A.8.15 Technological
Logging
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (26)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AU-2fullcovers — A.8.15's core requirement to record events and generate evidence directly accounts for the entirety of AU-2's identification, coordination, and specification of event types for logging; nothing in the target sits outside the source.
- AU-2mostlyaligns with — Both controls define the events and activities that must be captured in logs to support accountability and incident investigation.
- AU-3mostlyaligns with — Both specify the minimum data elements that each logged event must contain to enable reconstruction and correlation of security-relevant actions.
- AU-3mostlycovers — A.8.15's requirement to record events and generate evidence (with integrity and access controls) directly accounts for the bulk of au-3's mandated content fields that establish what/when/where/source/outcome/identity, but a residual of au-3's explicit, enumerated detail-level prescription sits outside the higher-level ISO wording.
- AU-9mostlyaligns with — Both require technical and procedural safeguards to prevent unauthorized modification or deletion of audit records, including by privileged users.
- AU-9mostlycovers — A.8.15's explicit requirements to ensure log integrity and prevent unauthorized access directly implement the core protection of audit information in AU-9, but AU-9's separate alerting-on-tampering obligation sits outside what A.8.15 records.
- AU-11partialaligns with — Both address retention and archival of log data when required for regulatory, evidentiary, or operational purposes.
- AU-11partialcovers — A.8.15's purpose includes generating evidence, identifying events, and supporting investigations, which overlaps with au-11's retention-for-investigations goal, but does not address the distinct retention-duration, regulatory, or organizational requirements that form the bulk of au-11.
- AU-6partialaligns with — Both emphasize systematic review and analysis of logged events to detect anomalies, indicators of compromise, and support incident response.
- AU-8partialaligns with — Both stress the need for synchronized, accurate time stamps across systems so that logs can be reliably correlated during analysis and investigations.
- AU-6covers — A.8.15's broad logging purposes (record events, generate evidence, ensure integrity, prevent unauthorized access, identify events, support investigations) address only a slice of AU-6's specific requirements for ongoing review, analysis, reporting of audit records, and risk-based adjustment of that process.
- AU-8covers — A.8.15's broad mandate to record events and generate evidence reaches the requirement to produce timestamps on audit records, but says nothing about clock synchronization, UTC/offset representation, or accuracy parameters that dominate au-8.
Aligned NIST CSF 2.0 outcomes (25)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- PR.PS-04fullcovers — The ISO control mandates generation and protection of event logs that capture user, system, and security-relevant activity, directly satisfying the CSF requirement to produce logs for continuous monitoring.
- DE.AE-02mostlyaligns with — The control’s emphasis on log analysis to detect unusual or anomalous behaviour supports the CSF goal of analyzing potentially adverse events to understand associated activities.
- DE.AE-03mostlyaligns with — Requiring synchronized time sources and correlation of logs across systems enables the CSF outcome of correlating information from multiple sources to understand adverse events.
- DE.CM-01partialaligns with — By generating logs of network-related events and access attempts, the control contributes to the CSF outcome of monitoring networks and services for potentially adverse events.
- DE.CM-03partialaligns with — Logging of user activities, privilege use, and identity changes provides the data needed to monitor personnel activity and technology usage for adverse events.
- ID.RA-01partialaligns with — Analysis of logged security events can reveal vulnerabilities or misconfigurations that need to be identified, validated, and recorded.
- RS.AN-03partialaligns with — Preserved and protected logs supply the detailed event data required for post-incident analysis to determine what occurred and identify root cause.
- DE.AE-02implements — A.8.15 logging directly supplies the raw records whose analysis is DE.AE-02; the technical logging control therefore gives operational effect to the adverse-event analysis outcome, but the link is inferential rather than named.
- DE.AE-03implements — A.8.15's logging, event identification, and investigation-support functions give operational effect to multi-source correlation within the DE.AE detection-analysis domain, but do not name correlation explicitly
- DE.CM-01implements — A.8.15's logging and event-identification functions give operational effect to network monitoring for adverse events within the detection domain, but do not name or exclusively perform the monitoring itself
- DE.CM-03implements — A.8.15's logging, integrity, and event-identification functions give direct operational effect to the monitoring of personnel activity and technology usage that DE.CM-03 requires; the link is within the detection domain but the CSF outcome does not name logging specifically.
- ID.RA-01implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- RS.AN-03implements — A.8.15's logging, integrity, and event-identification functions give direct operational effect to the incident analysis and root-cause determination required by RS.AN-03; the link is within the shared incident-response domain but RS.AN-03 does not name logging as the specific means.
Related OWASP ASVS 5.0 requirements (16)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V16.2.2fullaligns with — ISO’s explicit call for synchronized time sources across systems implements the ASVS requirement that timestamps in security logs use a consistent, synchronized time base (UTC or offset) to enable correlation.
- V16.2.1mostlyaligns with — The ISO requirement to capture user IDs, system activities, dates/times, device and network identifiers for each event directly supports the ASVS mandate that every log entry contain the metadata needed for detailed security investigations.
- V16.3.1mostlyaligns with — Logging of successful and rejected system access attempts, privilege use, and identity changes satisfies the ASVS requirement to record all authentication operations with relevant metadata.
- V16.4.2mostlyaligns with — ISO’s controls preventing privileged users from deleting or altering their own logs and protecting against unauthorized log changes implement the ASVS requirement that logs be protected from unauthorized access and modification.
- V16.2.5partialaligns with — ISO’s recognition that logs may contain sensitive or PII data and the call for privacy-protection measures aligns with the ASVS requirement to enforce logging rules based on data-protection levels.
- V16.3.2partialaligns with — ISO’s requirement to log successful and rejected data/resource access attempts partially fulfills the ASVS need to log failed (and, at L3, all) authorization decisions.
- V16.3.3partialaligns with — The ISO directive to log security-system activations, configuration changes, and attempts to bypass controls aligns with the ASVS requirement to log both defined security events and bypass attempts.
- V16.4.3partialaligns with — ISO’s guidance on sending logs to a separate system for analysis, detection and alerting partially satisfies the ASVS requirement for secure, logically separate log transmission and storage.
Related weaknesses / CWE (52)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1304nonedetects — Logging can record power events but does not ensure or verify configuration integrity.
- CWE-385nonedetects — Detailed logging can reveal timing anomalies but does not prevent covert timing channels.
- CWE-807nonedetects — Logging may record the flawed decisions but does not prevent them.
- CWE-1050finds — Logging may detect excessive consumption but does not stop the loop.
- CWE-125finds — Logging can record evidence of an out-of-bounds read but does not prevent the weakness itself.
- CWE-1274finds — Logging can detect unauthorized writes to volatile memory but does not prevent the weakness.
- CWE-1295prevents — Logging control requires that only necessary information is recorded, directly mitigating debug messages that leak sensitive data.
- CWE-1323prevents — Logging controls define where and how trace data may be stored.
- CWE-200finds — Cryptographic hashing, append-only storage, and access restrictions on log files limit an attacker’s ability to read or tamper with recorded sensitive information.
- CWE-202finds — Logging query activity supports detection of inference attempts after the fact.
- CWE-210prevents — Logging policy can require suppression of sensitive data in error messages.
- CWE-222prevents — Logging ensures security-relevant events are recorded without truncation that could hide attack details.
- CWE-223prevents — Logging directly requires recording security-relevant events that the weakness omits.
- CWE-269finds — Logging every use of privileges and protecting those records makes it harder for an attacker who has obtained elevated rights to operate without leaving evidence.
- CWE-284finds — Forbidding privileged users from deleting or altering their own logs prevents abuse of elevated rights to conceal unauthorized actions.
- CWE-360finds — Logging can capture event data but does not inherently validate its authenticity against spoofing.
- CWE-390finds — Logging captures error conditions but does not guarantee subsequent handling or remediation.
- CWE-400finds — Specifying log storage limits and rotation procedures reduces the risk that unbounded log growth will exhaust disk or memory resources and cause denial of service.
- CWE-406finds — Logging provides visibility into high-volume traffic but does not itself limit or control it.
- CWE-507finds — Logging can detect Trojan Horse activity after the fact but does not prevent its presence.
- CWE-509finds — Logging supports detection of malware activity and replication attempts.
- CWE-511finds — Logging can record execution of time- or logic-triggered code, aiding detection after the fact.
- CWE-515finds — Logging may record covert storage activity but does not prevent the channel itself.
- CWE-532prevents — Requiring de-identification and privacy controls before logs leave the organization reduces the chance that sensitive data inadvertently captured in logs becomes exposed to external parties.
- CWE-535mitigates — Logging can capture error messages but does not prevent their exposure to users.
- CWE-69finds — Logging of file-system events can record ADS access attempts, aiding detection, but does not prevent the weakness itself.
- CWE-74finds — Logging supports detection of injection attempts but does not prevent the weakness.
- CWE-75finds — Logging can record injection attempts for detection but does not prevent the weakness.
- CWE-754finds — Logging can record unhandled exceptions but does not prevent the weakness itself.
- CWE-755finds — Logging captures unhandled exceptions, aiding detection but not preventing the weakness.
- CWE-778prevents — Mandating comprehensive event logging with user IDs, timestamps, and access attempts directly eliminates the absence of audit trails that would otherwise allow undetected exploitation.
- CWE-779prevents — A.8.15 directly requires logging to be configured so that only necessary events are recorded, preventing excessive data.
- CWE-91finds — Logging can record injection attempts for detection but does not prevent the weakness.
Mitigated MITRE ATT&CK techniques (1914)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log review for malicious C2, correlation, and identification of probing or IOCs, which surfaces obfuscated C2 traffic when it deviates from baselines.
- T1001responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including probing or C2-like patterns via correlation, UEBA, DNS checks, etc.) once the obfuscated traffic is underway, which matches the `responds` verb; it is only partial because the clause stops at identification/investigation and does not itself perform containment or eradication.
- T1001.001detects — A.8.15 requires log analysis, anomaly detection via SIEM/IDS/UEBA, DNS log review for malicious C2, and correlation to identify indicators of compromise; this surfaces some junk-data C2 (especially non-trivial patterns or known IOCs) but leaves substantial residue for novel or obfuscated junk that evades signature/behavior rules.
- T1001.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log review for malicious C2, correlation of events, and identification of indicators of compromise including probing; this surfaces steganographic C2 traffic when it produces observable network, DNS, or behavioral artifacts in the logged events, though it cannot see purely in-band hidden payloads without detectable side effects.
- T1001.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log review for malicious C2, correlation of events, and identification of suspected incidents such as probing, all of which surface protocol/service impersonation that blends with or mimics legitimate traffic.
- T1001.003responds — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and incident identification explicitly surface and feed into the incident management process (5.25) once impersonated C2 traffic is underway, but this is limited to detectable cases rather than all impersonation variants.
- T1003detects — Recording privileged utility execution, file access, and system configuration changes can reveal attempts to dump credentials from memory or registry stores.
- T1003responds — A.8.15's log analysis, anomaly detection, and incident identification (e.g. via SIEM/UEBA/correlation) surface credential-dumping artifacts once the technique has run, feeding the incident response process, but this is only a slice of full containment/eradication.
- T1003.001detects — A.8.15 explicitly requires logging of privilege use, system access attempts, configuration changes, and security system activation/deactivation, plus log analysis with SIEM/IDS/UEBA rules, anomaly detection, and correlation to identify indicators of compromise such as LSASS dumping or SSP modifications.
- T1003.001responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. anomalous behaviour, indicators of compromise) and feed them into the incident management process (5.25), which is the core of `responds`; it does not itself contain or eradicate the LSASS dump once underway.
- T1003.002detects — A.8.15 explicitly requires logging of privilege use, system access attempts, configuration changes, and file/registry accesses plus SIEM/UEBA/correlation analysis to surface anomalous behaviour and indicators of compromise such as SAM extraction tools or registry saves.
- T1003.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of logs (including successful/rejected access, privilege use, file access/deletion, and security system events), and identification of suspected incidents such as probing or malware, which surfaces T1003.003 activity on domain controllers or backups in most cases.
- T1003.003responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. probing, anomalous access to protected resources or files) once underway for further investigation under incident management, but this is limited to detection-plus-handover rather than full containment/eradication of the NTDS copy or credential theft itself.
- T1003.004detects — A.8.15 explicitly requires logging of privilege use, system access attempts, configuration changes, and security system events plus SIEM/IDS/UEBA-driven analysis to surface anomalous behaviour and indicators of compromise such as credential dumping tools or registry reads of the LSA secrets hive.
- T1003.004responds — A.8.15 requires log analysis (including SIEM/IDS/UEBA rules, anomaly detection, correlation, and explicit review of access attempts and privilege use) to identify suspected incidents such as credential access; once the technique is underway this surfaces it for the incident management process (5.25) that contains and eradicates it.
- T1003.005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including successful/rejected access, privilege use, configuration changes, and physical events), and identification of indicators of compromise such as probing or malware, which surfaces T1003.005 extraction activity when it generates observable events on monitored systems.
- T1003.006detects — A.8.15 explicitly requires logging of privilege use, system access attempts, configuration changes, and security system events, plus SIEM/IDS/UEBA-driven analysis and correlation to surface anomalous behaviour and indicators of compromise such as DCSync replication requests from non-DC accounts.
- T1003.006prevents — A.8.15 mandates logging of privilege use, system access attempts, configuration changes and security system activation/deactivation (including on domain controllers), which can be configured to surface or block unauthorized DCSync replication attempts via monitoring rules; however, it does not stop the privileged user or process from performing the API abuse itself.
- T1003.006responds — A.8.15 requires log analysis, anomaly detection via SIEM/IDS/UEBA/correlation, and feeding suspected incidents (e.g. privilege use, config changes, access attempts) into the incident management process (5.25) for containment/eradication once DCSync is underway.
- T1003.007detects — A.8.15 explicitly requires logging of access attempts, privilege use, file accesses (including to /proc), configuration changes, and anomalous behaviour via log analysis, SIEM, UEBA, and correlation, which surfaces the T1003.007 technique when it reads credential patterns from proc filesystem files.
- T1003.008detects — A.8.15 explicitly requires logging of successful/rejected access attempts to files and resources, use of privileges, system activities, and log analysis (with SIEM/UEBA/IDS rules, anomalous behaviour detection, and correlation) that surfaces the cat/unshadow read of /etc/shadow as an indicator of compromise.
- T1003.008prevents — A.8.15 mandates logging of access attempts (successful/rejected) to resources including files like /etc/shadow, plus protection of those logs from tampering or deletion; this surfaces the T1003.008 read attempt in analysis and can deter or block it via accountability and integrity controls, but does not stop a root-privileged or bypassed adversary from reading the files themselves.
- T1005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts, file activity, privilege use and configuration changes — all of which surface the reconnaissance and collection behavior named by T1005 after it runs.
- T1006detects — A.8.15 explicitly requires logging of system activities, privilege use, file access (incl. deletion), configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the utilities and direct volume reads that bypass normal monitoring; the named remainder is the pre-log or non-monitored platform slice (e.g. network devices).
- T1007detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, configuration changes, utility-program execution, and anomalous behaviour (via SIEM/UEBA/threat-intel correlation), which surfaces the reconnaissance commands and their outputs that constitute T1007; the named remainder is unmonitored or non-logged endpoints where the technique can run silently.
- T1008detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation across synchronized logs (including network, DNS, and physical), and identification of indicators like probing or outbound C2 — which surfaces fallback channel usage when it produces observable events.
- T1010detects — A.8.15 explicitly requires log analysis and monitoring of events (including system activities, privilege use, application transactions, anomalous behaviour via UEBA/SIEM/IDS correlation) that surfaces T1010's use of native commands/APIs to enumerate windows as an indicator of compromise or reconnaissance.
- T1011detects — A.8.15 requires log analysis and monitoring (including network/DNS/physical logs, anomalous behaviour, UEBA, and correlation) that can surface exfiltration over secondary media when it produces observable events inside the monitored scope, but the clause sets scope by policy and does not mandate coverage of all alternative media (Bluetooth, RF, cellular) or all platforms.
- T1011.001detects — A.8.15 requires log analysis and monitoring (including anomalous behaviour, network connections, physical events, and correlation) that can surface Bluetooth exfiltration when it produces observable events inside the chosen scope, but the clause sets that scope by policy rather than mandating Bluetooth-specific instrumentation, leaving many realisations (especially proximity-only, non-networked) outside what is required.
- T1012detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, resource access attempts, and anomalous behaviour via SIEM/UEBA/threat-intel analysis, which surfaces Registry queries performed by adversaries as part of discovery.
- T1014detects — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and review of access/system events can surface rootkit indicators (e.g. anomalous hooks, hidden processes via behavioral deviation), but rootkits are designed to evade exactly these logging and monitoring mechanisms at kernel/firmware levels.
- T1016detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, network-related events, and log analysis (including SIEM/UEBA, anomalous behaviour detection, DNS logs, and correlation) that surfaces T1016 execution or its artifacts post-facto.
- T1016.001detects — A.8.15 explicitly requires logging, analysis, and monitoring of network activity (including outbound connections, anomalous behaviour, DNS logs, and correlation) that surfaces Internet Connection Discovery as an indicator of compromise or unusual activity.
- T1016.002detects — A.8.15 explicitly requires logging of system activities, network addresses/protocols, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces Wi-Fi enumeration commands, file reads (/etc/NetworkManager), netsh/wlanAPI calls, and related IOCs on Linux/Windows/macOS after they occur.
- T1018detects — A.8.15 explicitly requires logging, protection, and analysis of events including system access attempts, privilege use, configuration changes, network activity, alarms, and anomalous behaviour via SIEM/UEBA/correlation to identify indicators of compromise such as discovery commands or unusual network enumeration.
- T1018responds — A.8.15 requires log analysis (including correlation, UEBA, SIEM/IDS rules, and review of access attempts, alarms, and anomalous behavior) plus identification of suspected incidents for further investigation under the incident management process, which directly enacts containment/eradication once discovery activity is underway.
- T1020detects — A.8.15 requires determining, collecting, protecting, and analyzing logs of events including access attempts, configuration changes, privilege use, file access/deletion, alarms, and anomalous behavior via SIEM/UEBA/threat intel/correlation; this surfaces automated exfiltration (and its prerequisite collection) as an information security event or indicator of compromise in most cases, though some stealthy automated exfil may evade the defined logging scope.
- T1020responds — A.8.15 requires log analysis, anomaly detection, correlation and explicit hand-off of suspected incidents (including outbound connections to malicious C2) into the incident management process (5.25), which directly performs the containment/eradication actions that `responds` names once automated exfiltration is underway.
- T1020.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, DNS log review for malicious C2, correlation of logs including physical events, and identification of suspected incidents such as probing, all of which surface traffic mirroring or its exfiltration artifacts after the technique runs.
- T1021detects — Recording remote-service connections, privilege escalations, and network-address details helps identify lateral-movement activity over protocols such as RDP or SMB.
- T1021prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour analysis (with time sync and integrity protection), which can surface or deter some T1021 abuse of valid accounts over remote services but does not stop the login or execution itself.
- T1021responds — A.8.15's log analysis, anomaly detection, correlation, and explicit tie to feeding suspected incidents into the 5.25 incident management process enable response (containment/eradication) once remote-service logins via valid accounts are underway; partial because the control only surfaces the event and hands it off, with no containment/eradication actions inside A.8.15 itself, and because many T1021 sub-techniques (e.g., SaaS/IaaS federation, ARD abuse) leave limited or no detectable log footprint on the organization's estate.
- T1021.001detects — A.8.15 explicitly requires logging of successful/rejected access attempts, use of privileges, system activities, and log analysis (with SIEM/UEBA/IDS correlation and anomaly detection) that surfaces RDP logins by valid accounts as potential indicators of compromise or anomalous behavior.
- T1021.001prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour analysis (with time sync and integrity protection), which can surface or block unauthorized RDP logons before lateral movement succeeds; it does not stop the technique when valid credentials and an enabled RDP service are already present.
- T1021.001responds — A.8.15 requires log analysis and correlation (including of successful/failed access attempts, privilege use, and anomalous behaviour) to identify suspected incidents such as unauthorized RDP logons for further investigation under the incident management process; this is the core of `responds` once the technique is underway, but only a slice because the clause does not itself contain or eradicate the RDP session or actor foothold.
- T1021.002detects — A.8.15 explicitly requires logging, protection, and analysis of events including successful/rejected access attempts, use of privileges, file access/deletion, network activity, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces SMB admin share access (especially when paired with valid accounts or pass-the-hash) as an indicator of compromise.
