 activity (e.g. offline generation on PRE) leaves no logged trace.
- T1684detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts, configuration changes, privilege use, and physical events to surface social engineering indicators (e.g. unusual password-reset or MFA requests, urgent/emotion-driven actions) that precede or accompany the authorized-but-malicious outcome.
- T1684responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomaly detection, correlation, incident identification) surface social engineering once it produces observable events such as access attempts or configuration changes, enabling response; this is limited because the technique itself is non-technical, human-targeted, and often leaves minimal logs until after the authorized action succeeds.
- T1684.001detects — A.8.15 requires log analysis and monitoring (SIEM/UEBA/IDS correlation, anomalous behaviour review, DNS logs, physical logs) that can surface impersonation indicators such as anomalous access, unusual email patterns or spoofed sender activity once the technique is in flight; it does not guarantee detection of every social-engineering vector or pre-delivery reconnaissance.
- T1684.001responds — A.8.15's log analysis, anomaly detection, correlation, and identification of suspected incidents (e.g. probing, unusual activity) directly supports containment/eradication once impersonation (e.g. BEC phishing) is underway, with the named remainder being pre-realization social engineering that evades detection until action occurs.
- T1684.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of logs (including successful/failed access, configuration changes, alarms), and identification of suspected incidents such as probing or social-engineering precursors, which surfaces Email Spoofing attempts in monitored environments.
- T1685detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of logs (including from security systems and physical monitoring), and identification of suspected incidents such as probing or malware, which surfaces tampering with logging agents, event log modifications, or disabled sensors/telemetry as described in T1685.
- T1685prevents — A.8.15 requires protection of logs against deletion, alteration, deactivation, and overwriting (via append-only, hashing, access controls, and synchronized time sources), which directly stops many of the technique's sub-actions against logging agents, event logs, syslog, and SIEM pipelines, but leaves untouched the broader tampering of EDR/IDS/AV, sensors like ETW/Sysmon, configuration files outside logs, update mechanisms, and non-log defensive tools.
- T1685.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation, and monitoring of successful/failed access, DNS, physical events, and suspected incidents to surface tampering or disablement of logging itself.
- T1685.001prevents — A.8.15's determination of what must be logged, protection of the logging facility against disablement/alteration/deletion, prohibition on users (including privileged) deleting their own logs, and requirements for synchronized protected logs directly counters the T1685.001 techniques of stopping the EventLog service, altering auditpol/registry settings, or clearing policies; the bounded remainder is non-Windows platforms and logs outside the organization's defined scope.
- T1685.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation, and identification of suspected incidents (e.g. probing), which surfaces the disable/modify action when it affects observable events or leaves detectable gaps.
- T1685.002prevents — A.8.15's requirements to protect logs against deletion/deactivation, unauthorized changes, failure to record, and overwriting (via append-only, hashing, etc.) plus mandatory logging of access attempts, privilege use, and config changes directly stop many of the described modifications and bypasses, but the control is silent on cloud-specific integrations, licensing, or command-level toggles and cannot reach an adversary who already holds sufficient privileges to alter the logging configuration itself.
- T1685.003detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including via SIEM, UEBA, correlation, and review of access/security events), which can surface the spoofed-UI technique when it produces detectable discrepancies in logs or monitored signals, but the control has no view of purely visual UI fakery that leaves no log trail.
- T1685.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of logs (including successful/rejected access, privilege use, config changes, and security system activation), and identification of suspected incidents such as probing or malware — all of which surface attempts to disable or modify auditd rules, kill the daemon, or alter /etc/audit/* files when those actions are themselves logged and reviewed.
- T1685.004prevents — A.8.15 requires determining what to log, protecting logs against deletion/alteration/failure (via append-only, hashing, etc.), and analyzing them to identify incidents, which directly counters disabling or modifying auditd/rules on Linux; however, it is a policy-and-configuration mandate whose actual enforcement depends on implementation rigor and does not itself block root-level hooking or service-kill techniques.