- T1021.002prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes, and file access/deletion (including on network shares), plus analysis to surface anomalous behaviour; this can prevent the technique when it would be stopped by detection of the initial access or early lateral movement, but leaves the bulk of the technique (valid-account SMB/RPC execution, pass-the-hash variants, and post-access actions) untouched.
- T1021.002responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. anomalous access, privilege use, configuration changes) once the SMB share interaction is underway, feeding into incident response per 5.25, but does not itself contain or eradicate the active adversary session.
- T1021.003detects — A.8.15 explicitly requires logging, protection, and analysis of events including successful/rejected access attempts, privilege use, system configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces DCOM lateral movement (T1021.003) when it occurs.
- T1021.003prevents — A.8.15 mandates logging of access attempts, privilege use, configuration changes, and anomalous behaviour (with analysis via SIEM/UEBA), which can surface and deter some DCOM lateral movement by privileged accounts but does not stop the technique from running when valid credentials and ACLs permit it.
- T1021.003responds — A.8.15 requires log analysis, correlation, and identification of suspected incidents (including probing or anomalous remote access) to feed the incident management process (5.25), which directly enables containment/eradication once DCOM lateral movement is underway; partial because it only surfaces the event rather than performing the response actions.
- T1021.004detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, system activities, and log analysis (with SIEM/UEBA/correlation/threat intel) to identify anomalous behaviour and indicators of compromise such as unauthorized SSH logins by valid accounts.
- T1021.004prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour analysis (including SSH logins), which can surface misuse of valid accounts before further actions; this constrains the technique in monitored environments but does not stop the initial authorized SSH login itself.
- T1021.004responds — A.8.15 requires log analysis, correlation, anomaly detection (including successful access attempts, privilege use, configuration changes), and explicit routing of suspected incidents into the incident management process (5.25), which directly enacts containment/eradication once the SSH login technique is underway.
- T1021.005detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, system activities, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces VNC-based remote access and post-auth abuse as security events or indicators of compromise.
- T1021.005prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour (with analysis and correlation), which can surface and thereby deter some abuse of valid accounts over VNC but does not stop the technique from running.
- T1021.005responds — A.8.15 requires log analysis, anomaly detection, correlation, and identification of suspected incidents (including probing or unauthorized access) to feed the incident management process (5.25); this surfaces and enables response to VNC abuse by a valid account once underway, but the clause itself performs none of the containment/eradication steps that define the core of `responds` on the event lane.
- T1021.006detects — A.8.15 explicitly requires logging, protection, and analysis of events including successful/rejected access attempts, use of privileges, system activities, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces WinRM-based remote interaction by a valid account as an indicator of compromise.
- T1021.006prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, system changes, and anomalous behaviour (with analysis and correlation), which can prevent some abuse of valid accounts via WinRM by enabling detection and blocking before or during execution, but does not stop the technique itself from running when valid credentials are presented.
- T1021.006responds — A.8.15 requires log analysis, correlation, and identification of suspected incidents (including anomalous access and privilege use) to trigger further investigation under the incident management process, which directly enacts the `responds` verb once the WinRM technique is underway.
- T1021.007detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour analysis (SIEM/UEBA/threat intel/correlation), which surfaces T1021.007 logins and post-auth actions in cloud environments; the named remainder is fully stealthy or non-logged sessions outside the defined scope.
- T1021.007responds — A.8.15 requires log analysis (including correlation, UEBA, SIEM/IDS rules, and review of access attempts) to identify suspected incidents such as anomalous logins or probing, then routes them to incident management (5.25) for response once the technique is underway.
- T1021.008detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, system activities, configuration changes, and log analysis (with SIEM/UEBA/threat intel/correlation) that surfaces anomalous direct VM console logins as indicators of compromise or incidents.
- T1021.008prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes and anomalous behaviour (with analysis to surface indicators of compromise), which can prevent some abuse of valid accounts for direct cloud VM console access by enabling timely detection and response before pivoting; however, it does not stop the initial authentication or connection itself.
- T1025detects — A.8.15 requires log analysis and monitoring (including of file access, removable media via physical logs, anomalous behaviour, and correlation) that can surface the T1025 technique after it runs, but this is scoped by what the organization chooses to log/monitor and does not guarantee detection of all instances (e.g. non-logged USB activity or unmonitored physical access).
- T1027detects — A.8.15 mandates log analysis (including UEBA, SIEM rules, anomaly detection, DNS logs, and correlation) that can surface indicators of obfuscation such as anomalous file activity or encoded payloads, but this is scoped by what the organization chooses to log/monitor and does not inherently catch all obfuscation variants (e.g., in-transit, command obfuscation, or split benign files).
- T1027.001detects — A.8.15 requires log analysis and monitoring for anomalous behaviour, indicators of compromise, and unusual activity (including via SIEM, UEBA, trend/pattern analysis and threat intel), which can surface binary padding as an IOC when it produces observable anomalies such as oversized files or checksum mismatches in collected logs; this is a genuine but minority slice of the technique's evasion surface.
- T1027.002detects — A.8.15 requires log analysis (with SIEM/IDS/UEBA/threat intel) and specific monitoring to surface anomalous behaviour and indicators of compromise, which can catch many packing artifacts or post-unpacking execution; it does not guarantee detection of novel/custom packers that leave no observable artifacts in the listed events.
- T1027.003detects — A.8.15 requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and review of events (including file access, system changes, network activity, and physical logs) that can surface steganography indicators such as unusual image exfiltration or anomalous behavior, but does not guarantee detection of the hidden payload itself or cover all stego techniques.
- T1027.004detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including via SIEM/UEBA/threat intel), which can surface the use of native compilers or unusual compilation activity after delivery; this is a genuine but minority slice of the technique, as most instances occur without producing detectable log events or anomalous patterns that analysis would reliably flag.
- T1027.005detects — A.8.15 requires log analysis and monitoring to identify indicators of compromise, anomalous behaviour, malware infection and probing, which surfaces many (but not all) cases of an adversary removing indicators from a tool after detection/quarantine
- T1027.006detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, unusual activity (including via SIEM/IDS/UEBA rules, DNS logs, and correlation), which surfaces HTML smuggling as a delivery vector when it triggers logged events or anomalies; this is genuine but only a slice because the technique is designed to produce benign-looking MIME content that evades filters and many standard log patterns.
- T1027.007detects — A.8.15 mandates log analysis, SIEM/IDS rules, UEBA, anomaly detection on events (including process/file activity and privilege use) plus correlation to surface indicators of compromise; this surfaces some in-flight or post-execution artifacts of dynamic API resolution on Windows but leaves large slices (purely in-memory resolution with no observable call, no anomalous pattern, or no matching rule) unreached.
- T1027.008detects — A.8.15 requires log analysis and monitoring (SIEM/IDS/UEBA/threat intel/anomaly detection) that can surface stripped payloads as unusual/malicious binaries or anomalous behavior during incident analysis, but this is indirect, depends on other tools, and leaves many stripped payloads undetected until later stages.
- T1027.009detects — A.8.15 requires log analysis and monitoring (SIEM/UEBA/IDS rules, anomalous behaviour detection, correlation of access/config/privilege events) that can surface embedded-payload indicators once they trigger observable events, but the control does not mandate detection of the embedding act itself or of payloads that never reach a logged event.
- T1027.010detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including command-line and system activities), and identification of indicators of compromise such as probing or malware that can surface obfuscated commands in logs.
- T1027.010responds — A.8.15 requires log analysis and correlation (including UEBA, SIEM/IDS rules, anomalous behaviour detection, and physical logs) to identify suspected incidents such as probing or malware once they are underway, which matches the `responds` verb; it is only partial because the control stops at detection/analysis and hands off to incident handling (5.25) rather than performing containment/eradication itself.
- T1027.011detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of event logs (including successful/rejected access, privilege use, configuration changes, and alarms), and identification of indicators of compromise such as malware or probing, which surfaces fileless storage artifacts in Windows event logs, Registry-linked WMI repositories, and Linux shared-memory activity when those events are logged.
- T1027.011responds — A.8.15's log analysis and monitoring explicitly target anomalous behaviour and indicators of compromise (including in event logs themselves), enabling response once fileless storage activity is underway; this is bounded to detectable slices rather than all obfuscated or non-log forms.
- T1027.012detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, unusual activity in logs (including file access, system activities, and external connections), and correlation with threat intelligence, which surfaces LNK icon smuggling when it triggers observable events such as malicious downloads or execution; however, the technique can occur entirely in benign-looking local LNK metadata with no guaranteed log artifact, especially pre-compromise or without specific SIEM/UEBA rules.
- T1027.013detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of events such as file access/deletion, configuration changes, and privilege use that can surface indicators of obfuscated malicious files (e.g. anomalous payloads or logs), but does not guarantee detection of the obfuscation itself or cover all file artifacts.
- T1027.014detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and correlation of events (including malware signatures and indicators of compromise) which surfaces polymorphic malware in flight or post-execution; it is limited to a slice because polymorphic code is designed to evade signature-based and many behavioral detections, leaving substantial residue outside monitored scopes or novel mutations.
- T1027.015detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/patterns/threat intel, and monitoring of file access/deletion, system activities, and suspicious events that can surface compressed or concatenated archives used for obfuscation or delivery.
- T1027.016detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including via UEBA, SIEM, IDS signatures, and correlation), which can surface the presence or effects of junk-code-obfuscated malware; this is a genuine but minority slice because the control does not specifically target or reliably identify the obfuscation technique itself.
- T1027.017detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules, correlation of logs (including from web/file/DNS/physical sources), and identification of indicators like probing or malware that can surface SVG smuggling when the technique produces observable events in those monitored channels; it does not guarantee coverage of all delivery vectors or silent SVG-embedded payloads.
- T1027.018detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspicious events (including via SIEM, UEBA, pattern analysis and correlation), which can surface the presence of invisible Unicode in files/scripts as part of broader anomaly or IOC detection; it does not specifically target or guarantee detection of this Unicode abuse technique.
- T1029detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/pattern analysis, correlation of logs (including network activity and timing), and identification of indicators of compromise or unusual behavior, which surfaces scheduled exfiltration blending with normal traffic patterns.
- T1030detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, DNS log review for malicious outbound connections, and correlation of logs (including network activity) to identify indicators of compromise; this surfaces the technique when chunked transfers deviate from known patterns, but only where such monitoring is scoped in and the evasion does not fully mimic normal traffic.
- T1033detects — A.8.15 explicitly requires logging of user/session events (logons, privileges, identities, system activities), synchronized time sources, and log analysis (including UEBA, SIEM/IDS rules, anomalous behaviour detection, and correlation) that surfaces T1033 artifacts such as whoami/w/who output, running process ownership, or active sessions as indicators of compromise.
- T1036detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts, configuration changes, privilege use, and process activity — all of which surface masquerading artifacts (renamed binaries, spoofed metadata, fake service names) once they execute and generate observable events.
- T1036responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation) can surface masquerading once underway as an indicator of compromise, enabling incident response, but this is a minority slice of the broad technique (many masquerading variants leave no detectable log artifact).
- T1036.001detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, unusual activity (including via SIEM, UEBA, trend/pattern analysis and threat intelligence), plus correlation of logs across systems; this surfaces the use of invalid/mimicked code signatures when they trigger events, alarms, or deviate from known patterns.
- T1036.002detects — A.8.15 explicitly requires log analysis and monitoring for anomalous behaviour, indicators of compromise, and correlation of events (including file access, system activities, and unusual patterns via UEBA/SIEM), which surfaces disguised filenames or RTLO abuse when it appears in logged events, but this depends on whether the specific anomalous display or file metadata is within the chosen scope of logging and analysis rules.
- T1036.003detects — A.8.15 explicitly requires logging of utility-program use, privilege use, process/file activity and anomalous behaviour, plus SIEM/UEBA/correlation analysis that surfaces renamed binaries masquerading as legitimate utilities (the exact T1036.003 evasion); the named remainder is fully stealthy renames that produce no observable deviation from baseline.
- T1036.003responds — A.8.15's log analysis and monitoring explicitly surface renamed-utility anomalies (via UEBA, pattern/trend analysis, correlation, and review of access/execution events) once the technique has run, feeding into incident handling; this is genuine response but only a slice, as the clause does not itself contain/eradicate the actor or artifact.
- T1036.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including process/task/service activity, privilege use, configuration changes), and identification of indicators of compromise, which surfaces masquerading of tasks/services when they deviate from known benign patterns.
- T1036.005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/pattern matching, correlation of events (including file access, privilege use, configuration changes, and creation of identities/resources), and identification of indicators of compromise, which surfaces most instances of masquerading via legitimate-looking names/locations after the fact.
- T1036.006detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including via UEBA, SIEM, and correlation of file-access, privilege-use, and process events), which can surface the suspicious double-click/execution of a disguised file, but does not guarantee detection of this specific macOS/Linux filename trick.
- T1036.007detects — A.8.15 explicitly requires log analysis and monitoring of events (including file access, resource access attempts, alarms, anomalous behaviour via UEBA/SIEM/IDS, and correlation with physical logs) that can surface double-extension masquerading when it triggers observable indicators, but this is limited to post-execution or specific monitored contexts rather than universal detection of the filename technique itself.
- T1036.008detects — A.8.15 explicitly requires logging of file accesses/deletions, privilege use, configuration changes, and anomalous behaviour via log analysis (SIEM/UEBA/patterns/threat intel), which surfaces masquerading artifacts (e.g. mismatched signatures/extensions, polyglots) post-placement as indicators of compromise.
- T1036.009detects — A.8.15 explicitly requires log analysis and monitoring of system activities, process-related events (use of privileges, utility programs, file access, alarms), anomalous behaviour via UEBA/trend analysis/correlation, and inclusion of physical monitoring to surface indicators of compromise such as unusual process tree patterns after the double-fork or daemon techniques run.
- T1036.010detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, unusual account creation/renaming patterns, and correlation of events (including identity creation and privilege use), which surfaces T1036.010 post-execution; the named remainder is stealthy or non-logged masquerading outside monitored scope.
- T1036.010responds — A.8.15 requires log analysis and correlation (including of account creation, privilege use, identity changes, and anomalous patterns) to identify suspected incidents once underway for further investigation under incident management; this is the core of `responds` but only a slice because the control stops at detection/analysis and does not itself perform containment or eradication.
- T1036.011detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including via UEBA, SIEM, process activity patterns, and correlation of logs such as command-line arguments visible in /proc/<PID>/cmdline or ps output), which surfaces the in-memory argument overwrite once it has occurred.
- T1036.012detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/pattern analysis, and monitoring of network traffic, DNS logs, and access attempts that surface spoofed or anomalous browser fingerprints and crafted User-Agent strings as indicators of compromise.
- T1037detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of boot/logon events, and review of successful/failed access and privilege-use logs, which surfaces T1037 execution or its persistence artifacts after the fact.
- T1037.001detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, system configuration changes, and log analysis (with SIEM/UEBA/threat intel) that surfaces anomalous logon behavior and indicators of compromise such as unexpected logon scripts.
- T1037.002detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, identity creation/modification, and log analysis (including SIEM/UEBA rules, anomalous patterns, and correlation) that surfaces login-hook plist modifications or root-privilege script execution as indicators of compromise.
- T1037.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of events (including logon, privilege use, script/application execution, and configuration changes), and identification of indicators of compromise, which surfaces the execution of a network logon script for persistence.
- T1037.004detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, file accesses/deletions, security system activation, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces RC script modification (a privileged config change) and its post-reboot effects as indicators of compromise.
- T1037.005detects — A.8.15 explicitly requires logging of boot-time events (system activities, privilege use, configuration changes, startup of security systems), log analysis with UEBA/SIEM/IDS rules to surface anomalous behaviour, and correlation of logs (including physical) to identify indicators of compromise such as unauthorized persistence mechanisms.
- T1039detects — A.8.15 explicitly requires logging and analysis of file/resource access attempts (including on network shares), privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation to surface indicators of compromise such as unusual data collection from shared drives.
- T1040detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, threat intel correlation, and specific monitoring (DNS logs for C2, physical logs, access attempts) to surface anomalous behaviour and indicators of compromise that include network sniffing and its artifacts.
- T1041detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of network activity (including DNS and outbound connections to malicious C2 servers) to surface indicators of compromise such as exfiltration over an existing channel.
- T1041responds — A.8.15 requires log analysis, monitoring for anomalous behaviour (including outbound C2 connections via DNS logs and UEBA), correlation, and identification of suspected incidents for further investigation under the incident management process, which directly enacts the `responds` verb once exfiltration is underway.
- T1046detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of network activity (including DNS logs for outbound C2, access attempts, and correlation) that surfaces the scanning/probing behavior described in T1046.
- T1046prevents — A.8.15 mandates logging of access attempts, privilege use, configuration changes, alarms from access-control/IDS systems, and anomalous behaviour analysis (including network patterns and threat intel), which can prevent some discovery techniques (e.g. noisy port scans triggering logged alarms or UEBA) but leaves the bulk of stealthy/local/Bonjour/mDNS/cloud methods untouched.
- T1046responds — A.8.15 requires log analysis and correlation (including of network, DNS, firewall, IDS, and physical events) to identify anomalous behaviour such as probing or scanning that can represent indicators of compromise, then routes suspected incidents to the incident management process (5.25) for response once underway; this matches the `responds` verb but is only a slice because the control is silent on containment/eradication actions themselves and many T1046 instances (e.g. local Bonjour/mDNS queries or unmonitored cloud port scans) fall outside the prescribed logging/analysis scope.
- T1047detects — A.8.15 explicitly requires logging of system activities, privilege use, process/application execution, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces WMI abuse (local/remote execution, wmic/PowerShell/COM) as an information security event or indicator of compromise.
- T1047responds — A.8.15 requires log analysis, anomaly detection, correlation, and identification of suspected incidents (including via SIEM/IDS rules and UEBA) that can surface WMI abuse in flight for further investigation under the incident management process, but does not itself contain or eradicate the actor's foothold or the technique once underway.
- T1048detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of logs (including network activity, DNS, file access, and outbound connections to malicious servers), and identification of indicators of compromise such as probing or unusual data transfers, which surfaces most instances of T1048 exfiltration over alternate protocols.
- T1048responds — A.8.15's log analysis, correlation, anomalous-behaviour detection and explicit tie to the incident-management process (5.25) let responders contain/eradicate an exfiltration event once underway, but only for the subset of T1048 activity that produces observable logs (most alternate-protocol exfil is designed to blend with or avoid logging, and the control itself does not act on the exfiltration channel or remove the actor's foothold).
- T1048.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/threat intel, correlation of logs (including network activity, DNS, and outbound connections to malicious servers), and identification of indicators of compromise such as probing or unusual data flows, which surfaces symmetric-encrypted exfiltration when it produces observable network or application events.
- T1048.001responds — A.8.15's log analysis, correlation, and identification of anomalous events (including outbound connections and unusual network activity) surfaces suspected exfiltration in flight for further incident response per 5.25, but does not itself contain or eradicate the ongoing technique.
- T1048.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of logs (including network events, DNS, and physical), and identification of indicators of compromise such as probing or outbound connections to malicious servers, which surfaces exfiltration over asymmetric encrypted protocols like HTTPS/TLS when it generates observable events.
- T1048.002responds — A.8.15 requires log analysis and correlation (including network/DNS/UEBA patterns and physical events) to identify suspected incidents such as probing or exfiltration, then feeds them into the incident management process (5.25) for response; this acts once the technique is underway but only on detectable slices, leaving encrypted non-C2 flows without clear indicators or physical correlation as a remainder.
- T1048.003detects — A.8.15 explicitly requires logging, protection, and analysis of network events, DNS logs, anomalous outbound connections, and correlation to identify indicators of compromise such as data exfiltration over unencrypted protocols (HTTP/FTP/DNS).
- T1048.003responds — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and incident identification explicitly surface and feed suspected exfiltration events (including over unencrypted protocols) into the incident management process (5.25) for response once underway.
- T1049detects — A.8.15 explicitly requires logging of network-related events (system activities, network addresses/protocols, resource access attempts, alarms from access control/IDS, physical monitoring) plus mandated analysis/SIEM/UEBA/correlation to surface anomalous behaviour and indicators of compromise such as discovery commands (netstat, lsof, who, show ip sockets, etc.) once they execute.
- T1049responds — A.8.15 requires log analysis and correlation (including of network, access, and anomalous events) to identify suspected incidents such as probing, which can surface T1049 in flight for further investigation under incident management, but does not contain/eradicate the running discovery action itself.
- T1052detects — A.8.15 explicitly requires logging and analysis of physical access events, device identities, successful/failed resource access attempts, and correlation with physical monitoring logs to surface anomalous behaviour that can represent indicators of compromise, which would surface T1052 use of removable media in many (but not all) cases.
- T1052.001detects — A.8.15 explicitly requires logging and analysis of events including USB/physical device access, file access/deletion, successful/failed resource attempts, and correlation with physical monitoring to surface anomalous exfiltration indicators; this is genuine detection but only a slice because it depends on what the organization chooses to log/analyze and does not mandate coverage of all USB exfil vectors or real-time detection.
- T1053detects — A.8.15 explicitly requires logging, protection, and analysis of events including use of privileges, system activities, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces scheduled task abuse both in creation and execution on covered platforms.
- T1053responds — A.8.15 requires log analysis and correlation (including of privilege use, config changes, scheduled tasks via system activities and alarms) to identify and investigate suspected incidents once underway, which is the core of `responds`; it is only partial because the clause stops at detection/analysis hand-off to incident management (5.25) and does not itself perform containment or eradication.
- T1053.002detects — A.8.15 explicitly requires logging of privilege use, system activities, scheduled-task-like events, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces at/abuse of the scheduler both in real time and during investigation.
- T1053.002prevents — A.8.15 mandates logging of privilege use, system activities, configuration changes, and access attempts (including those tied to at/scheduled jobs), plus analysis for anomalous behaviour; this surfaces the technique after it runs but does not stop adversaries from invoking at for persistence/execution/escalation.
- T1053.002responds — A.8.15 requires log analysis, anomaly detection, correlation, and feeding suspected incidents (e.g. via alarms, privilege use, configuration changes, or scheduled-task-like events) into the incident management process (5.25), which performs containment/eradication once the technique is underway; this is genuine but only a slice because the control's logging/analysis surface does not observably engage every at-abuse vector (e.g. silent local escalation or non-logged startup tasks).
- T1053.003detects — A.8.15 explicitly requires logging of privilege use, system activities, configuration changes, scheduled tasks via utilities, and log analysis (with SIEM/UEBA/correlation) that surfaces anomalous scheduled execution as an indicator of compromise.
- T1053.005detects — A.8.15 explicitly requires logging and analysis of events including use of privileges, system activities, configuration changes, application transactions, anomalous behaviour via SIEM/UEBA/IDS rules, and correlation of logs (including physical), which surfaces scheduled task abuse for persistence, execution, or hiding as an information security event or indicator of compromise.
- T1053.005prevents — A.8.15 mandates logging of privilege use, system configuration changes, access attempts, and anomalous behaviour (with SIEM/UEBA correlation), which can block many abuse paths for task creation/execution by surfacing them before or during persistence/lateral movement; it does not stop the scheduler APIs or hidden-task techniques themselves.
- T1053.005responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. anomalous scheduled-task creation/use via reviewed access attempts, privilege use, configuration changes, alarms) for further investigation under incident management, but this is after the technique has run and only for the detectable non-hidden slice
- T1053.006detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, file access/deletion, security system activation, identity creation/modification, and anomalous behaviour via log analysis (SIEM/UEBA/IDS rules, correlation, trend analysis), which surfaces systemd timer installation and activation as suspicious scheduled/persistence activity on Linux.
- T1053.007detects — A.8.15 explicitly requires logging, analysis, and monitoring of events including system activities, privilege use, configuration changes, scheduled tasks/utility programs, anomalous behaviour via SIEM/UEBA/IDS rules, and correlation of logs (with time sync) to identify indicators of compromise such as malware or probing; this surfaces T1053.007 abuse of container orchestration jobs in monitored environments, though coverage depends on whether the specific container events fall inside the organization's defined logging scope.
- T1053.007responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. anomalous behaviour, malware, probing) for further investigation under incident management (5.25), which is the core of `responds`; it does not itself contain/eradicate the running job or its persistence.
- T1055detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, correlation, and monitoring of access attempts, privilege use, system changes, alarms, and physical events — all of which surface process injection in flight as anomalous behavior or an indicator of compromise, with the bounded remainder being injections into unmonitored processes or those that produce no observable events.
- T1055responds — A.8.15 requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and explicit identification of suspected incidents (e.g. probing or malware) for further investigation under the incident management process, which directly enacts the containment/eradication acts that `responds` names once the technique is underway.
- T1055.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of events (including process, privilege-use, system-activity and access logs), and identification of indicators of compromise such as malware or probing, which surfaces in-process DLL injection when the observable artifacts fall inside the monitored scope.
- T1055.001responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS correlation, and explicit tie-in to incident identification/investigation (5.25) enable containment and eradication once DLL injection is underway, with the named remainder being the pre-detection impact already realized.
- T1055.002detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, threat intel correlation, and specific monitoring of access attempts, alarms, privilege use, process activities, and anomalous behaviour — all of which surface PE injection in flight as an information security event or indicator of compromise.
- T1055.002responds — A.8.15 requires log analysis, monitoring for anomalous behaviour, correlation, and identification of suspected incidents (including via SIEM/IDS/UEBA) which can surface PE injection once underway as part of incident handling, but this is after-the-fact knowledge with no containment/eradication act asserted by the control itself.
- T1055.003detects — A.8.15 explicitly requires logging of process/thread activities, privilege use, system changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces Thread Execution Hijacking indicators (suspicious SuspendThread/WriteProcessMemory/SetThreadContext sequences under a legitimate process) post-execution.
- T1055.003responds — A.8.15 requires log analysis, anomaly detection, correlation, and identification of suspected incidents (including via SIEM/IDS/UEBA) which surfaces Thread Execution Hijacking once underway for further investigation under the incident management process; this is the core of `responds` with a bounded remainder for stealthy in-memory cases that produce no observable events.
- T1055.004detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection on process behavior, privilege use, system activities, and correlation to surface indicators of compromise such as APC injection masked under legitimate processes.
- T1055.004responds — A.8.15's log analysis, monitoring of access attempts/privileges/security systems, anomaly detection via SIEM/UEBA/IDS correlation, and explicit tie to incident management (5.25) enable containment/eradication once APC injection is underway as an observable event.
- T1055.005detects — A.8.15 explicitly requires logging, protection, and analysis of events including system activities, privilege use, process/resource access attempts, alarms from access control/IDS, anomalous behaviour via SIEM/UEBA/correlation, and indicators of compromise such as malware or probing, which surfaces TLS callback injection in flight as anomalous execution under a legitimate process.
- T1055.005responds — A.8.15's log analysis, correlation, SIEM/IDS/UEBA rules, and incident identification explicitly surface in-flight anomalous behaviour (including process-injection artifacts) for further investigation under the incident management process, which is the core of `responds`; it is only partial because the clause sets requirements for what is logged/analysed rather than mandating universal detection of every TLS-callback manipulation.
- T1055.008detects — A.8.15 explicitly requires logging of system activities, privilege use, process-relevant events, alarms from access-control/IDS systems, and log analysis (with UEBA, SIEM, IDS signatures, anomalous behaviour detection, and correlation) that surfaces ptrace-based injection as an indicator of compromise or anomalous process modification.
- T1055.008responds — A.8.15 requires log analysis, anomaly detection, correlation, and identification of suspected incidents (including probing or malware-like behavior) to feed the incident management process (5.25), which directly enacts the containment/eradication act that `responds` names once the ptrace injection is underway.
- T1055.009detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection on process/activity events, correlation across logs (including system, privilege use, and security-system activation), and identification of indicators of compromise such as probing or anomalous behaviour, which surfaces proc-memory injection in flight on Linux systems where those events are logged.
- T1055.011detects — A.8.15 explicitly requires logging of security-relevant events (privilege use, system activities, process anomalies via SIEM/IDS/UEBA rules and monitoring of access attempts), analysis to surface indicators of compromise, and correlation that would flag EWM injection as anomalous behavior under a legitimate process, though some stealthy in-memory variants may evade basic log sources.
- T1055.011responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS correlation, and incident identification explicitly surface EWM injection once underway (as process anomalies or indicators of compromise), triggering the incident management process that contains and eradicates it.
- T1055.012detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, correlation of events (including process creation, privilege use, system activities, and security system activation/deactivation), and identification of indicators of compromise such as malware or probing, which surfaces process hollowing in flight as anomalous behavior under a legitimate process.
- T1055.012responds — A.8.15's log analysis, monitoring, and incident identification explicitly surface hollowing indicators (anomalous process behavior, memory changes, privilege use, alarms) once underway for further investigation under incident management, but this is limited to observable events rather than containment/eradication of the in-flight technique itself.
- T1055.013detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and security events (including via SIEM, UEBA, correlation, and review of system activities, process creation, privilege use, and file operations), which surfaces in-process execution anomalies like doppelgänging even though the technique itself is fileless and avoids certain monitored APIs.
- T1055.013responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification directly support responding to an in-flight doppelganging execution once it produces observable events, but the control stops at detection/analysis and hands off to 5.25 incident handling rather than performing containment/eradication itself.
- T1055.014detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of events (including process, system, privilege-use and library-loading activity), and identification of indicators of compromise such as malware or probing, which surfaces VDSO hijacking in a live process; the bounded remainder is fully in-memory hijacks that produce no observable log events before execution.
- T1055.015detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, anomaly detection, correlation of logs (including process, access, and security-system events), and identification of indicators of compromise such as malware or probing, which surfaces ListPlanting execution in a hijacked process; the bounded remainder is fully in-memory variations that produce no observable log artifact at all.
- T1055.015responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification explicitly surface ListPlanting once it runs inside a legitimate process (via unusual list-view messages, callback execution, or behavioral deviations), feeding the 5.25 incident process for containment/eradication; the named remainder is fully in-memory variants that produce no observable log events at all.
- T1056detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, privilege use, configuration changes, and physical events to surface indicators of compromise such as input-capture malware or anomalous credential prompts.
- T1056.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, configuration changes, privilege use, and security system events, which surfaces keylogging behaviors (API hooks, driver installs, registry mods, anomalous input patterns) in most cases once they generate observable events.
- T1056.002detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including via SIEM, UEBA, correlation, and review of access attempts, privilege use, and application activity), which surfaces GUI input capture prompts that mimic legitimate credential dialogs on Linux/macOS/Windows.
- T1056.003detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the web portal credential-capture technique (or its indicators) once installed and active.
- T1056.003responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. anomalous login activity or probing) once underway and feed them into the incident management process (5.25), which is the core of `responds`; it does not contain/eradicate the already-installed capture code itself.
- T1056.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of events (including process/activity/use-of-privileges and security-system alarms), and identification of indicators of compromise such as malware or probing, which surfaces credential API hooking when it triggers observable events or anomalous behavior on monitored systems.
- T1057detects — A.8.15 explicitly requires logging of process-related events (use of utilities/applications, system activities, privilege use), log analysis with UEBA/SIEM/IDS rules to surface anomalous behaviour, and correlation of those logs to identify indicators of compromise such as process enumeration commands.
- T1057responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of process-related events such as privilege use or system activities) surface an in-progress Process Discovery technique once it runs, enabling identification as part of incident response, but this is only a slice of the broad technique rather than containment/eradication itself.
- T1059detects — Logging of command interpreters, utility programs, and user transactions provides visibility into interactive or scripted adversary commands.
- T1059prevents — A.8.15 mandates logging of interpreter use, privilege use, system activities, configuration changes and anomalous behaviour, which (when reviewed) can stop many abuse paths before or during execution; it does not remove or disable the interpreters themselves, which remain available on every listed platform.
- T1059responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and explicit tie to the 5.25 incident management process let responders contain/eradicate an in-flight interpreter abuse once it is logged and flagged, but the control itself performs none of the containment or eradication actions and many T1059 executions (especially non-interactive or short-lived) produce no observable event for response.
- T1059.001detects — A.8.15 explicitly requires logging of system activities, privilege use, command/script interpreter execution (via utility programs and application transactions), successful/rejected access attempts, and subsequent log analysis with SIEM/UEBA/threat-intel rules to surface anomalous behaviour and indicators of compromise such as PowerShell abuse.
- T1059.001responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. anomalous behaviour, malware, probing) for further investigation under incident management (5.25), which matches the `responds` verb once a T1059.001 execution event is underway; extent is partial because the clause sets requirements for what to log/analyse rather than mandating detection of every in-memory or non-powershell.exe invocation of the technique.
- T1059.002detects — A.8.15 explicitly requires logging of system activities, privilege use, command-line/script execution, application interactions, anomalous behaviour via SIEM/UEBA/IDS correlation, and analysis of events (including outbound connections and unusual patterns) that would surface AppleScript abuse such as osascript invocation, NSAppleScript calls, or scripted behaviors on macOS.
- T1059.003detects — A.8.15 explicitly requires logging of command/shell use, privilege use, system activities, successful/rejected access attempts, and log analysis (with SIEM/UEBA/threat intel) to surface anomalous behaviour and indicators of compromise such as cmd.exe abuse for execution.
- T1059.003responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. anomalous commands, probing) once underway for further investigation under incident management, which is the core of `responds`; it is partial because the clause stops at detection/analysis and does not itself perform containment or eradication.
- T1059.004detects — A.8.15 explicitly requires logging of shell-relevant events (command execution, privilege use, system activities, script-like transactions), synchronized time sources, and SIEM/UEBA/log analysis to surface anomalous behaviour and indicators of compromise such as shell abuse.
- T1059.004responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including shell abuse via commands, privilege use, or scripts), then routes them to incident management (5.25) for response, but does not itself perform containment or eradication.
- T1059.005detects — A.8.15 explicitly requires logging of system activities, privilege use, application/script execution, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces VB/VBA/VBScript abuse (e.g. macro execution, suspicious scripts) as security events or indicators of compromise.
- T1059.006detects — A.8.15 explicitly requires logging and analysis of events including use of applications/utilities, system activities, privilege use, and anomalous behaviour via SIEM/UEBA/IDS correlation, which surfaces Python-based execution as an indicator of compromise.
- T1059.006responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. anomalous behaviour, malware, probing) for further investigation under the incident management process, which is the core of `responds`; it does not itself contain or eradicate the Python execution once underway.
- T1059.007detects — A.8.15 explicitly requires logging of system activities, privilege use, application/script execution, successful/rejected access attempts, and anomalous behaviour via log analysis, SIEM, UEBA, and correlation, which surfaces JavaScript abuse (e.g. osascript, JScript, or script payloads) in most cases once it executes.
- T1059.007responds — A.8.15 requires log analysis, anomaly detection, correlation, and explicit identification of suspected incidents (e.g. malware or probing) for further investigation under the incident management process, which directly enacts the containment/eradication actions that `responds` names once the JS execution technique is underway.
- T1059.008detects — A.8.15 explicitly requires logging of CLI-relevant events (use of privileges, system activities, configuration changes, successful/rejected access attempts), synchronized time sources, and log analysis (including UEBA, SIEM/IDS rules, anomalous behaviour detection, and correlation) that surfaces abuse of network device CLI as an indicator of compromise.
- T1059.008prevents — A.8.15 mandates logging of CLI-relevant events (privilege use, config changes, access attempts, security system activation) plus protection against log tampering or disabling, which constrains the 'disable logging to avoid detection' and some configuration-abuse slices of T1059.008 but does not stop adversaries from executing arbitrary CLI commands or scripts on the device.
- T1059.008responds — A.8.15's log analysis, anomaly detection, correlation, and explicit tie to feeding the incident management process (5.25) directly enable containment/eradication once CLI abuse is underway on a network device.
- T1059.009detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, privilege use, configuration changes, and cloud-relevant events that surface abuse of cloud APIs when they occur.
- T1059.009prevents — A.8.15 mandates logging of access attempts, privilege use, configuration changes, and anomalous API-driven behaviour (via SIEM/UEBA rules and correlation), which can block many abuse paths before execution; it does not stop an already-authorized call.
- T1059.009responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomaly detection, correlation, incident identification) surface and feed into response once cloud API abuse is underway, but the clause itself performs no containment or eradication.
- T1059.010detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, application/script execution, anomalous behaviour via SIEM/UEBA/pattern analysis, and correlation of events (including successful/failed access and process-like actions), which surfaces AHK/AutoIT script or compiled execution as an indicator of compromise on Windows.
- T1059.011detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/rules, correlation, and review of events including script/utility use, system access, and configuration changes — all of which surface Lua-based execution as anomalous behavior or an indicator of compromise.
- T1059.012detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA patterns, correlation, and monitoring of events including system activities, privilege use, configuration changes, and security system activation — which surfaces hypervisor CLI abuse on ESXi as anomalous behavior or an indicator of compromise, but only where such logs are collected, analyzed, and in scope.
- T1059.013detects — A.8.15 explicitly requires logging, protection, and analysis of events including system activities, privilege use, configuration changes, resource access, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces T1059.013 CLI/API abuse in container environments as part of identifying security events and indicators of compromise.
- T1068detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, access attempts, alarms from access control/IDS, and log analysis (with SIEM/UEBA/IDS rules, anomaly detection, and correlation) that surfaces indicators of exploitation leading to privilege escalation.
- T1068responds — A.8.15's log analysis, anomaly detection, correlation, and identification of suspected incidents (e.g. via alarms, privilege use, config changes) enable response once T1068 exploitation is underway, but this is limited to detection feeding incident handling rather than direct containment/eradication actions.
- T1069detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/rules, correlation, and review of access attempts/privilege use/configuration changes to surface indicators of compromise such as permission-group discovery activity.
- T1069.001detects — A.8.15 explicitly requires logging of privilege use, system access attempts, configuration changes, and identity modifications, plus mandated analysis (SIEM/UEBA/rules/threat intel/correlation) that surfaces anomalous enumeration of local groups and permission settings; the bounded remainder is stealthy in-memory or non-logged discovery that evades the defined event set.
- T1069.002detects — A.8.15 explicitly requires logging and analysis of events including successful/rejected access attempts, privilege use, configuration changes, identity creation/modification/deletion, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the reconnaissance commands and their outputs as indicators of compromise
- T1069.003detects — A.8.15 explicitly requires logging of privilege use, access attempts, configuration changes, identity creation/modification/deletion, and log analysis (with SIEM/UEBA/threat-intel correlation) that surfaces anomalous permission-group enumeration by an authenticated adversary; the named remainder is activity that evades the chosen log sources or analysis rules.
- T1070prevents — Centralized, tamper-protected logs make it harder for an adversary to erase or alter evidence of their actions across multiple event types.
- T1070detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation, and review of access attempts, configuration changes, privilege use, and other events that directly surface selective log modification or deletion attempts by an adversary.
- T1070responds — A.8.15's protection of logs (prevent deletion/alteration by users including privileged ones, append-only/read-only mechanisms, cryptographic hashing) and its explicit identification of suspected incidents for further investigation directly engages once T1070 has begun, containing the removal by preserving evidence and enabling response actions.
- T1070.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, configuration changes, privilege use, and security system events, which can surface command-history clearing as anomalous activity on covered platforms, but the control's scope is limited to what the organization chooses to log/analyze and does not guarantee coverage of every command-history file or technique variant (e.g., in-memory PowerShell Clear-History or network-device CLI clears).
- T1070.003prevents — A.8.15 requires logging of specific events including use of privileges, system activities, and file accesses/deletions, plus protection against log deletion or alteration (append-only, hashing, no self-deletion by privileged users); this directly stops many T1070.003 variants that target bash_history, shell.log, or ConsoleHost_history.txt, but leaves a bounded remainder for in-memory session-only histories, network-device CLI clears, and non-logged interpreters.
- T1070.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and review of file-access/deletion events plus physical logs to surface indicators of compromise such as post-intrusion cleanup.
- T1070.004responds — A.8.15 requires log analysis and correlation (including of file-access/deletion events and alarms) to identify and investigate suspected incidents once underway, which is the core of `responds`; it does not itself contain/eradicate the deletion or actor foothold.
- T1070.005detects — A.8.15 explicitly requires logging, analysis, and monitoring of system activities, privilege use, configuration changes, resource access attempts, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces the net use /delete command or related share-removal events after they occur.
- T1070.006detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/patterns/threat intel, correlation of events (including file access/deletion, privilege use, config changes), and review of logs to identify indicators of compromise such as timestomping that alters timestamps to blend with legitimate files.
- T1070.007detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including network and physical), and identification of suspected incidents such as probing, which surfaces the T1070.007 clearing activity when it touches logged artifacts or produces detectable anomalies.
- T1070.008detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including via SIEM, UEBA, DNS logs, usage reports, and correlation), which surfaces T1070.008 mailbox/mail-log clearing when it produces detectable artifacts in the required event types; it is only partial because the control's scope is limited to what the organization chooses to log/analyze and does not guarantee coverage of all adversary methods (e.g. silent API deletions with no logged event).