- T1685.004responds — A.8.15 requires log protection (no deletion/deactivation by users, append-only mechanisms, integrity via hashing) and analysis to identify incidents once underway, which responds to the technique's effects but does not cover all vectors like kernel hooking or pre-modification of rules.
- T1685.005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of logs (including security/audit events), and identification of suspected incidents such as probing or malware that would surface the clearing of Windows Event Logs.
- T1685.005prevents — A.8.15 explicitly requires protecting logs against deletion, editing, deactivation, overwriting, or unauthorized changes (via append-only/read-only mechanisms, crypto hashing, privilege restrictions, and retention), which directly stops the T1685.005 clearing actions on Windows Event Logs; mostly because the control is a set of requirements whose completeness depends on implementation rigor and does not name every possible clearing vector (e.g. direct .evtx deletion in all scenarios).
- T1685.005responds — A.8.15 explicitly requires protecting logs against deletion/alteration (no user permission to delete own-activity logs, append-only/read-only mechanisms, cryptographic hashing), detecting the clearing via analysis/monitoring of anomalous events, and subjecting suspected incidents (including log-clearing as an indicator of compromise) to incident response per 5.25, which matches the `responds` verb of containment/eradication once the technique is underway.
- T1685.006detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation, and review of access attempts/alarms to surface suspected incidents such as log tampering that would be visible in protected logs or their absence.
- T1685.006prevents — A.8.15 explicitly requires protecting logs against deletion/editing/overwriting (including by privileged users), using append-only/read-only mechanisms, cryptographic hashing, and retention policies, which directly stops the adversary action of clearing /var/log/* files on Linux/macOS.
- T1685.006responds — A.8.15 requires log protection (no deletion by actors, append-only mechanisms, cryptographic hashing) plus explicit identification of suspected incidents (e.g. probing, anomalous activity) for further investigation under the incident management process, which directly enacts containment/eradication once the clearing technique is underway.
- T1686detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of events (including changes to system configuration, use of privileges, alarms from access control systems, and activation/deactivation of security systems), and identification of indicators of compromise such as probing of firewalls, which surfaces T1686 behaviors after they occur.
- T1686prevents — A.8.15 mandates logging of configuration changes, privilege use, security system activation/deactivation and alarms, plus protected logs that cannot be deleted or altered by the actor; this surfaces or constrains many T1686 behaviors (especially post-privilege tampering) but does not stop the adversary from disabling or modifying the firewall itself.
- T1686responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification directly surface firewall tampering once it has occurred (the technique has run), feeding the incident response process, but this is only a detection slice that does not itself contain or eradicate the actor's changes.
- T1686.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of configuration changes, privilege use, security system activation/deactivation, and physical events to surface indicators of compromise such as firewall rule modifications.
- T1686.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of configuration changes, privilege use, security system activation/deactivation, and firewall-related events to surface suspected incidents such as probing or rule manipulation.
- T1686.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules, correlation of logs (including successful/rejected access attempts, configuration changes, privilege use, alarms from access control systems, and activation/deactivation of security systems), and identification of suspected incidents such as probing of firewalls, which surfaces T1686.003 activity after it occurs.
- T1686.003responds — A.8.15's log analysis, anomaly detection, correlation, and explicit identification of incidents (e.g. probing of firewalls) followed by further investigation directly enacts the `responds` verb once the firewall modification is underway.
- T1687detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, monitoring of access attempts/alarms/security system activation, and correlation to identify suspected incidents including probing or malware that can represent defense-impairment activity.
- T1688detects — A.8.15 requires log analysis and monitoring (including of system configuration changes, privilege use, boot-related events via alarms/IDS, and anomalous behaviour via SIEM/UEBA/correlation) that can surface safe-mode boots and related Registry/BCD tampering as indicators of compromise, but this is scoped by what the organization chooses to log/monitor and does not guarantee coverage of all safe-mode abuse vectors.
- T1689detects — A.8.15 explicitly requires log analysis (with SIEM/UEBA/rules/threat intel/correlation) and monitoring of events including privilege use, configuration changes, system activities, and anomalous behaviour to surface indicators of compromise such as a downgrade that impairs logging or security controls.