- T1070.008prevents — A.8.15's requirements to log specific events (including use of privileges, system configuration changes, and application transactions), protect logs against deletion/alteration by users (including via append-only mechanisms), and perform log analysis for anomalous activity directly stops many of the mailbox/mail-app data clearing actions described in T1070.008 from succeeding or from removing evidence; it does not reach every platform or every possible mailbox-export/deletion vector, leaving a genuine minority slice unreached.
- T1070.008responds — A.8.15 requires log analysis, anomaly detection, correlation, and identification of suspected incidents (including via SIEM/IDS/UEBA) to trigger further investigation under the incident management process; this surfaces and acts on realized T1070.008 mailbox-clearing events after they occur, but only for the subset that generates detectable log artifacts rather than all instances.
- T1070.009detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of events (including privilege use, account changes, configuration changes, file deletions, and security system activity) to surface indicators of compromise and suspected incidents, which directly catches most T1070.009 cleanup actions on covered platforms.
- T1070.009responds — A.8.15's log analysis, correlation, and identification of suspected incidents (including anomalous cleanup that could indicate prior persistence) supports detection and response once the T1070.009 technique has run, but the control's focus is on recording/analyzing events rather than active containment or eradication of the adversary's cleanup actions.
- T1070.010detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of events (including file access, creation/modification/deletion of identities, and privilege use), and identification of indicators of compromise such as malware infection, which surfaces relocated malware copies and related evasion artifacts after they occur.
- T1071detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log review for malicious C2, correlation of events, and identification of suspected incidents such as probing, which surfaces T1071 C2 blending in with legitimate application-layer traffic.
- T1071responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. probing of firewalls, anomalous outbound to C2, correlation for investigation) once T1071 C2 traffic is underway, feeding the incident management process, but this is only a slice of full response (containment/eradication) and does not address all protocol variants or non-log-visible cases.
- T1071.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log review for malicious C2, correlation of events, and identification of suspected incidents such as probing, all of which surface web-protocol C2 blending in with legitimate traffic.
- T1071.001responds — A.8.15 requires log analysis, anomaly detection via SIEM/IDS/UEBA/correlation, and feeding suspected incidents (e.g. probing, C2) into the 5.25 incident management process for containment/eradication once underway; this engages the core of `responds` for in-band web C2 but is only a slice because the control's mechanism is passive logging/analysis rather than active containment and many T1071.001 implementations (e.g. encrypted HTTPS blending, non-malicious-looking patterns) produce no detectable event.
- T1071.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of network activity (including DNS, outbound connections, and correlated logs) that surfaces the use of file-transfer protocols for C2 blending or data concealment.
- T1071.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and correlation of events (including network activity, DNS, and physical logs) to surface indicators of compromise such as anomalous outbound connections or unusual protocol behavior that would reveal hidden C2 in common mail protocols.
- T1071.003responds — A.8.15's log analysis, correlation, anomaly detection (including DNS, UEBA, SIEM/IDS rules) and incident identification can surface mail-protocol C2 once underway as part of response, but the control's core is logging/analysis rather than containment/eradication and many stealthy embeddings go unseen
- T1071.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log review for outbound connections to malicious C2 servers, and correlation to identify probing or indicators of compromise — directly surfacing DNS tunneling/beaconing that blends with normal traffic.
- T1071.004prevents — A.8.15 mandates logging of DNS-related events (outbound connections, anomalous patterns, SIEM/IDS rules) and analysis to identify indicators of compromise such as C2 beacons or tunneling, which can block the technique from proceeding undetected in monitored environments; however, it is a detection/logging practice that does not stop the adversary from initiating blended DNS traffic, especially infrequent or pre-authentication uses.
- T1071.004responds — A.8.15 requires log analysis (including DNS logs for outbound connections to malicious C2 servers) plus correlation and incident identification to respond to suspected events once underway; this directly engages the DNS-tunneling technique when observed in logs, but leaves the core containment/eradication steps to the separate incident-management process (5.25) and does not act on every variant (e.g., infrequent beacons or non-malicious-domain C2).
- T1071.005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of network traffic patterns (including outbound connections to malicious servers) to surface indicators of compromise; pub/sub C2 blends with normal broker traffic but is still observable in the mandated event logs, DNS checks, and correlation once the technique runs.
- T1071.005responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/correlation, and incident identification explicitly feed into the 5.25 incident management process that contains and eradicates an active pub/sub C2 channel once underway, but this is only a slice (monitoring/analysis handoff) while core containment/eradication lives in the separate incident response control.
- T1072detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, successful/rejected access attempts, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces abuse of centralized deployment tools (especially by privileged accounts) as indicators of compromise.
- T1072responds — A.8.15 requires log analysis (including SIEM/IDS/UEBA rules, anomaly detection, correlation, and review of access attempts, privilege use, configuration changes, and alarms) to identify suspected incidents such as probing or malware, which directly supports the incident management process (5.25) that contains and eradicates an in-progress T1072 abuse of deployment tools.
- T1074detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts, file activity, configuration changes and privilege use — all of which surface the file-copy, archive and staging behaviors named in T1074 after they occur.
- T1074responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/UEBA/threat intel) surface staging activity once underway as part of the incident management process, but this is only a slice of the technique's mechanics (local file ops, archiving, cloud instance staging) with no containment or eradication named in the control.
- T1074.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including file access, system activities, privilege use, and configuration changes), and identification of indicators of compromise, which surfaces local data staging activity in the great majority of cases.
- T1074.002detects — A.8.15 explicitly requires logging of access attempts, privilege use, file access/deletion, configuration changes and alarms plus mandated analysis (SIEM/UEBA/rules/threat intel/correlation) that surfaces anomalous staging activity on endpoints, networks and cloud instances; the named remainder is fully stealthy or off-scope activity that evades the chosen monitoring set.
- T1078detects — Detailed logging of successful and failed access attempts, privilege use, and identity changes enables detection of unauthorized account usage.
- T1078prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes, identity creation/deletion and anomalous behaviour (with analysis, correlation and alerting), which can prevent many T1078 abuse paths by enabling timely detection and response before persistence/escalation; it does not stop credential compromise or initial abuse itself.
- T1078responds — A.8.15 requires log analysis, anomaly detection via SIEM/UEBA/IDS, correlation, and explicit routing of suspected/actual incidents (including those using valid accounts) into the incident management process (5.25), which is exactly the containment/eradication act that `responds` names once the technique is underway.
- T1078.001detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, identity changes, configuration changes and anomalous behaviour via SIEM/UEBA/correlation, which surfaces default-account abuse (including post-creation vpxuser-style accounts) as an indicator of compromise; the named remainder is default accounts used only via stolen keys on unmonitored remote services or appliances outside the logged scope.
- T1078.001responds — A.8.15's log analysis, anomaly detection, correlation, and identification of suspected incidents (including via SIEM/IDS/UEBA) directly enable response once default-account abuse is underway, with the named remainder being incidents that produce no observable events in the logged set.
- T1078.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, privilege use, configuration changes and alarms — all of which surface domain-account abuse after it occurs.
- T1078.002prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, identity changes, and anomalous behaviour analysis (with time sync and integrity protection), which can surface and deter abuse of compromised domain accounts in many scenarios but does not stop credential compromise itself (e.g. via dumping or reuse) nor block all initial access/persistence paths.
- T1078.002responds — A.8.15 requires log analysis and correlation (including of access attempts, privilege use, configuration changes, and alarms) to identify suspected incidents such as probing or anomalous behaviour, then feeds them into the incident management process (5.25) for response; this acts once the domain-account abuse is already underway but only on the detectable subset that generates observable events, leaving credential theft via dumping/reuse that evades logging as a clear remainder.
- T1078.003detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, identity creation/modification/deletion, and log analysis (with SIEM/UEBA/threat intel/correlation) that surfaces anomalous behaviour and indicators of compromise from local account abuse.
- T1078.003responds — A.8.15 requires log analysis, anomaly detection, correlation and explicit identification of suspected incidents (e.g. probing, malware) for further investigation under the incident management process, which directly enacts the `responds` verb once the local-account abuse technique is underway.
- T1078.004detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, identity creation/modification, and log analysis (with SIEM/UEBA/IDS rules, anomaly detection, and correlation) that surfaces indicators of compromise from cloud-account abuse such as anomalous logons, privilege escalations, or lateral movement.
- T1078.004responds — A.8.15's log analysis, anomaly detection, and explicit tie to feeding suspected incidents into the 5.25 incident management process constitute a genuine response action once the T1078.004 account abuse is underway, but only for the subset of techniques whose artifacts appear in the listed events and logs; many stealthy or credential-only uses (e.g. pivoting via assumed roles or long-lived Additional Cloud Credentials) leave no observable event inside the clause's scope.
- T1080detects — A.8.15 explicitly requires logging and analysis of file access/deletion, configuration changes, privilege use, utility/app execution, alarms from access controls, and anomalous behaviour via SIEM/UEBA/correlation to identify indicators of compromise such as tainted shared content or directory-share pivots.
- T1080responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification directly support responding to (containing/eradicating) T1080 once the tainted content is accessed and executes, but the control stops at detection/analysis and hands off to 5.25 incident management without performing containment itself.
- T1082detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, configuration changes, and anomalous behaviour (including via SIEM/UEBA/correlation) to identify indicators of compromise such as reconnaissance commands that surface system information.
- T1083detects — A.8.15 explicitly requires logging and analysis of file-access events, privilege use, configuration changes, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces T1083 activity once it occurs.
- T1087detects — A.8.15 explicitly requires logging of account-related events (user IDs, successful/rejected access attempts, privilege use, identity creation/modification/deletion) plus analysis and correlation to identify anomalous behaviour and indicators of compromise such as account enumeration.
- T1087.001detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, account creation/modification/deletion, and log analysis (with SIEM/UEBA/correlation) to identify anomalous behaviour and indicators of compromise such as account enumeration commands.
- T1087.002detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, identity creation/modification/deletion, system configuration changes, and log analysis (with SIEM/UEBA/IDS rules, anomaly detection, and correlation) that surfaces domain account enumeration as anomalous behavior or an indicator of compromise.
- T1087.002prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, identity changes and configuration changes, which can be configured to log (and therefore block via policy+enforcement) many of the specific commands and tools used to enumerate domain accounts; this is a genuine but minority slice of the technique because the control does not reach all discovery vectors, all platforms, or all privilege levels, and the clause itself stops at recording rather than mandating enforcement.
- T1087.003detects — A.8.15 explicitly requires log analysis and monitoring of events (including successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation) to identify indicators of compromise such as account enumeration; this surfaces T1087.003 when it generates observable logs, with the bounded remainder being stealthy or non-logged executions.
- T1087.003prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes, and identity creation/modification, plus protected analysis to surface anomalous behavior; this directly stops the authenticated PowerShell or directory-enumeration technique in many cases by creating detectable evidence that feeds incident response, but leaves a remainder where the adversary holds sufficient privileges or the logging scope/monitoring is not configured to catch the specific query.
- T1087.004detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, identity creation/modification/deletion, configuration changes, and log analysis (with SIEM/UEBA/threat intel/correlation) that surfaces anomalous account enumeration activity, directly detecting the technique when it runs.
- T1090detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of network activity (including DNS logs for C2, correlating logs, and reviewing access attempts), which surfaces proxy-based C2 and traffic redirection as indicators of compromise.
- T1090.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of logs (including network activity, system access, configuration changes, and physical events), and identification of indicators of compromise such as probing or unusual outbound connections, which surfaces internal proxy usage for C2 redirection in most cases.
- T1090.001responds — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and incident identification explicitly surface and feed into the incident management process (5.25) once internal proxy C2 redirection is underway, but this is limited to observable network/DNS/physical events rather than all proxy behaviors (e.g., SMB p2p blending or host-level redirection).
- T1090.002detects — A.8.15 explicitly requires log analysis, anomalous behaviour detection via SIEM/IDS/UEBA/threat intel, DNS log checks for malicious C2, correlation of events, and identification of probing or indicators of compromise, which surfaces external proxy usage in most cases.
- T1090.002responds — A.8.15's log analysis, correlation, and identification of anomalous events (e.g. unusual outbound connections, probing) can surface and trigger response to an already-underway external proxy C2 channel, but only for the observable slice that produces detectable log artifacts rather than the full technique.
- T1090.003detects — A.8.15 explicitly requires log analysis, correlation, UEBA, SIEM/IDS rules, DNS log checks for malicious C2, and anomaly detection on network activity to surface indicators of compromise, which directly surfaces multi-hop proxy traffic (last-hop identification, anomalous routing, onion/P2P patterns) in most cases.
- T1090.004detects — A.8.15 explicitly requires log analysis and monitoring for anomalous behaviour, including DNS logs for outbound connections to malicious C2 servers, UEBA, trend/pattern analysis, and correlation of events; domain fronting produces observable anomalies in HTTPS/TLS traffic patterns, SNI/Host mismatches (where logged), or unusual CDN routing that can be surfaced by these mechanisms, but many implementations (and the clause's own scope) leave real gaps in deep TLS inspection or coverage of all fronted flows.
- T1091detects — A.8.15 explicitly requires logging of removable-media and device events (USB mounts, file access/deletion, alarms from access-control/IDS, physical monitoring), synchronized time sources, and log analysis with UEBA/SIEM/threat-intel to surface anomalous behaviour and indicators of compromise such as malware replication or autorun activity.
- T1092detects — A.8.15 explicitly requires logging, analysis, and correlation of events including system activities, privilege use, file access/deletion, configuration changes, and anomalous behaviour (with SIEM/UEBA/threat intel support), which surfaces the file drops, USB activity, and command relay patterns of T1092 after it runs.
- T1095detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS outbound checks for C2, correlation of events, and review of network activity patterns, which surfaces most non-application-layer C2 (ICMP, UDP, SOCKS, VMCI) once it generates observable events; the bounded remainder is traffic that produces no logs at all or occurs entirely outside monitored scope (e.g., pre-compromise VMCI inside the hypervisor).
- T1095responds — A.8.15's log analysis, correlation, anomalous-behaviour detection and explicit tie-in to the incident-management process (5.25) let responders see and act on non-application-layer C2 once it is underway, but the clause stops at identification and hands off to incident handling; it neither contains nor eradicates the technique itself.
- T1098detects — A.8.15 explicitly requires logging of account-related events (creation/modification/deletion of identities, privilege use, configuration changes, successful/rejected access) plus analysis to surface anomalous behaviour and indicators of compromise, which directly detects T1098 manipulations once performed.
- T1098prevents — A.8.15 mandates logging of account/identity creation/modification/deletion, privilege use, configuration changes and anomalous behaviour, which surfaces many T1098 actions in time for detection and response before persistence solidifies; it does not stop the manipulation itself once the adversary already holds the necessary permissions.
- T1098responds — A.8.15 requires log analysis and correlation (including of account/identity changes, privilege use, and anomalous behaviour) to identify suspected incidents for further investigation under the incident management process; this surfaces and feeds response once manipulation is underway, but only for the detectable subset of actions that generate observable logs rather than all manipulation techniques.
- T1098.001detects — A.8.15 explicitly requires log analysis and monitoring of events (including privilege use, configuration changes, identity creation/modification, and anomalous behaviour via SIEM/UEBA/threat intel) to identify indicators of compromise such as unauthorized credential additions, which surfaces the T1098.001 technique post-execution.
- T1098.002detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including privilege use, configuration changes, and mailbox-related events via SIEM/UEBA/correlation), which surfaces T1098.002 after it occurs; partial because the control's scope and detection efficacy depend on what is chosen for logging/analysis and many delegate-permission changes (especially in third-party cloud services) can be configured to evade or fall outside the monitored events.
- T1098.003detects — A.8.15 explicitly requires logging of privilege use, configuration changes, identity creation/modification/deletion, and anomalous behaviour via SIEM/UEBA/threat-intelligence-driven analysis, which surfaces the addition of cloud roles or IAM policy updates as an indicator of compromise.
- T1098.003prevents — A.8.15 mandates logging of privilege use, configuration changes, identity modifications, and access attempts plus protected immutable logs and analysis that can surface the role-addition activity before or while it occurs, thereby preventing the technique in monitored environments; however this is only a slice because the control does not enforce any preventive guardrails on the IAM/policy modification APIs themselves.
- T1098.004detects — A.8.15 explicitly requires logging of privilege use, configuration changes, file accesses/deletions, and anomalous behaviour via log analysis (SIEM/UEBA/IDS rules, correlation, trend analysis) which surfaces SSH authorized_keys modifications as indicators of compromise or privilege escalation.
- T1098.004prevents — A.8.15 mandates logging of privilege use, configuration changes, file accesses/deletions, and anomalous behaviour via analysis/SIEM/UEBA, which can surface unauthorized authorized_keys edits before persistence is fully leveraged, but does not stop the modification itself.
- T1098.004responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour (including privilege-use, config changes, and access attempts) that can represent indicators of compromise, and to feed suspected incidents into the incident-management process (5.25); this surfaces T1098.004 once it has run on covered platforms but does not contain or eradicate it, and physical/privileged-user log protections plus the clause's scope-setting nature leave a named remainder of unmodified or unmonitored authorized_keys files.
- T1098.005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of events (including successful/rejected access, privilege use, configuration changes, identity creation), and identification of suspected incidents such as probing — which surfaces device registration as anomalous MFA/device-management activity after it occurs.
- T1098.005prevents — A.8.15 mandates logging of device/identity creation, privilege use, configuration changes, and anomalous registration-like events plus analysis to surface indicators of compromise; this can stop the technique from completing or persisting when the registration is detected and investigated in time, but the control only records/analyzes rather than blocking enrollment at the MFA/Intune boundary, leaving the bulk of the technique (credentialed self-enrollment) unreached.
- T1098.006detects — A.8.15 explicitly requires logging of privilege use, role/identity changes, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the addition of roles or bindings after the fact.
- T1098.007detects — A.8.15 explicitly requires logging and analysis of privilege use, group membership changes, identity creation/modification, configuration changes and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces the addition of groups to an account as an indicator of compromise.
- T1102detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including network activity, DNS, and outbound connections to malicious infrastructure), and identification of indicators of compromise, which surfaces most Web-service C2 usage that deviates from baseline traffic.
- T1102.001detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including outbound connections to malicious servers via DNS logs and correlation), which can surface dead-drop resolver activity when it produces observable network or log artefacts; however, the technique's use of common legitimate services (Google/Twitter) blends into expected noise, many implementations lack the specific UEBA/threat-intel rules to flag obfuscated resolvers, and pre-compromise external Web-service registration is invisible to organisational logs.
- T1102.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including network activity, outbound connections, and unusual patterns), and identification of suspected incidents such as probing or C2-like behavior, which surfaces bidirectional Web-service C2 when it generates observable logs.
- T1102.002responds — A.8.15 requires log analysis, correlation, and identification of suspected incidents (including anomalous outbound connections and indicators of compromise) to feed the incident management process (5.25), which performs the containment/eradication act that `responds` names; this catches some but not most T1102.002 executions because the technique blends into expected web noise and many instances produce no detectable log anomaly.
- T1102.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/threat intel, DNS log review for C2 connections to malicious servers, correlation of events, and identification of indicators like probing or malware that map to one-way C2 over web services, covering the observable network and behavioral artifacts on the organization's estate.
- T1104detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation across event types (including network activity, system changes, privilege use, and outbound connections to malicious infrastructure), and identification of suspected incidents such as probing or malware, which surfaces the observable behaviors and infrastructure shifts of multi-stage C2.
- T1105detects — A.8.15 explicitly requires logging, analysis, and monitoring of events including successful/rejected access attempts, use of utilities/applications, network activity, anomalous behaviour, and indicators of compromise (with SIEM/UEBA/threat-intel support), which surfaces most T1105 ingress-tool-transfer activity (downloads via curl/wget/certutil/PowerShell/etc.) while the named remainder is activity on unmonitored or out-of-scope systems.
- T1106detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, correlation, and review of access attempts, privilege use, process activity, and configuration changes — all of which surface native API abuse (syscalls, process creation, tampering) once it occurs.
- T1110detects — Systematic logging of rejected access attempts and authentication events supports detection of password-guessing or spraying campaigns.
- T1110prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes and alarms, plus analysis to surface anomalous patterns (including brute-force attempts), which can trigger preventive controls or block further guessing; this stops some but not most instances of the technique (e.g. offline attacks, rate-limit bypasses, or non-logged vectors remain untouched).
- T1110responds — A.8.15 requires log analysis and monitoring to identify anomalous activity (including brute-force patterns such as repeated failed logons), flag suspected incidents, and feed them into the incident management process (5.25) for response once the technique is underway.
- T1110.001detects — A.8.15 explicitly requires logging of successful/rejected access attempts, use of privileges, alarms from access control systems, and log analysis (with SIEM/IDS/UEBA rules, anomaly detection, and correlation) that surfaces password-guessing patterns as indicators of compromise or incidents.
- T1110.001prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, alarms, and anomalous behaviour plus protected immutable logs and analysis that surfaces guessing in flight; this directly enables account lockouts, rate limiting and blocking after failed attempts (explicitly referenced in the T1110.001 description), stopping the technique from succeeding on most covered vectors while leaving a bounded remainder for exempted identities, legacy protocols and unmonitored services.
- T1110.001responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (e.g. probing of firewalls, unsuccessful access attempts) then subject them to further investigation as part of incident management (5.25), which is exactly the containment/eradication act that `responds` names once the guessing is underway.
- T1110.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and correlation of access attempts, privilege use, configuration changes and alarms to surface indicators of compromise such as password-cracking activity.
- T1110.003detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation rules, directly surfacing password-spraying patterns (many failed logins from one or few passwords across accounts) while the technique is in flight or shortly after.
- T1110.003prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes and anomalous behaviour plus protected immutable logs and analysis (SIEM/UEBA/threat intel), which surfaces many password-spraying attempts and can trigger account-lock or rate-limit responses that stop the technique; it does not stop the spraying itself from being attempted or succeeding on unmonitored vectors, throttled low-and-slow attempts, or non-logged services.
- T1110.003responds — A.8.15 requires log analysis, anomaly detection, correlation, and explicit hand-off of suspected/actual incidents (including probing or authentication anomalies) into the incident management process (5.25), which is exactly the containment/eradication act that `responds` names once the sprayed technique is underway.
- T1110.004detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, alarms from access control systems, and log analysis (with SIEM/IDS/UEBA rules, anomalous behaviour detection, and correlation) that surfaces credential-stuffing patterns such as repeated authentication failures across targeted services.
- T1110.004prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour via analysis/SIEM/UEBA, which surfaces credential-stuffing patterns (e.g. repeated failures) for blocking before success; it does not stop the technique from being attempted or guarantee enforcement of lockouts/rate limits.
- T1110.004responds — A.8.15 requires log analysis and correlation to identify suspected incidents (e.g. probing of firewalls, anomalous access attempts) once underway and feed them into the incident management process (5.25), which performs containment/eradication; this engages the core of `responds` for the authentication-failure and probing slice of credential stuffing but leaves the bulk (successful overlap logins that do not trigger alarms or anomalies) untouched.
- T1111detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, privilege use, configuration changes, and physical events that surface MFA interception indicators (keyloggers, anomalous auth, SMS compromise, token replay patterns).
- T1112detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, and resource access attempts, plus log analysis (with SIEM/UEBA/threat intel) to surface anomalous behaviour and indicators of compromise; registry modifications for evasion/persistence are observable in those events and detectable via the mandated analysis, with a bounded remainder for stealth techniques that evade the listed log sources.
- T1113detects — A.8.15 explicitly requires log analysis and monitoring of events (including system activities, privilege use, application execution, anomalous behaviour via SIEM/UEBA/IDS correlation, and physical logs) to identify indicators of compromise such as malware or probing; screen capture via native utilities or RAT features is observable in those logs and would surface as anomalous activity.
- T1114detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, configuration changes, privilege use, and physical events that surface email collection from servers/clients or related anomalous forwarding/behavior.
- T1114responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. anomalous behaviour, probing) for further investigation under incident management (5.25), which is the core of `responds`; it does not itself contain/eradicate the collection once underway.
- T1114.001detects — A.8.15 explicitly requires logging of file access/deletion, privilege use, system activities and anomalous behaviour, plus SIEM/UEBA/correlation analysis that surfaces local email file collection as an indicator of compromise.
- T1114.002detects — A.8.15 explicitly requires logging of access attempts, privilege use, resource access, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces credentialed Exchange/Office 365 email collection both during and after the fact.
- T1114.002responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (e.g. unusual access patterns, probing), which can surface remote email collection in flight for further incident response, but does not itself contain/eradicate the actor or technique once underway.
- T1114.003detects — A.8.15 explicitly requires log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of logs including successful/unsuccessful access and configuration changes) that surface creation or use of email forwarding rules as an information security event or indicator of compromise.
- T1114.003responds — A.8.15 requires log analysis and correlation (including of successful/unsuccessful access, privilege use, configuration changes, and anomalous behaviour) to identify suspected incidents such as this rule creation, then hands them to the incident management process; this matches the `responds` verb once the technique is underway, but only a slice of the attack (the detectable logging surface) is covered while hidden rules, transport rules, and post-forwarding exfiltration sit outside what the logging facility itself can contain or eradicate.
- T1115detects — A.8.15 explicitly requires logging of system activities, privilege use, application transactions, successful/rejected access attempts, and anomalous behaviour via log analysis (SIEM/UEBA/IDS rules, pattern analysis, threat intel, DNS logs, usage reports); clipboard collection or monitoring/replacement is observable in process, command-line, or file-activity logs on all three platforms and surfaces as anomalous in analysis.
- T1119detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts, file activity, configuration changes and privilege use — all of which surface automated collection once it runs.
- T1119responds — A.8.15 requires log analysis and correlation (including of file-access, privilege-use, configuration-change and anomalous-behaviour events) to identify and hand off suspected incidents for the incident-management process (5.25); once T1119 has run, those logs supply the evidence that lets responders contain/eradicate the collection activity, but the control itself performs none of the containment or eradication steps and many T1119 variants (especially cloud-API/ETL) leave no detectable log trail under the clause's listed events.
- T1120detects — A.8.15 explicitly requires logging, protection, and analysis of events including system activities, device identities, use of utilities/applications, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces T1120's reconnaissance actions on Linux/macOS/Windows systems.
- T1123detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of events including use of applications/utilities, privilege use, system activities, and physical monitoring to surface indicators of compromise such as malware invoking audio APIs or writing suspicious files.
- T1124detects — A.8.15 explicitly requires log analysis and monitoring activities (including correlation, UEBA, SIEM/IDS rules, and review of access/system events) to identify anomalous behaviour and indicators of compromise; this surfaces T1124 reconnaissance when it triggers logged events or patterns, but many local discovery methods (direct syscalls, GetTickCount, CLI queries on unmonitored devices) produce no observable event or fall outside the clause's scoped activities.
- T1125detects — A.8.15 explicitly requires log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomalous behaviour detection, correlation of access/use logs, physical monitoring) that surface video-capture indicators such as unexpected device activation, API use, file writes of images/video, or outbound exfil — the core of the `detects` verb — with only a bounded remainder for fully stealthy in-memory capture that evades all logging.
- T1127detects — A.8.15 explicitly requires logging, analysis, and correlation of events including use of applications/utilities, privilege use, system configuration changes, and anomalous behaviour via SIEM/UEBA/threat intel, which surfaces T1127's proxy execution through trusted signed developer tools as an indicator of compromise.
- T1127.001detects — A.8.15 explicitly requires logging, protection, and analysis of events including use of applications/utilities, system activities, privilege use, anomalous behaviour via SIEM/UEBA/IDS correlation, and indicators of compromise, which surfaces MSBuild abuse as a signed binary proxying arbitrary code.
- T1127.002detects — A.8.15 explicitly requires logging, protection, and analysis of events including successful/rejected access attempts, privilege use, application/utility execution, system configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces ClickOnce abuse (e.g. dfshim.dll via rundll32, startup folder placement, or child of DFSVC.EXE) as an indicator of compromise.
- T1127.003detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and security events (including use of utilities, system activities, and application transactions), which surfaces JamPlus abuse when it produces observable log artifacts on Windows systems.
- T1129detects — A.8.15 requires logging, protection, and analysis of events including system activities, privilege use, process loading (via shared modules/DLLs/SOs), anomalous behaviour, and indicators of compromise, which surfaces T1129 when it triggers observable events; however, many in-memory module loads (especially stealthy or non-anomalous ones) produce no detectable log or anomaly within the clause's scope.
- T1132detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of network/DNS/activity patterns that can surface encoded C2 traffic as anomalous; this is genuine detection but only a slice, as the control does not mandate instrumentation depth or coverage of all encoding variants and many encoded payloads remain indistinguishable from legitimate traffic without additional specific tooling.
- T1132.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and specific monitoring of network traffic/DNS/outbound connections to malicious C2, which surfaces standard encoding (Base64, etc.) in C2 traffic as anomalous; the remainder is non-network or fully obfuscated cases outside the monitored scope.
- T1132.002detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and unusual network activity (including DNS and outbound connections), which surfaces non-standard encoding in C2 traffic as an observable deviation; this is a genuine but minority slice because the control's scope is limited to what is logged, analyzed per defined procedures, and correlated within the organization's estate, leaving many encoding variants, non-monitored channels, and pre-analysis evasion outside its reach.
- T1133detects — A.8.15 explicitly requires logging of successful/rejected access attempts to remote services, privilege use, configuration changes, alarms from access-control systems, and subsequent log analysis (with SIEM/IDS/UEBA rules, anomaly detection, correlation, and threat intel) that surfaces indicators of compromise such as unauthorized external remote service use.
- T1133responds — A.8.15 requires log analysis, correlation, and identification of suspected incidents (e.g. probing of firewalls or anomalous access attempts) to feed the incident management process (5.25), which acts on an external-remote-service event once underway; this is genuine but only a slice because the control stops at detection/analysis and does not itself perform containment or eradication.
- T1134detects — A.8.15 explicitly requires logging of privilege use, system access attempts, configuration changes and anomalous behaviour, plus SIEM/UEBA/correlation analysis that surfaces token manipulation as an indicator of compromise or privilege escalation.
- T1134.001detects — A.8.15 explicitly requires logging of privilege use, system access attempts, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces token impersonation when it triggers observable events (e.g. unusual privilege use or access patterns); the named remainder is stealthy in-memory impersonation that evades the logged events or monitoring scope.
- T1134.001responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including privilege use and access attempts), which supports containment/eradication once token impersonation is underway, but does not itself perform the response actions.
- T1134.002detects — A.8.15 explicitly requires logging of privilege use, system access attempts, process/activity events and anomalous behaviour via SIEM/UEBA/correlation, which surfaces T1134.002 when it executes; the named remainder is events that evade the chosen log sources or analysis rules.
- T1134.002responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/UEBA/IDS rules on privilege use, access attempts, and config changes) surface T1134.002 once it runs, feeding the incident management process, but this is limited to observable events rather than full containment/eradication.
- T1134.003detects — A.8.15 explicitly requires logging of privilege use, successful/rejected access attempts, system activities, and log analysis (with SIEM/UEBA/IDS rules, anomalous behaviour detection, and correlation) that surfaces token creation and impersonation as indicators of compromise on Windows.
- T1134.003responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including privilege use and access attempts), which supports containment/eradication once token impersonation is underway, but does not itself perform the response actions.
- T1134.004detects — A.8.15 requires log analysis and monitoring of process-related events (system activities, privilege use, anomalous behaviour via UEBA/SIEM/IDS correlation) that can surface PPID spoofing as an IOC, but does not mandate the specific process-creation or parent-child telemetry needed to reliably catch it.
- T1134.005detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM rules, anomalous behaviour detection, privilege-use logging, and correlation) that can surface SID-History injection as a privileged-account anomaly or configuration change, but the control's scope is set by what the organization chooses to log/monitor and does not mandate coverage of this specific AD attribute manipulation.
- T1135detects — A.8.15 explicitly requires logging, analysis and correlation of events including successful/rejected resource access attempts, file shares accessed, network activity, alarms from access control systems, and anomalous behaviour via SIEM/UEBA/threat intel, which surfaces T1135's network share enumeration (SMB net view/share, sharing -l) as an indicator of compromise.
- T1136detects — A.8.15 explicitly requires logging of account creation/modification/deletion events, synchronized time sources, protected logs, and analysis (including SIEM/UEBA/threat intel correlation) that surfaces anomalous account creation as an indicator of compromise.
- T1136prevents — A.8.15 mandates logging of account creation/modification/deletion events plus protected analysis to surface them as indicators of compromise, which can stop the persistence technique from succeeding when the creation is detected and investigated before the account is leveraged; this is only a slice of the technique's surface (creation itself is not blocked, only some post-creation use on monitored platforms).
- T1136responds — A.8.15 requires log analysis and correlation to identify suspected incidents (including account creation events) and feed them into the incident management process (5.25) for response, but the control itself performs only detection/analysis and hands off containment/eradication, leaving the core response actions to another control.
- T1136.001detects — A.8.15 explicitly requires logging and analysis of identity creation, privilege use, configuration changes, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces the creation of a local account as an information security event or indicator of compromise.
- T1136.001prevents — A.8.15 mandates logging of identity creation events (item i), privilege use, configuration changes, and anomalous behaviour analysis via SIEM/UEBA/threat intel, which can surface the account creation in real time or shortly after and enable blocking response; this stops many but not all instances of the technique (e.g. stealthy or post-compromise creations outside monitored scopes, or on unlogged network devices/ESXi).
- T1136.002detects — A.8.15 explicitly requires logging and analysis of identity creation events, privilege use, configuration changes, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces domain account creation as a potential indicator of compromise.
- T1136.002prevents — A.8.15 mandates logging of identity creation events (including domain accounts) plus protected analysis to surface them as anomalies or IOCs, which can prevent the persistence technique from succeeding when caught early; it does not stop the account from being created in the first place.
- T1136.003detects — A.8.15 explicitly requires logging of identity creation/modification, privilege use, configuration changes and anomalous behaviour, plus SIEM/UEBA/correlation analysis that surfaces the creation of a cloud account as an information security event or indicator of compromise.
- T1136.003responds — A.8.15 requires log analysis and correlation (including of identity creation, privilege use, and configuration changes) to identify suspected incidents such as unauthorized account creation, then feeds them into the incident management process (5.25) for response; this acts once the technique is underway but only on detectable slices, not all stealthy or low-privilege cloud account creations.
- T1137detects — A.8.15 explicitly requires logging of application transactions, privilege use, configuration changes, identity creation/modification, and anomalous behaviour via log analysis (SIEM/UEBA/IDS rules, correlation, threat intel), which surfaces Office startup persistence mechanisms (macros, add-ins, Outlook rules/forms) as security events or IOCs once they execute.
- T1137.001detects — A.8.15 explicitly requires logging of macro-related events (use of applications/utilities, privilege use, file access/deletion, configuration changes), log analysis with UEBA/SIEM/IDS rules to surface anomalous behaviour, and correlation of logs (including physical) to identify indicators of compromise such as malicious Office template macro execution on startup.
- T1137.001prevents — A.8.15 mandates logging of application transactions, privilege use, configuration changes, and anomalous behaviour (with analysis via SIEM/UEBA/threat intel), which can surface the macro insertion or registry hijack before it becomes persistent; this constrains the technique on systems where detection leads to blocking, but does not stop the adversary from modifying the template or enabling macros.
- T1137.002detects — A.8.15 explicitly requires log analysis and monitoring of events including changes to system configuration, use of privileges, and anomalous behaviour via SIEM/UEBA/threat intel to surface indicators of compromise; this can detect the Office Test registry addition and DLL execution on Windows/Office, but only where those specific events fall inside the organisation's chosen logging scope and analysis rules rather than being mandated universally.
- T1137.003detects — A.8.15 explicitly requires logging of application transactions, privilege use, system activities, configuration changes and identity creation/modification plus SIEM/UEBA-driven log analysis to surface anomalous behaviour and indicators of compromise; this directly surfaces the mailbox form registration and the subsequent form-triggered execution on mail receipt.
- T1137.003responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification explicitly surface suspected persistence via malicious Outlook forms (e.g. via UEBA, SIEM rules, or email-related event logs), feeding the incident management process, but this is a minority slice of the technique's execution rather than containment/eradication once underway.
- T1137.004detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, application transactions, configuration changes, identity creation/modification, and anomalous behaviour via log analysis (including SIEM/UEBA rules, pattern analysis, and correlation), which surfaces the addition of a malicious Outlook Home Page and its execution on folder load as an information security event.
- T1137.005detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including via SIEM, UEBA, correlation, and review of access/use events), which surfaces the creation or triggering of malicious Outlook rules as an information security event.
- T1137.006detects — A.8.15 explicitly requires logging of application transactions, privilege use, system activities, configuration changes, identity creation/modification, and anomalous behaviour via log analysis (SIEM/UEBA/IDS rules, threat intel, correlation), which surfaces Office add-in persistence mechanisms (e.g. registry changes, add-in loading on startup) once present on Windows/Office systems.
- T1140detects — A.8.15 explicitly requires logging of security-relevant events (access attempts, privilege use, configuration changes, alarms, system activations), log protection, and analysis (including SIEM/IDS/UEBA rules, anomalous patterns, and correlation) that surfaces deobfuscation activity when it triggers observable indicators such as certutil execution, file reassembly commands, or anomalous process behavior.
- T1176detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including via UEBA, SIEM, IDS rules, and correlation of events such as privilege use, configuration changes, and application activity), which surfaces malicious or abused extensions once installed and active; it does not cover pre-install marketplace scanning or the full set of stealthy extension behaviours that leave no observable event.
- T1176.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of events such as privilege use, configuration changes, file access/deletion, and security system activation/deactivation — all of which surface the installation, persistence, and post-install actions (stealth, C2, data theft) of malicious browser extensions on Linux/Windows/macOS.
- T1176.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of events (including application and privilege use), and identification of indicators of compromise or suspicious activity that can surface malicious IDE extensions once they execute or trigger logged events, but this is limited to post-install/runtime observables and does not cover silent/side-loaded extensions that produce no detectable log artifacts.
- T1185detects — A.8.15 explicitly requires logging of access attempts, privilege use, configuration changes, system activities and anomalous behaviour, plus SIEM/UEBA/correlation analysis that surfaces browser injection, proxy pivots and inherited-session anomalies as indicators of compromise.
- T1185prevents — A.8.15 mandates logging of access attempts, privilege use, configuration changes, and anomalous behaviour plus protected analysis that can surface browser-injection or pivoting indicators before or during execution, but the control only records and analyses — it does not stop the injection, proxy setup, or session inheritance itself.
- T1185responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (e.g. via SIEM, UEBA, correlation), which surfaces browser session hijacking once underway for further investigation under incident management, but only for observable events and without containment/eradication actions.
- T1187detects — A.8.15 explicitly requires logging of access attempts, privilege use, configuration changes, alarms, security system activation, and anomalous behaviour via SIEM/IDS/UEBA/correlation, which surfaces the forced SMB/WebDAV/EFSRPC authentication events and the resulting NTLM hash exfiltration as indicators of compromise.
- T1189detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including successful/rejected access, configuration changes, privilege use, alarms from access control and security systems), and identification of suspected incidents such as malware infection or probing — which surfaces drive-by compromise in flight or post-exploitation on client endpoints.
- T1189responds — A.8.15 requires log analysis and correlation (including of alarms, access attempts, configuration changes, and anomalous behaviour via SIEM/IDS/UEBA) to identify suspected incidents such as probing or malware for further investigation under the incident management process; this bounds an in-progress drive-by once its artifacts reach observable logs, but does not contain/eradicate the actor's foothold or code execution itself.
- T1190detects — A.8.15 explicitly requires logging of access attempts, configuration changes, privilege use, alarms from access-control/IDS systems, and log analysis (with SIEM/IDS/UEBA rules, anomaly detection, and correlation) that surfaces indicators of compromise such as probing or exploitation attempts against public-facing applications.
- T1190responds — A.8.15 requires log analysis and correlation (including of alarms, access attempts, configuration changes, and anomalous behaviour) to identify suspected incidents such as probing of firewalls or malware, then feeds them into the incident management process (5.25) for response once the exploit technique is already underway; this is genuine but only a slice because the clause itself performs detection/analysis rather than containment/eradication.
- T1195detects — A.8.15's log analysis, anomaly detection via SIEM/UEBA/threat intel, and correlation of events (including from third-party apps, updates, and access attempts) can surface indicators of a supply-chain compromise after it has occurred, but this is limited to post-delivery observable artifacts on the consuming systems rather than the upstream manipulation stages themselves.
- T1195.001detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including via SIEM, UEBA, threat intel, and correlation of events such as configuration changes, privilege use, and third-party application transactions), which surfaces some supply-chain compromises after they occur but only for the subset observable in the victim's logs rather than the upstream manipulation itself.