- T1690detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/rules, correlation, and review of access attempts plus security-system events to surface indicators of compromise; this surfaces the technique when it produces observable anomalies or is itself logged as a configuration change/privilege use, but the core in-memory HIST* or Set-PSReadLineOption manipulations often leave no detectable event and fall outside the clause's named detection scope.
Prevented OWASP Web Top 10 (2025) risks (28)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A01finds — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, and correlation to surface suspected incidents including access-control violations (e.g. rejected attempts, privilege use, configuration changes), but this is post-facto discovery only and does not cover design-time or code-level access-control defects such as path traversal, IDOR or CSRF that never reach logs.
- A01mitigates — logging and its analysis can detect and limit the realized impact of some broken-access-control events (e.g. via alarms on privilege use, configuration changes, or anomalous access patterns) but does not bound or reduce the consequence of the majority of the category (path traversal, IDOR, CSRF, missing function-level checks)
- A02finds — A.8.15 explicitly requires log analysis (with SIEM/IDS/UEBA/threat-intel rules, anomaly detection, DNS/firewall review, correlation) that surfaces misconfigurations as security events or indicators of compromise, but this is only one slice of the broad A02 class (e.g. it catches runtime symptoms of weak defaults or exposed surfaces but does not discover static config flaws like unhardened framework defaults or cloud IAM gaps before they are exercised).
- A02mitigates — logging and its analysis can detect anomalous behavior resulting from a misconfiguration (e.g. via alarms, access attempts, configuration changes) and thereby limit the realized consequence or duration of an incident, but the weakness itself (the exposed configuration) remains untouched
- A05finds — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, and correlation to identify security events and indicators of compromise, which surfaces many injection attempts (e.g. probing, anomalous queries, outbound C2) after they occur; it does not discover injection flaws in code or untriggered weaknesses.
- A05mitigates — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification can surface realized injection (e.g. outbound C2 from command injection or anomalous SQL patterns) and thereby limit further damage, which is mitigation of consequence; it does not stop the untrusted input from reaching or succeeding at the interpreter boundary itself.
- A07finds — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts (including successful/failed logons and privilege use) to surface suspected incidents, which discovers many authentication failures such as brute-force or anomalous credential use; it does not discover design defects like weak reset flows or flawed session management that are not expressed in observable events.
- A07mitigates — A.8.15's log analysis, anomaly detection, and correlation of access attempts (including failed logons, privilege use, and alarms) can surface indicators of brute-force, credential stuffing, or hijacking after they occur, bounding the realized consequence without stopping the authentication weakness itself.
- A08finds — A.8.15's log analysis and monitoring sections surface anomalous activity, indicators of compromise, and suspected incidents that can include integrity failures (e.g. unsigned updates or CI/CD anomalies via correlated logs, UEBA, or threat intel), but this is indirect, post-facto, and limited to detectable events rather than systematically finding the class's core weaknesses like insecure deserialization.
- A08mitigates — A.8.15's log analysis, anomaly detection, and correlation (including physical logs and threat intel) can surface indicators of integrity failures such as unsigned updates or CI/CD tampering after they occur, thereby bounding consequences, but does not limit the realization of the weakness itself.
- A09mitigates — A.8.15 directly protects log integrity, prevents deletion/alteration by users (including privileged), mandates synchronized protected logging of security events, and requires analysis to identify anomalies/incidents, which bounds the realized impact of missing or tampered logs without preventing the logging failure itself.
- A10finds — A.8.15 explicitly requires log analysis (including SIEM/IDS/UEBA rules, anomaly detection, trend analysis, and correlation of events such as access attempts, configuration changes, and alarms) to identify unusual activity or indicators of compromise that can represent mishandled exceptions or logic-flaw errors, but this is only one slice of the broad A10 class (e.g., it surfaces runtime leaks or fail-open states via logs but does not inspect code for inconsistent error paths or fail-open auth design).
- A10mitigates — Logging and its analysis can detect anomalous states or leaked information from mishandled exceptions after they occur, thereby bounding the consequence, but does not address fail-open behavior, inconsistent states, or prevent the mishandling itself.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.