- T1195.002detects — A.8.15 requires log analysis (with SIEM/IDS/UEBA/threat intel) and monitoring of events like config changes, privilege use, file access/deletion, and anomalous behaviour to surface supply-chain indicators such as unexpected modifications or malicious updates; this is genuine but only a slice, as the technique occurs pre-receipt and leaves no guaranteed observable footprint on the victim's systems.
- T1197detects — A.8.15 explicitly requires logging of system activities, privilege use, process/application execution, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces BITS job abuse (PowerShell/BITSAdmin invocations, long-lived background transfers, post-reboot execution) as security events or indicators of compromise.
- T1197responds — A.8.15's log analysis, correlation, and identification of suspected incidents (including anomalous behavior or probing) can surface BITS abuse once it has begun, feeding into incident response, but the control itself performs no containment or eradication.
- T1199detects — A.8.15 requires log analysis and monitoring (SIEM/UEBA/IDS correlation, anomalous behaviour review, DNS logs for C2, physical logs) that can surface post-breach use of a trusted third-party account or connection, but the technique's upstream acquisition and initial abuse of the external relationship often occurs outside the organization's estate and observable logs.
- T1200detects — A.8.15 requires log analysis, monitoring for anomalous behaviour, correlation of logs (incl. physical access events), and identification of indicators of compromise or incidents, which can surface some hardware additions (e.g. new devices, network changes, or anomalous traffic) but does not guarantee detection of stealthy or physical-only insertions like DMA or passive taps.
- T1201detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules, correlation, and review of access attempts (including privilege use and configuration changes) to surface indicators of compromise; this catches many T1201 discovery actions in logs, but leaves a bounded remainder for stealthy/local-only queries or unmonitored platforms that produce no observable events.
- T1202detects — A.8.15 explicitly requires logging of command-line and utility usage (including privilege use, system activities, and application transactions), log analysis with UEBA/SIEM/IDS rules to surface anomalous behaviour, and correlation to identify indicators of compromise such as indirect execution that subverts cmd restrictions.
- T1203detects — A.8.15 explicitly requires logging, protection, and analysis of events (including successful/rejected access, privilege use, configuration changes, alarms from IDS/AV, anomalous behaviour via SIEM/UEBA/threat intel, and correlation with physical logs) to identify indicators of compromise such as exploitation leading to client execution.
- T1203responds — A.8.15's log analysis, anomaly detection, correlation, and explicit tie to feeding suspected incidents into the 5.25 incident management process enable response actions once client-exploitation events are underway, but only for the detectable post-exploitation artifacts (e.g. anomalous access, alarms, configuration changes) rather than the exploit delivery or code-execution step itself.
- T1204detects — A.8.15 explicitly requires logging of user actions, privilege use, application execution, file access/deletion, alarms, and anomalous behaviour via log analysis, SIEM, UEBA, and correlation, which surfaces the specific user actions that realise T1204 (opening malicious docs/links, running JS, enabling RATs, manual execution) after they occur.
- T1204responds — A.8.15 requires log analysis and correlation (including of access attempts, privilege use, alarms, and anomalous behaviour) to identify suspected incidents such as malware execution, then feeds them into the incident management process (5.25) for response; this acts once user execution is underway but only surfaces a slice of the technique (e.g. observable post-execution artifacts) rather than containing/eradication itself.
- T1204.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, DNS, and correlated events that surface the user click, follow-on execution, or indicators of the resulting compromise.
- T1204.001responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. probing, anomalous behavior) once the malicious-link click has occurred and produced observable events, enabling further investigation per the incident management process; this matches `responds` but is limited to detection-plus-investigation rather than containment/eradication of the technique itself.
- T1204.002detects — A.8.15 explicitly requires logging of file access/deletion, privilege use, application execution, alarms from access control/IDS, and log analysis (with UEBA, SIEM, pattern/trend analysis, and correlation) to identify anomalous behavior and indicators of compromise such as malware or probing, which surfaces T1204.002 execution; the named remainder is events on unmonitored systems or without sufficient analysis depth.
- T1204.002responds — A.8.15 requires log analysis and correlation (including of file-access events, alarms, and anomalous behaviour) to identify suspected incidents such as malware and feed them into the incident-management process (5.25); this is exactly the containment/eradication moment that `responds` names, but only after the file has already been opened and executed.
- T1204.003detects — A.8.15 requires log analysis and monitoring (including SIEM/IDS/UEBA rules, anomalous behaviour detection, and correlation of events such as resource access, configuration changes, privilege use, and alarms) that can surface indicators of a malicious image being deployed and executed, but this is scoped to what the organization chooses to log/monitor and does not guarantee detection of the image-based execution technique itself.
- T1204.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, configuration changes, privilege use, and suspicious activity that surfaces the social-engineering-triggered execution step of T1204.004; the named remainder is the pre-execution social-engineering delivery (e.g. the phishing lure or fake CAPTCHA page itself) which leaves no system log until the paste occurs.
- T1204.005detects — A.8.15's log analysis, anomaly detection via SIEM/UEBA/threat intel, and review of access/usage events can surface indicators of a malicious library after installation and execution, but this is limited to observable post-execution artifacts rather than the library upload, typosquatting, or install itself.
- T1205detects — A.8.15 explicitly requires logging of access attempts (successful/rejected), network activity, alarms from access-control/IDS systems, anomalous behaviour via SIEM/UEBA/correlation, and analysis of events against threat intelligence to surface indicators of compromise such as unusual packet sequences or port-knocking patterns.
- T1205.001detects — A.8.15 explicitly requires logging of successful/rejected access attempts, network activity, alarms from access control systems, and analysis of logs (including via SIEM/IDS rules, UEBA, and correlation) to identify anomalous behaviour and indicators of compromise such as probing; this surfaces port-knocking sequences in the great majority of cases, with a bounded remainder for fully stealth implementations that generate no observable events at all.
- T1205.001prevents — A.8.15 mandates logging of access attempts, configuration changes, privilege use, alarms, and security system activation/deactivation plus analysis to surface anomalous behaviour; this can prevent the port-knocking sequence from successfully triggering a hidden port on systems where the firewall or custom listener is itself configured under the logged baseline and the knock packets are treated as rejected-access or anomalous events that are blocked before the port opens.
- T1205.001responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including probing of firewalls), which can surface port-knocking sequences once underway and feed the incident-response process, but does not itself contain or eradicate the actor or the opened port.
- T1205.002detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, DNS log checks for malicious C2, correlation of events, and identification of indicators like probing or anomalous behavior, which can surface socket filter installation or triggered backdoor activity in monitored environments, but the technique's passive/low-activity/raw-socket nature (as noted in the source prose) leaves substantial detection gaps on unmonitored interfaces or without specific raw packet/setsockopt visibility.
- T1207detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, correlation, and review of access attempts/config changes/privilege use to surface indicators of compromise; this can catch post-registration replication anomalies or metadata tampering, but the technique's explicit design to bypass system logging/SIEM (actions not reported to sensors) and delete metadata leaves a large, named gap in detection coverage.
- T1207responds — A.8.15 requires log analysis and correlation (including SIEM/IDS/UEBA rules, anomalous behaviour detection, and incident identification) that can surface DCShadow activity once it occurs, feeding the incident management process, but the technique's explicit bypass of logging/SIEM and metadata tampering create a large, named remainder where the response trigger is absent.
- T1210detects — A.8.15 explicitly requires logging, analysis, and monitoring of events including successful/rejected access attempts, privilege use, configuration changes, alarms from access control/IDS, anomalous behaviour via SIEM/UEBA/correlation, and identification of incidents such as probing of firewalls or malware, which surfaces most instances of remote service exploitation (T1210) after it occurs.
- T1210responds — A.8.15 requires log analysis (with SIEM/IDS/UEBA rules, anomaly detection, correlation, and explicit identification of suspected incidents such as probing of firewalls or malware) plus escalation to incident management (5.25), which surfaces and contains an in-progress remote service exploitation once it generates observable events.
- T1211detects — A.8.15 mandates determining what to log, protecting logs from tampering/deletion, requiring synchronized time sources, and performing log analysis (with SIEM/IDS/UEBA rules, anomaly detection, correlation, and review of access attempts/DNS/physical logs) to identify indicators of compromise and suspected incidents, which surfaces exploitation used to suppress logging or evade audit trails.
- T1212detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including access attempts, privilege use, configuration changes, and alarms), and identification of suspected incidents such as probing or malware that would surface exploitation activity aimed at credential mechanisms.
- T1213detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts, configuration changes, privilege use, and alarms to surface indicators of compromise including repository access and data exfiltration patterns.
- T1213.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and correlation of events (including access attempts, configuration changes, privilege use, and physical logs) to identify indicators of compromise such as probing or unauthorized access to repositories like Confluence.
- T1213.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including access attempts, configuration changes, privilege use, and file access/deletion on resources like SharePoint), and identification of indicators of compromise such as probing or unusual activity, which surfaces the technique when it generates observable events on monitored systems.
- T1213.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts (including to resources like code repositories) to surface indicators of compromise such as unauthorized collection activity.
- T1213.003prevents — A.8.15 requires logging of access attempts, privilege use, configuration changes, and file accesses (including in applications and third-party services), plus protected immutable logs and analysis that can surface anomalous repository access before or during collection; this constrains the technique on monitored internal/SaaS repositories but leaves unmonitored public or external repos, incomplete coverage of credential extraction inside source, and post-breach collection after valid access fully outside its scope.
- T1213.004detects — A.8.15 requires log analysis and monitoring (including SIEM/UEBA rules, anomalous behaviour detection, and correlation of access/resource events) that can surface adversary mining of CRM data as unusual activity or an indicator of compromise once it occurs, but this is scoped only to events the organization chooses to log and analyse rather than a dedicated or guaranteed detection of this technique.
- T1213.005detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM/IDS rules, anomalous behaviour detection, and correlation of events such as access attempts or configuration changes) that can surface adversary mining of messaging apps when it produces observable indicators, but the control's scope is limited to defined events and does not guarantee coverage of all chat-based exfiltration or reconnaissance on SaaS platforms.
- T1213.006detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including access attempts, privilege use, configuration changes, and physical logs), and identification of suspected incidents such as probing — which surfaces database mining in real time or post-facto across the named platforms.
- T1216detects — A.8.15 explicitly requires logging and analysis of events including use of applications/utilities, privilege use, system activities, anomalous behaviour via SIEM/UEBA/IDS correlation, and indicators of compromise, which surfaces proxy execution of malicious files through trusted signed scripts.
- T1216.001detects — A.8.15 explicitly requires logging, protection, and analysis of events including system activities, use of privileges, utility programs/applications, successful/rejected access attempts, and anomalous behaviour via SIEM/UEBA/threat intel correlation, which surfaces PubPrn.vbs abuse (a signed script proxying remote execution) as an indicator of compromise; the bounded remainder is that some stealthy or non-logged invocations may evade detection.
- T1216.002detects — A.8.15 explicitly requires logging of system activities, privilege use, script/application execution, command-line details and anomalous behaviour, plus analysis via SIEM/UEBA/correlation to surface indicators of compromise such as living-off-the-land proxy execution of PowerShell via a signed VBS.
- T1217detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise, which directly surfaces browser enumeration activity (e.g. via file-access, process, or privilege-use logs) once it occurs on the monitored estate.
- T1218detects — A.8.15 explicitly requires logging and analysis of events including use of privileges, utility programs, system activities, successful/rejected access attempts, and anomalous behaviour via SIEM/UEBA/IDS correlation, which surfaces proxy execution of malicious content through trusted binaries as an indicator of compromise.
- T1218.001detects — A.8.15 explicitly requires logging and analysis of events including successful/rejected access attempts, use of applications/utilities, system configuration changes, alarms from access control/IDS, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces hh.exe execution of suspicious CHM payloads as an indicator of compromise.
- T1218.002detects — A.8.15 explicitly requires logging of system access attempts, privilege use, configuration changes, application execution, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces control.exe proxying of malicious CPL/DLL payloads as an information security event.
- T1218.003detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, application transactions, successful/rejected access attempts, and anomalous behaviour via SIEM/UEBA/IDS correlation plus physical logs; this surfaces CMSTP.exe abuse (a signed binary proxying DLL/SCT execution or UAC bypass) as an anomalous or suspicious event after it runs.
- T1218.004detects — A.8.15 explicitly requires logging of system activities, privilege use, application execution, configuration changes and anomalous behaviour, plus SIEM/IDS/UEBA correlation and analysis that surfaces proxy execution through a signed utility such as InstallUtil.
- T1218.005detects — A.8.15 explicitly requires logging of system activities, privilege use, application/utility execution, successful/rejected access attempts, and anomalous behaviour via log analysis (SIEM/UEBA/IDS correlation), which surfaces mshta.exe abuse as an anomalous or suspicious process execution.
- T1218.005responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/IDS/UEBA rules on executed processes, scripts, network activity or privilege use) surface mshta.exe abuse once underway for containment under incident management, but this is only a slice of the technique's possible forms (e.g. inline scripts or non-logged executions) rather than a bounded remainder.
- T1218.007detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, application execution, configuration changes, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces msiexec.exe abuse as an indicator of compromise on Windows systems.
- T1218.008detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, application execution, configuration changes, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces the signed-binary proxy execution of a malicious DLL as an observable event.
- T1218.009detects — A.8.15 explicitly requires logging of system activities, privilege use, application execution, configuration changes and anomalous behaviour, then mandates analysis (SIEM/UEBA/rules/threat intel) that surfaces proxy-execution techniques such as Regsvcs/Regasm; the named remainder is events outside the chosen logging scope or before analysis occurs.
- T1218.010detects — A.8.15 explicitly requires logging of system activities, privilege use, application execution, successful/rejected access attempts, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces Regsvr32 abuse (especially network-loaded COM scriptlets or unusual process activity) as an indicator of compromise; the named remainder is stealthier in-memory or allowlisted invocations that produce no distinct log artifact.
- T1218.010responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (e.g. malware execution or probing), then subject them to further investigation as part of incident management; this directly enacts the containment/eradication steps that `responds` names once the Regsvr32 abuse is underway.
- T1218.011detects — A.8.15 explicitly requires logging of system activities, privilege use, process/application execution, successful/rejected access attempts, and anomalous behaviour via SIEM/UEBA/IDS correlation plus log analysis to surface indicators of compromise such as unusual rundll32.exe invocations proxying malicious code.
- T1218.011responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, suspected incidents (including malware execution or probing), and support further investigation under incident management, which matches the `responds` verb once the rundll32 abuse is underway; partial because the clause sets requirements for what to log/analyse rather than mandating universal detection of every proxying, masquerading or ordinal variant described.
- T1218.012detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, process execution, anomalous behaviour via SIEM/UEBA/IDS correlation, and indicators of compromise, which surfaces verclsid.exe abuse as a signed-binary proxy technique.
- T1218.012prevents — A.8.15 requires logging of system activities, privilege use, application execution, configuration changes and anomalous behaviour (with analysis via SIEM/UEBA), which can surface verclsid.exe abuse as an unusual process or COM activity before or during execution; however, it does not stop the binary from being invoked or the payload from running.
- T1218.013detects — A.8.15 explicitly requires logging of process activities, privilege use, system changes, and anomalous behaviour via SIEM/UEBA/IDS correlation plus specific monitoring of access attempts and outbound connections, which surfaces mavinject.exe abuse (a signed binary performing DLL/import injection) as an anomalous or suspicious event.
- T1218.013responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification steps (including physical logs and SIEM/IDS rules) surface mavinject.exe abuse once underway as part of the incident management process, but the control's mechanism is observation and does not itself contain or eradicate the running injection.
- T1218.014detects — A.8.15 explicitly requires logging and analysis of events including use of privileges, system activities, application transactions, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces MMC abuse (signed binary proxying malicious .msc/CLSID payloads) as an indicator of compromise.
- T1218.014responds — A.8.15's log analysis, correlation, anomalous-behaviour detection and explicit tie to the incident-management process (5.25) let responders contain/eradicate an MMC-abuse event once it is underway and logged; the remainder is that the control supplies only detection-plus-hand-off, not the containment/eradication actions themselves, and many MMC executions (e.g. wbadmin catalog deletion) produce no observable event until after impact.
- T1218.015detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of events (including process activity, privilege use, application execution, and child-process patterns), and identification of indicators of compromise such as malware or probing, which surfaces Electron abuse (e.g. anomalous child processes from teams.exe/chrome.exe or planted JS) in monitored environments.
- T1219detects — A.8.15 explicitly requires logging, protection, and analysis of events including system access attempts, privilege use, configuration changes, application transactions, anomalous behaviour via SIEM/UEBA/IDS correlation, and indicators of compromise, which surfaces post-compromise use or installation of remote access tools as described in T1219.
- T1219responds — A.8.15's log analysis, correlation, and identification of suspected incidents (including anomalous remote sessions or EDR-abuse patterns) directly supports the incident-handling response once a RAT technique is underway, but the clause itself performs no containment or eradication.
- T1219.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of network connections, successful/failed access, configuration changes, privilege use, and physical events — all of which surface IDE tunneling (network sessions, process/CLI activity, persistence, and anomalous developer-tool behavior) in most cases, with a bounded remainder for fully encrypted or out-of-scope sessions.
- T1219.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, configuration changes, privilege use, and network activity that would surface unauthorized or anomalous use of remote desktop tools as indicators of compromise.
- T1219.002responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. anomalous remote access, probing, or C2 patterns) for further investigation under the incident management process, which is the core of `responds`; it is only partial because the clause stops at identification/analysis and does not itself perform containment or eradication.
- T1219.003detects — A.8.15 explicitly requires log analysis, anomalous behaviour detection via SIEM/IDS/UEBA/correlation, and monitoring of physical events (e.g. entrance/exit logs) plus successful/failed access attempts, which surfaces some post-install use of hardware KVM as an alternate C2 channel but leaves the bulk of stealthy physical installation and bypass of software solutions outside its scope.
- T1220detects — A.8.15 explicitly requires logging of security-relevant events (access attempts, privilege use, configuration changes, alarms, security system activation), analysis for anomalous behaviour/IOC via SIEM/UEBA/threat intel, and correlation of logs (including from physical monitoring) to identify incidents such as probing or malware; this surfaces T1220's use of msxsl.exe/wmic with suspicious XSL files or anomalous script execution in most cases, though file-extension tricks and non-monitored processes remain a bounded remainder.
- T1221detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, unusual activity (including from external resources, DNS, and correlated events), which surfaces template-injection documents when they trigger fetches, authentication attempts, or other logged events; this is genuine but only a slice because the technique can be crafted to produce no observable events until after payload execution and many delivery vectors (e.g. phishing) fall outside the logging scope.
- T1222detects — A.8.15 explicitly requires logging and analysis of events including privilege use, configuration changes, file access/deletion, alarms from access-control systems, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces T1222's permission/ACL modifications after they occur.
- T1222.001detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, file access/deletion, and anomalous behaviour via log analysis (SIEM/UEBA/rules/threat intel), which surfaces Windows DACL permission modifications performed by icacls/takeown/PowerShell as security events or indicators of compromise.
- T1222.002detects — A.8.15 explicitly requires log analysis and monitoring of events including privilege use, configuration changes, file access/deletion, and anomalous behaviour (with SIEM/UEBA/correlation), which surfaces Linux/Mac permission modifications (chown/chmod) when they occur and are logged.
- T1480detects — A.8.15 mandates log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and explicit review of access attempts, configuration changes, privilege use, and alarms that can surface guardrail checks or environment-specific conditions when they produce observable events.
- T1480.001detects — A.8.15 mandates log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of events (including system activities, privilege use, configuration changes, and network behavior) that can surface indicators of environmental keying such as anomalous decryption, unusual file/system checks, or unexpected network/IP-derived behavior; this is genuine but only a slice because the technique is designed to evade detection, operates silently until triggered, and many of its environmental-value derivations (e.g., specific AD joins or physical-device checks) produce no observable event in the required logs.
- T1480.002detects — A.8.15 requires log analysis and monitoring (including SIEM/IDS/UEBA rules, anomalous behaviour detection, and correlation of events such as process activities or file locks) that can surface mutex-based single-instance checks as indicators of compromise, but this is only a slice of the technique's possible implementations and is not required to cover mutex acquisition itself.
- T1482detects — A.8.15 explicitly requires logging and analysis of system access attempts, privilege use, configuration changes, identity modifications, and anomalous behaviour via SIEM/UEBA/correlation to surface indicators of compromise, which directly catches domain trust enumeration activity (Nltest, LDAP, API calls) in monitored environments.
- T1484detects — A.8.15 explicitly requires logging, protection, and analysis of events including changes to system configuration, use of privileges, and anomalous behaviour via SIEM/UEBA/threat intel correlation, which surfaces T1484's policy modifications (GPO, trust, federation) as security events or indicators of compromise.
- T1484.001detects — A.8.15 explicitly requires logging of privilege use, configuration changes, system access attempts, and security system activation/deactivation, plus log analysis with SIEM/UEBA/threat-intel rules to surface anomalous behaviour and indicators of compromise; GPO modification (especially of rights or scheduled tasks) produces observable events in those categories on Windows domain controllers, though some stealthy or post-compromise edits may evade the logged set.
- T1484.001prevents — A.8.15 mandates logging of privilege use, configuration changes, system access attempts, and protected-resource access (including GPO-related paths in SYSVOL), plus protected immutable logs and analysis that can surface anomalous GPO modifications before they fully succeed; this constrains the technique on monitored Windows domains but does not stop an adversary who already holds delegated write rights or bypasses the logging scope.
- T1484.001responds — A.8.15 requires log analysis and correlation (including of configuration changes, privilege use, and security-system events) to identify suspected incidents for further investigation under the incident-management process; this surfaces and hands off a realized GPO-modification event but does not itself contain or eradicate it.
- T1484.002detects — A.8.15 explicitly requires logging, analysis, and monitoring of configuration changes, privilege use, system access attempts, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces trust modifications as security events or indicators of compromise in most covered environments.
- T1484.002responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (including configuration changes, privilege use, and anomalous behavior) for further investigation under the incident management process (5.25), which is the core of `responds`; it is only partial because the control stops at detection/analysis/hand-off and does not itself perform containment or eradication.
- T1485detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including file deletions, privilege use, configuration changes, and alarms), and identification of incidents such as malware or probing that match T1485's destructive actions.
- T1485recovers — A.8.15 requires determining logging purposes, protecting logs against deletion/alteration/overwriting, archiving for retention/evidence, and analysis to identify incidents, which supports forensic recovery and investigation after data destruction but does not itself restore destroyed data or availability.
- T1485.001detects — A.8.15 explicitly requires log analysis, monitoring of configuration changes, alarms from access control, correlation of logs (including physical), UEBA, SIEM/IDS rules, and identification of anomalous activity or indicators of compromise such as probing; these surface lifecycle policy modifications and bulk-deletion events on IaaS buckets when they generate observable logs or alarms.
- T1485.001recovers — A.8.15 requires determining log purposes, protecting logs against deletion/overwriting (via append-only, hashing, archiving per 5.28), and retaining them for evidence/incident support; this directly enables recovery of deleted log objects via retained/archived copies after a lifecycle-triggered deletion.
- T1486detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including file access/deletion, privilege use, config changes, and physical logs), and identification of suspected incidents such as malware infection, which surfaces ransomware encryption activity after it begins.
- T1486recovers — A.8.15 requires determining what to log (including file access/deletion, configuration changes, privilege use), protecting logs against tampering or loss, and performing analysis/correlation to identify incidents; this directly supports post-encryption recovery investigations and evidence-based restoration per the control's stated purpose, with the named remainder being that it does not itself perform data restoration (that is A.8.13).
- T1486responds — A.8.15 requires log analysis and correlation (including of physical events, alarms, configuration changes, privilege use, and anomalous patterns via SIEM/UEBA/threat intel) to identify suspected/actual incidents such as ransomware encryption, then feeds them into the incident management process (5.25) for response; this directly supports containment/eradication once the technique is underway, with the named remainder being impact (already-encrypted data) that responding does not undo.
- T1489detects — A.8.15 explicitly requires logging, analysis, and monitoring of events including use of privileges, system configuration changes, alarms from access control/IDS, activation/deactivation of security systems, and anomalous behaviour via SIEM/UEBA/correlation to identify incidents, which surfaces T1489 (service stop/disable) in most cases as it triggers these logged indicators.
- T1489responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. service-stop alarms, anomalous behaviour, correlation for incident management per 5.25), which is the core of `responds` once the technique is underway; it is only partial because the clause stops at identification/analysis and does not itself perform containment or eradication.
- T1490detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of logs (including physical), and identification of suspected incidents such as probing or malware that commonly precede or accompany T1490 actions on recovery features.
- T1491detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including via SIEM/IDS/UEBA rules, pattern analysis, and correlation of access/configuration changes), which surfaces defacement after it occurs on monitored systems; it does not cover all platforms/vectors or pre-empt the act itself.
- T1491.001detects — A.8.15 explicitly requires logging, protection, and analysis of events including system configuration changes, privilege use, file accesses/deletions, alarms, and anomalous behaviour via SIEM/UEBA/threat intel/correlation, which surfaces internal defacement (e.g. altered websites, login messages, desktop wallpaper) after it occurs.
- T1491.001responds — A.8.15's log analysis, anomaly detection, and incident identification (e.g. via SIEM/UEBA/correlation) surface defacement once performed, feeding the incident response process (5.25), but do not themselves contain or eradicate it.
- T1491.002detects — A.8.15 requires logging, analysis, and monitoring of events including system access attempts, configuration changes, alarms, security system activation, anomalous behaviour, and correlation with threat intelligence — all of which surface external defacement once it has occurred on web-facing assets.
- T1495detects — A.8.15 requires log analysis and monitoring (including of system activities, configuration changes, privilege use, security system activation, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface firmware corruption indicators post-event, but this is a minority slice — the control's focus is on OS/application/event logging rather than low-level firmware or non-volatile memory manipulation on the listed platforms.
- T1496detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and monitoring of resource-use indicators (privileged use, system changes, network activity, alarms) that surface cryptomining, proxying, or spam patterns as IOCs.
- T1496responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of logs including resource usage patterns) surface suspected resource hijacking once underway as an information security event, feeding into incident management (5.25) for response, but this is only a slice of the broad technique (e.g. does not address all forms like proxyjacking or SMS spam).
- T1496.001detects — A.8.15 explicitly requires logging, analysis, and monitoring of system activities, resource access, configuration changes, privilege use, anomalous behaviour via UEBA/SIEM/IDS, and correlation to identify indicators of compromise such as unexpected high CPU consumption from mining processes.
- T1496.001responds — A.8.15 requires log analysis and monitoring to identify anomalous resource consumption or indicators of compromise (e.g. via SIEM, UEBA, trend analysis, and correlation), which surfaces an in-progress compute hijacking for further investigation and incident response per 5.25, but does not itself contain or eradicate the technique once underway.
- T1496.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, DNS log checks for malicious C2, correlation of events, and identification of indicators like probing or malware that surface bandwidth hijacking, botnet activity, or scanning as security events.
- T1496.002responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS correlation, and explicit tie to incident management (5.25) enable response once bandwidth hijacking (botnet, proxyjacking, scanning) is underway, but this is only a detection-to-response slice with no containment or eradication mechanism in the control itself.
- T1496.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of logs (including from web forms, applications, and network activity), and identification of suspected incidents such as probing or anomalous behaviour that directly surfaces SMS-pumping patterns before or while availability and cost impacts occur.
- T1496.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and monitoring of access attempts, configuration changes, privilege use, and resource activity — all of which surface SaaS hijacking behaviors such as unexpected service enablement, bulk messaging, or anomalous AI proxying after the fact.
- T1496.004prevents — A.8.15's logging of access attempts, privilege use, configuration changes, identity creation and anomalous behaviour (via analysis, SIEM, UEBA, threat intel) can surface the initial compromise or service-enablement step that enables SaaS hijacking, thereby preventing the technique in some but not most cases; it does not stop already-compromised credential abuse or quota exhaustion itself.
- T1497detects — A.8.15's log analysis and monitoring explicitly surface anomalous behavior, indicators of compromise, and events like security tool usage or unusual activity that map to T1497's detection of monitoring artifacts (e.g. Wireshark, Sysinternals) or sandbox checks, but only for executed techniques on monitored systems and not the pre-execution evasion itself.
- T1497.001detects — A.8.15 requires log analysis and monitoring of events (including system activities, configuration changes, privilege use, and anomalous behaviour via SIEM/UEBA/correlation) that can surface many of the discovery-oriented system checks and artifacts named in T1497.001, but does not mandate coverage of all possible VME checks (especially low-level hardware, memory, or non-event-based ones) nor guarantee detection before the technique completes.
- T1497.002detects — A.8.15's log analysis and monitoring explicitly surface anomalous user activity, UEBA patterns, and indicators of compromise that can include the specific user-interaction artifacts (mouse movements, browser history, file counts, interaction timing) this technique relies on or leaves behind
- T1497.003detects — A.8.15 requires synchronized time sources, log analysis for anomalous behaviour, and correlation of events (including physical monitoring and UEBA), which can surface time-based sandbox evasion as anomalous activity or an IOC; this is genuine but only a slice, as the control does not mandate instrumentation of the specific API calls or time-check patterns themselves.
- T1498detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of logs (including network/DNS/firewall/physical), and identification of suspected incidents such as probing of firewalls, which surfaces most forms of network DoS traffic or its precursors.
- T1498recovers — A.8.15's log analysis, correlation, and identification of incidents (including anomalous traffic or probing) can support post-DoS recovery by enabling faster investigation and restoration of availability, but the control itself performs no restoration of service or bandwidth.
- T1498responds — A.8.15 requires log analysis and correlation (including of network events, alarms, and anomalous traffic) to identify suspected incidents such as probing or bandwidth-exhausting attacks once underway, feeding the incident management process; this is the core of `responds` but stops at detection/analysis without mandating containment or eradication actions.
- T1498.001detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, DNS log checks for malicious outbound C2, correlation of events, and identification of indicators like probing of firewalls or anomalous traffic patterns, which surfaces Direct Network Flood (including botnet-driven volumetric attacks) once underway.
- T1498.001responds — A.8.15 requires log analysis and correlation (including network/DNS/IDS events and anomalous traffic patterns) to identify suspected incidents such as probing or flooding once underway, feeding the incident response process, but does not itself contain or eradicate the flood.
- T1498.002detects — A.8.15 explicitly requires logging, analysis, and monitoring of network events, anomalous behaviour, DNS logs for outbound connections to malicious servers, and correlation to identify indicators of compromise such as probing or high-volume traffic patterns that match reflection amplification DoS.
- T1498.002recovers — A.8.15's log analysis, correlation, and identification of incidents (including network anomalies like probing or high-volume traffic) supports post-DoS investigation and recovery activities, but does not itself restore availability or functionality of the targeted system(s) and network.
- T1498.002responds — A.8.15's log analysis, correlation, and identification of suspected incidents (e.g. probing of firewalls, anomalous outbound DNS) can surface an ongoing reflection amplification flood once underway for further incident handling, but this is limited to detection-plus-response workflow rather than containment/eradication itself.
- T1499detects — A.8.15 explicitly requires logging of access attempts, privilege use, configuration changes, alarms, security system activation, and anomalous behaviour via SIEM/IDS/UEBA/correlation, which surfaces the resource-exhaustion or crash symptoms of endpoint DoS (and many of its precursors) after the fact.
- T1499recovers — A.8.15's log analysis and correlation explicitly support incident investigation and identification of events leading to incidents, which aids recovery from the availability loss caused by Endpoint DoS once the attack has occurred.
- T1499responds — A.8.15 requires log analysis and correlation (including of alarms, access attempts, configuration changes, and anomalous behaviour via SIEM/IDS/UEBA) to identify suspected incidents such as probing or resource exhaustion, which feeds the incident management process (5.25) for containment/eradication once the DoS is underway; this is a genuine but minority slice of the broad technique that spans multiple unlogged layers and botnet-scale traffic.
- T1499.001detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, threat intelligence, and monitoring of network activity (including DNS, firewalls, and anomalous behaviour) to identify indicators of compromise such as probing or resource-exhaustion events; this surfaces the flood technique in flight for most cases, with the bounded remainder being fully stealthy or non-network floods outside configured scopes.
- T1499.001responds — A.8.15 requires log analysis and correlation (including of network events, alarms, and anomalous behaviour) to identify suspected incidents such as probing or resource-exhaustion patterns once underway, feeding the incident-management process; this is exactly `responds` but only partial because the clause stops at detection/analysis and does not itself perform containment or eradication.
- T1499.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of network events, resource access attempts, DNS logs for malicious outbound, and correlation to identify incidents such as probing or resource exhaustion that match the flood/renegotiation patterns in T1499.002.
- T1499.002responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, suspected incidents (e.g. probing or resource exhaustion patterns), and feed them into the incident management process (5.25) for response once the flood is underway.
- T1499.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of resource-related events (access attempts, configuration changes, alarms, application transactions, physical events) that surface application-exhaustion floods as indicators of compromise or anomalous behavior.
- T1499.003responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. anomalous resource usage, probing) for further investigation under the incident management process, which is the core of `responds`; it does not itself contain or eradicate the flood.
- T1499.004detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and security events (including crashes, resource exhaustion, or exploitation patterns via SIEM/UEBA/correlation), which surfaces this DoS technique in flight on the organization's estate; partial because the control's scope is limited to what is logged/analyzed per policy (e.g. no guarantee of coverage for all zero-day exploits, physical-only vectors, or unmonitored systems).
- T1499.004responds — A.8.15 requires log analysis and correlation (including of crashes, alarms, configuration changes, and anomalous behaviour) to identify suspected incidents for further investigation under the incident management process, which is the core of `responds`; it does not itself contain or eradicate the exploitation.
- T1505detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of events such as configuration changes, privilege use, application transactions, and alarms that would surface installation of a malicious server component.
- T1505.001detects — A.8.15 explicitly requires logging of privilege use, configuration changes, system activities, application transactions, and anomalous behaviour via SIEM/UEBA/threat-intelligence-driven analysis, which surfaces malicious stored-procedure creation, modification, or invocation (including xp_cmdshell or CLR abuse) after it occurs.
- T1505.002detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, application transactions, and anomalous behaviour analysis (including via SIEM/UEBA/threat intel), which surfaces registration and invocation of a malicious Exchange transport agent as an information security event.
- T1505.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of events (including access attempts, configuration changes, privilege use, and web/application transactions), and identification of indicators like probing or malware that surface a deployed web shell after it is present.
- T1505.003responds — A.8.15 requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and feeding suspected incidents (e.g. probing or malware) into the incident management process (5.25), which directly enacts the containment/eradication steps that `responds` names once a web shell is present and active; it is only partial because the clause stops at identification/analysis/hand-off and does not itself perform the response actions.
- T1505.004detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, application transactions, security system activation, and anomalous behaviour via log analysis (SIEM/UEBA/IDS rules, threat intel, DNS logs, usage reports), which surfaces installation and use of malicious IIS components/modules on a Windows web server.
- T1505.005detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, configuration changes, service-related events, alarms from access control/IDS, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the Registry modification, DLL replacement, and resulting RDP/terminal service anomalies on Windows.
- T1505.006detects — A.8.15 explicitly requires logging, analysis, and monitoring of events including system configuration changes, privilege use, utility program execution, alarms from access control and security systems (e.g. IDS), anomalous behaviour via SIEM/UEBA/threat intel, and correlation of logs to identify indicators of compromise such as malware or probing; this surfaces malicious VIB installation and boot-persistent changes on ESXi in a monitored environment but only for events inside the chosen scope and tooling, leaving gaps for unmonitored hypervisors or stealthy VIBs that avoid logged indicators.
- T1518detects — A.8.15 requires log analysis, anomaly detection via SIEM/UEBA/threat intel, and specific monitoring (e.g. of system activities, privilege use, configuration changes, and installed tools) that surfaces software enumeration as anomalous behavior or an indicator of compromise.
- T1518responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification directly surface Software Discovery in flight or post-execution as an information security event, enabling response under the linked incident management process (5.25).
- T1518.001detects — A.8.15 explicitly requires log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomalous behaviour detection, correlation of logs including security system alarms and AV/IDS activation) that surface the execution of discovery commands and the presence/behaviour of security software itself.
- T1518.002detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, file access/deletion, security system activation, and especially log analysis + correlation (SIEM/UEBA/threat intel) to surface anomalous behavior and indicators of compromise such as backup software discovery commands or processes.
- T1525detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of configuration changes, privilege use, file access/deletions, and security system events, which surfaces many (but not all) indicators of an internal image being implanted or modified in a registry.
- T1526detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, unusual activity (including via SIEM, UEBA, threat intel, and correlation of events such as access attempts, privilege use, configuration changes, and security system activation), which surfaces cloud service enumeration after initial access as an information security event.
- T1528detects — A.8.15 mandates logging of access attempts, privilege use, configuration changes, identity creation/modification, alarms, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces token theft (especially post-compromise API calls, OAuth grants, or IMDS requests) as security events or indicators of compromise.
- T1528responds — A.8.15 requires log analysis and correlation (including of access attempts, privilege use, alarms, and anomalous behaviour) to identify suspected incidents such as probing or unauthorized access that can surface token theft once underway, feeding the incident management process, but does not itself contain or eradicate the adversary action.
- T1529detects — A.8.15 explicitly requires logging, analysis, and monitoring of events including system activities, privilege use, configuration changes, security system activation/deactivation, and anomalous behaviour via SIEM/UEBA/correlation to identify incidents or indicators of compromise; this surfaces T1529 (shutdown/reboot commands, privilege acquisition, or post-impact use) in most cases once executed.
- T1530detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of access logs (including successful/rejected resource access, privilege use, configuration changes), and identification of indicators of compromise such as probing or unauthorized access to protected resources, which surfaces T1530 when it triggers detectable logging events.
- T1530prevents — A.8.15 mandates logging of access attempts (successful/rejected), privilege use, configuration changes, and anomalous behaviour analysis (including via SIEM/UEBA/threat intel), which can surface misconfigurations or credential abuse leading to T1530 before the data is taken; this constrains some but not most vectors (e.g. public buckets, leaked creds from non-log sources, or direct API access without triggering logged events).
- T1530responds — A.8.15's log analysis and incident identification (e.g. anomalous access, alarms, configuration changes) plus linkage to 5.25 incident management enables response once T1530 data access is underway, but only for logged/observable cases rather than all stealthy or misconfig-driven exfiltration.
- T1531detects — A.8.15 explicitly requires logging of account-related events (creation/modification/deletion of identities, privilege use, access attempts, configuration changes) plus analysis to surface anomalous behaviour and indicators of compromise, which directly detects T1531 actions such as account deletion, locking or credential changes.
- T1531responds — A.8.15 requires log analysis and correlation (including of account changes, privilege use, identity creation/deletion, and access attempts) to identify suspected incidents for further investigation under the incident management process; this surfaces and enables response to T1531 once the account manipulation has occurred, but does not itself contain or eradicate it.
- T1534detects — A.8.15 mandates logging, protection, and analysis of events (including access attempts, privilege use, configuration changes, anomalous behaviour via SIEM/UEBA/correlation, and indicators of compromise) that directly surface internal spearphishing campaigns once they are underway.
- T1534responds — A.8.15's log analysis, correlation, anomaly detection (UEBA/SIEM/IDS), and explicit tie to feeding the incident management process (5.25) let responders contain/eradicate an ongoing internal spearphishing campaign once it is underway; it is not the primary response mechanism and does not address every vector (e.g. physical-device compromise or chat-app lures outside monitored logs).
- T1535detects — A.8.15's log analysis, correlation, UEBA, threat intel, and specific monitoring (including of successful/unsuccessful access attempts, configuration changes, privilege use, and anomalous behavior) can surface creation of resources in unused regions as an indicator of compromise, but only where those regions fall inside the organization's defined monitoring scope and logging policy; the control itself sets that scope rather than mandating universal coverage of all possible cloud regions.
- T1537detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/threat intel, correlation of events (including successful access, configuration changes, privilege use, file access/deletion, and backups), and identification of indicators of compromise, which surfaces T1537's internal cloud transfers, API calls, SAS links, or backup creation to another account as anomalous.
- T1537responds — A.8.15's log analysis, anomaly detection, correlation, and explicit tie to feeding the incident management process (5.25) let responders know an internal cloud transfer has occurred once it is underway, but the control only surfaces the event and does not itself contain or eradicate it.
- T1538detects — A.8.15 explicitly requires logging of access attempts, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces an adversary using stolen credentials in a cloud dashboard as an information security event or indicator of compromise.
- T1539detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection on access attempts, DNS, physical logs, and correlation to surface indicators of compromise including session-cookie theft vectors such as malware, JS injection, and anomalous authenticated behavior.
- T1539prevents — A.8.15 mandates logging of access attempts, privilege use, configuration changes, and anomalous behaviour plus protected immutable logs and analysis that can surface cookie theft (e.g. malware, JS injection, or anomalous auth), thereby stopping many realisations of T1539; it leaves the actual theft vectors (browser memory scraping, MitM proxies, local malware) untouched.
- T1539responds — A.8.15 requires log analysis and correlation (including of access attempts, alarms, and anomalous behaviour) to identify suspected incidents such as probing or malware, which feeds the incident management process (5.25) that performs containment/eradication once the cookie-theft event is underway; this is a genuine but minority slice because the clause stops at detection/analysis and does not itself contain or eradicate.
- T1542detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including boot-time security system activation/deactivation and configuration changes), and physical monitoring to surface indicators of compromise such as firmware tampering that could be logged at the pre-OS layer or via correlated events.
- T1542.001detects — A.8.15 requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and explicit review of physical monitoring logs plus correlation to identify incidents like probing; this surfaces some firmware modification (e.g. via boot-time events or anomalous system activity) but leaves the bulk of stealthy BIOS/UEFI overwrites (especially pre-boot or on network devices) outside typical event logging scope.
- T1542.002detects — A.8.15 requires log analysis and monitoring (including of system activities, configuration changes, privilege use, security system activation, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface indicators of component firmware modification after the fact, but this is a minority slice because the technique executes outside the OS with no guaranteed host-visible events or logs.
- T1542.003detects — A.8.15 requires log analysis and monitoring (including of system activities, configuration changes, privilege use, boot-related events where logged, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface indicators of a bootkit after the fact; it does not guarantee detection of pre-OS modifications that may produce no usable logs.
- T1542.004detects — A.8.15 explicitly requires logging of system configuration changes, privilege use, boot-time security system activation/deactivation, and log analysis (with SIEM/IDS/UEBA/threat intel) that can surface anomalous firmware/boot behavior as an indicator of compromise; this is genuine detection coverage for the technique but only a slice because ROMMONkit is a low-level, hard-to-observe persistence mechanism on network devices that may evade standard event sources and correlation.
- T1542.005detects — A.8.15 requires log analysis and monitoring (including of configuration changes, privilege use, system activities, network connections to malicious servers, and anomalous behaviour via SIEM/UEBA/correlation) that can surface indicators of a malicious TFTP server or unauthorized boot image, but this is limited to observable post-boot events on covered systems and does not guarantee detection of the configuration manipulation or netboot itself.
- T1543detects — Creation or modification of system services and processes is captured in configuration-change and privilege-use logs, exposing persistence mechanisms.
- T1543responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. anomalous service changes, privilege use, config alterations) for further investigation under incident management (5.25), which is the core of `responds`; it is only partial because the clause stops at identification/analysis and does not itself perform containment or eradication.
- T1543.001detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, file accesses, identity creation/modification/deletion, and anomalous behaviour via log analysis (SIEM/UEBA/threat intel/correlation), which surfaces the .plist placement, launchd loading, and login-time execution of a Launch Agent as an indicator of compromise.
- T1543.002detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, service/system activations, file accesses and anomalous behaviour, then mandates analysis (SIEM/UEBA/rules/threat intel/correlation) that surfaces indicators of a new or modified systemd service as an information security event
- T1543.002prevents — A.8.15 mandates logging of configuration changes, privilege use, system activities, and file accesses (including in /etc/systemd/system and related paths), which surfaces the creation or modification of a malicious .service file or generator; this constrains the persistence technique by enabling detection and response before it fully succeeds, but does not stop the adversary from creating or altering the unit file itself.
- T1543.002responds — A.8.15 requires log analysis and correlation (including of configuration changes, privilege use, service activation/deactivation, and anomalous behaviour) to identify suspected incidents once underway for further investigation under incident management; this surfaces and supports response to the technique but does not contain or eradicate it.
- T1543.003detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, service-related events (via alarms, utility/app use, and identity changes), plus SIEM/IDS-driven analysis, UEBA, and correlation to surface anomalous behavior and indicators of compromise such as new or modified Windows services.
- T1543.003responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification directly support responding to a realized T1543.003 service creation/modification once it has executed, but the clause stops at detection/analysis and hands off to 5.25 incident management rather than performing containment/eradication itself
- T1543.004detects — A.8.15 explicitly requires logging of system configuration changes, privilege use, file access/deletion, security system activation, and anomalous behaviour via log analysis (SIEM/UEBA/threat intel/correlation), which surfaces the plist creation, modification, or hijacking of a Launch Daemon as an indicator of compromise.
- T1543.004responds — A.8.15's log analysis and monitoring activities (SIEM/IDS correlation, anomalous behaviour detection, review of system changes/privilege use/access attempts) can surface a running Launch Daemon once it has executed at startup, enabling incident response; this is only a slice because the control is silent on containment/eradication steps and many Launch Daemon artifacts (plist edits, pre-login execution) occur before or outside routine log review.
- T1543.005detects — A.8.15's log analysis, monitoring of system activities/privilege use/configuration changes/resource access, and anomaly detection (SIEM/UEBA/IDS correlation) can surface container service modifications or anomalous DaemonSet/pod deployments after they occur, but this is only a slice — the clause does not mandate coverage of container-specific artifacts, Kubernetes control-plane events, or out-of-scope physical/third-party logs, and detection depends on what the implementer chooses to log/analyze.
- T1546detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of logs (including access attempts, privilege use, config changes, and security system events), and identification of suspected incidents, which surfaces T1546 triggers and their execution artifacts after they run.
- T1546responds — A.8.15 requires log analysis and correlation (including of access attempts, privilege use, config changes, alarms, and security system activation) to identify suspected incidents for further investigation under the incident management process; this surfaces and acts on T1546 once the triggered execution has already run and produced observable events, but only for the subset of triggers that generate detectable logs rather than all mechanisms or the creation/modification step itself.
- T1546.001detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, file access/deletion, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces Registry modifications and suspicious file-association handlers after they occur.
- T1546.002detects — A.8.15 explicitly requires logging of user activities, privilege use, configuration changes, alarms, security system activation, and anomalous behaviour via log analysis (including UEBA, SIEM rules, and correlation), which surfaces screensaver-based persistence (registry tampering and PE execution on inactivity) once it occurs.
- T1546.003detects — A.8.15 explicitly requires logging of events including successful/rejected access attempts, privilege use, system configuration changes, identity creation/modification/deletion, and anomalous behaviour via log analysis (SIEM/UEBA/IDS rules, correlation, threat intel); these directly surface WMI event subscriptions used for persistence/privilege escalation (e.g. via login, uptime, or config events), with the bounded remainder being stealthy or non-logged subscriptions outside monitored scope.
- T1546.003prevents — A.8.15 mandates logging of privilege use, system configuration changes, and security system activation/deactivation (including relevant WMI events), plus protected analysis to surface anomalies, which can stop many but not all WMI event subscriptions from being planted or persisting undetected.
- T1546.003responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including via SIEM/IDS/UEBA correlation), which can surface a running WMI event subscription once it triggers, but does not contain, eradicate or act on the adversary once underway.
- T1546.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including shell activity, privilege use, configuration changes, and file access), and identification of indicators of compromise such as suspicious commands or modifications, which surfaces T1546.004 post-execution on Linux/macOS systems.
- T1546.005detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including via SIEM/IDS/UEBA rules and correlation), which can surface trap-based persistence when it triggers observable events, but the control's scope is limited to what is explicitly logged/analyzed per the organization's policy and does not guarantee coverage of trap registration or interrupt signals themselves.
- T1546.006detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of events (including process/file changes, privilege use, and system activities), and identification of indicators of compromise, which can surface LC_LOAD_DYLIB modifications on monitored macOS systems; however, the control's scope is set by organizational policy and does not mandate coverage of this specific low-level Mach-O binary tampering technique.
- T1546.007detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, configuration changes, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces the registry writes, netsh.exe invocations, and resulting DLL execution as security events or indicators of compromise.
- T1546.008detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, system configuration changes, alarms from access control systems, security system activation, and log analysis (with SIEM/IDS/UEBA rules, anomalous behaviour detection, and correlation) that surfaces indicators of the binary replacement, registry changes, or unexpected SYSTEM-level execution at the login screen.
- T1546.008responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (e.g. via SIEM/UEBA/correlation of access, privilege-use, configuration changes and security-system events), which surfaces T1546.008 once the binary/registry change or key-triggered execution occurs and hands it to incident response; it does not contain or eradicate the persistence itself.
- T1546.009detects — A.8.15 explicitly requires logging of system activities, privilege use, process creation events, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces AppCert DLL abuse as it triggers ubiquitous process-creation APIs and produces observable registry/process anomalies.
- T1546.009responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification directly surface the technique once it runs (e.g. via registry changes, privilege-use events, process-creation anomalies), enabling response under 5.25; mostly because physical/log-protection slices and incomplete coverage of every possible trigger leave a bounded remainder.
- T1546.010detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, process-start events, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces AppInit_DLLs abuse as a persistence or privilege-escalation indicator after it occurs.
- T1546.011detects — A.8.15 explicitly requires logging and analysis of events including use of privileges, system configuration changes, alarms from access control/IDS, anomalous behaviour via SIEM/UEBA/threat intel, and correlation of logs (including physical), which surfaces application shimming as a persistence/elevation technique in most realistic cases.
- T1546.011responds — A.8.15's log analysis, anomaly detection, SIEM/IDS/UEBA correlation, and explicit tie to identifying suspected incidents for the incident management process (5.25) directly enable response once the shim-based persistence/elevation technique is underway.
- T1546.012detects — A.8.15 explicitly requires logging, analysis, and monitoring of events including successful/rejected access attempts, privilege use, system configuration changes, alarms from access control/IDS, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces IFEO registry abuse, debugger hijacks, and privilege-escalation/persistence activity as security events or indicators of compromise.
- T1546.013detects — A.8.15 explicitly requires logging of privilege use, system activities, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the profile modification and its triggered execution as an indicator of compromise.
- T1546.014detects — A.8.15 explicitly requires logging of events including successful/rejected access attempts, privilege use, system configuration changes, identity creation/modification, and alarms from access control systems, plus analysis via SIEM/IDS/UEBA rules and correlation to identify anomalous behaviour and indicators of compromise; this surfaces emond rule installation and triggered actions on macOS (a named subset of the technique), with the bounded remainder being stealthy rule placement that evades the specific monitored event types or analysis scope.
- T1546.015detects — A.8.15 explicitly requires logging of registry changes, privilege use, system configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces COM hijacking (a Registry-tampering persistence technique) after it occurs; the named remainder is stealthy or non-logged hijacks that evade the monitored event set.
- T1546.016detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, successful/rejected access attempts, and anomalous behaviour via log analysis (SIEM/UEBA/IDS rules, correlation, threat intel), which surfaces installer-script execution with elevated rights or post-install actions as indicators of compromise.
- T1546.016responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/IDS rules, UEBA, and review of access/configuration changes) surface the post-install execution or privilege-elevating script once it runs, feeding the 5.25 incident process, but this is only a slice of the technique's full surface (pre-install, non-logged installer actions, or non-anomalous legitimate packages).
- T1546.017detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, file accesses, security system activation, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces udev rule modifications (privileged file writes in /etc/udev/rules.d etc.) and the resulting anomalous executions; the bounded remainder is stealthy in-memory or non-logged rule triggers that evade the listed monitoring scope.
- T1546.018detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, file accesses, security-system activation, identity creation/modification, and anomalous behaviour via SIEM/UEBA/threat-intelligence-driven analysis, all of which surface Python startup-hook abuse when it executes on monitored systems.
- T1547detects — A.8.15 explicitly requires logging of boot/logon-related events (successful/rejected access attempts, privilege use, configuration changes, identity creation/modification), synchronized time sources, and log analysis with UEBA/SIEM/IDS rules, trend analysis, and correlation to surface anomalous autostart behavior or indicators of compromise.
- T1547.001detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, file accesses/deletions, and alarms, plus analysis with SIEM/UEBA/rules/threat intel to surface anomalous behavior and indicators of compromise such as persistence mechanisms; this directly surfaces T1547.001 activity on Windows, with the bounded remainder being stealthy or non-logged variants (e.g., very early boot or fully masqueraded entries outside monitored events).
- T1547.002detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, successful/rejected access attempts, and log analysis (with SIEM/UEBA/IDS rules, anomaly detection, and correlation) that surfaces LSA/registry autostart abuse at boot as anomalous behavior or an indicator of compromise.
- T1547.003detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, service activation/deactivation, and log analysis (including SIEM/IDS/UEBA rules, anomalous behaviour, and correlation) that surfaces time-provider registration and boot-time DLL loading as an indicator of compromise.
- T1547.003prevents — A.8.15 mandates logging of configuration changes, privilege use, system activities and alarms, which would surface the admin-level registry edit that registers a malicious time-provider DLL; this constrains the technique from completing undetected on systems under the logging regime, but the control only records rather than blocks the registration or boot-time load itself.
- T1547.003responds — A.8.15's log analysis and monitoring explicitly surface anomalous behaviour, privilege use, configuration changes, and security system events that can represent the registration and boot-time execution of a malicious time-provider DLL, enabling incident response once underway.
- T1547.004detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, system configuration changes, identity creation/modification/deletion, and log analysis (with SIEM/UEBA/correlation) that surfaces anomalous behavior and indicators of compromise such as malicious Winlogon registry modifications at logon time.
- T1547.004responds — A.8.15 requires log analysis and correlation (including of successful/rejected access, privilege use, configuration changes, and alarms) to identify and investigate suspected incidents once they occur, which engages the core of `responds` for a Winlogon persistence artifact that would appear in those logs; it does not itself contain or eradicate the DLL/registry change.
- T1547.005detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, successful/rejected access attempts, and anomalous behaviour via SIEM/UEBA/IDS correlation plus physical logs, which surfaces SSP Registry modifications and LSA DLL loads as indicators of compromise.
- T1547.006detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including privilege use, system changes, security system activation, and log tampering), and identification of indicators of compromise such as malware or probing, which surfaces LKM/kext rootkit behavior on Linux/macOS after it runs.
- T1547.007detects — A.8.15 explicitly requires logging of login events, privilege use, application execution, configuration changes and anomalous behaviour, plus analysis via SIEM/UEBA/threat intel to surface indicators of compromise such as a malicious plist modification for auto-reopen; this directly surfaces the technique on macOS where the relevant events are in scope, with only a bounded remainder (e.g. fully offline or non-correlated cases) left unaddressed.
- T1547.008detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, security system activation/deactivation, and anomalous behaviour via SIEM/IDS/UEBA/correlation, which surfaces LSASS driver tampering as a detectable indicator of persistence; the remainder is stealthy in-memory or pre-boot driver loads outside standard event sources.
- T1547.009detects — A.8.15 explicitly requires logging and analysis of events including successful/rejected access attempts, privilege use, configuration changes, file access/deletion, startup-related system activities, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces shortcut modifications used for persistence on Windows.
- T1547.010detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, successful/rejected access attempts, and anomalous behaviour via SIEM/UEBA/IDS correlation plus physical logs, which surfaces the boot-time DLL load or Registry modification under SYSTEM context as an indicator of compromise.
- T1547.012detects — A.8.15 explicitly requires logging of privilege use, system configuration changes, service activation/deactivation, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the registry writes, spoolsv.exe restart, and elevated-DLL load that constitute this technique.
- T1547.012responds — A.8.15's log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomaly detection, correlation of events including privilege use, service changes, and alarms) can surface the anomalous boot-time DLL load or spoolsv behavior once the technique has executed, enabling incident response.
- T1547.013detects — A.8.15 explicitly requires logging of user activities, privilege use, system configuration changes, application execution, and anomalous behaviour via log analysis (including UEBA, SIEM, and correlation), which surfaces XDG Autostart modifications or the resulting malicious execution at login on Linux systems; the bounded remainder is stealthy or non-logged cases that evade the prescribed events and analysis.
- T1547.014detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, system configuration changes, identity creation/modification, and log analysis (with SIEM/UEBA/threat intel) that surfaces anomalous registry or login-time execution; this covers the T1547.014 technique in flight or post-execution with a bounded remainder for stealthy or non-logged variants.
- T1547.015detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, system configuration changes, application launches, and anomalous behaviour via log analysis (SIEM/UEBA/threat intel/correlation), which surfaces the addition or execution of a login item at user login on macOS.
- T1548detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/rules, correlation of events (including privilege use, access attempts, config changes, and security system activation), and identification of suspected incidents, which surfaces most T1548 abuse of elevation mechanisms after the fact.
- T1548.001detects — A.8.15 explicitly requires logging and analysis of privilege use, system activities, configuration changes, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces setuid/setgid abuse both when the bits are set on binaries and when they are later executed.
- T1548.002detects — A.8.15 explicitly requires logging of privilege use, successful/rejected access attempts, system configuration changes, alarms from access control systems, and log analysis (with SIEM/IDS/UEBA rules, anomalous behaviour detection, and correlation) that surfaces UAC bypass indicators such as unexpected elevation, auto-elevation via eventvwr.exe, or injection into trusted processes.
- T1548.002responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (including privilege-related events such as use of privileges, access attempts, and anomalous behaviour) and subject them to further investigation as part of incident management, which matches the `responds` verb once the bypass technique is underway; the extent is only partial because the control is scoped to what is logged/analyzed per policy rather than guaranteeing containment or eradication of every UAC bypass method.
- T1548.003detects — A.8.15 explicitly requires logging of privilege use, successful/rejected access attempts, configuration changes (including to sudoers), and log analysis with SIEM/UEBA/IDS rules to surface anomalous behaviour and indicators of compromise such as sudo caching abuse or tty_tickets tampering; the bounded remainder is in-memory or non-logged sudo actions outside the monitored events.
- T1548.003responds — A.8.15's log analysis, correlation, and incident-identification steps (including alarms, privilege use, configuration changes, and suspected incidents) enable response actions once sudo-caching or sudoers abuse is underway, but the control only surfaces the event and hands it off; it performs neither containment nor eradication itself.
- T1548.004detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, privilege use, and security events (including use of privileges, system access attempts, and alarms), which surfaces the credential-prompt and elevated-execution behaviour described in T1548.004; the remainder is events on unmonitored macOS endpoints or before analysis rules are tuned.
- T1548.005detects — A.8.15 explicitly requires logging of privilege use, access attempts, configuration changes, identity creation/modification, and log analysis (with SIEM/UEBA/threat intel) to identify anomalous behaviour and indicators of compromise, which surfaces most T1548.005 abuse of temporary elevation paths; the named remainder is stealthy impersonation cases where logs do not clarify the activity (per the technique note).
- T1548.005prevents — A.8.15 mandates logging of privilege use, access attempts, configuration changes, and identity modifications plus protected immutable analysis that can surface misconfigurations enabling temporary elevation; this constrains the technique in environments where detection leads to preemptive correction, but does not stop the permission structures or requests themselves from existing or being abused.
- T1548.005responds — A.8.15 requires log analysis and correlation (including of privilege use, access attempts, configuration changes, and alarms) to identify suspected incidents for further investigation under the incident management process, which is the core of `responds` once the technique is underway; partial because the control only surfaces the event and hands it off rather than performing containment or eradication itself.
- T1548.006detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, configuration changes, security system activation, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces TCC database manipulation or inherited elevated permissions as an information security event
- T1550detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, identity creation/modification, and log analysis (with SIEM/UEBA/threat intel) to identify anomalous behaviour and indicators of compromise such as stolen alternate auth material (e.g. tickets/hashes/tokens) used for lateral movement.
- T1550.001detects — A.8.15 explicitly requires logging of access attempts, privilege use, configuration changes, identity creation/modification, and anomalous behaviour via SIEM/UEBA/threat-intel analysis plus correlation, which surfaces stolen-token abuse that appears in logs as legitimate-looking API activity; the named remainder is stealthy or non-logged token use that evades the prescribed events and analysis.
- T1550.001responds — A.8.15 requires log analysis, anomaly detection, correlation and identification of suspected incidents (including via SIEM/UEBA/threat intel) which can surface token abuse as an in-flight or post-compromise event, but its core is logging/analysis rather than the containment/eradication actions that define `responds` on this lane, leaving most of the incident-handling response outside its scope.
- T1550.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of access attempts/privilege use/configuration changes, and identification of indicators of compromise, which surfaces PtH lateral movement after the fact in monitored environments.
- T1550.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including successful/rejected access, privilege use, system changes), and identification of indicators of compromise such as probing or anomalous authentication patterns that would surface PtT lateral movement after the fact.
- T1550.003responds — A.8.15's log analysis, correlation, and identification of suspected incidents (including anomalous access and privilege use) enable response once PtT lateral movement is underway, but this is only a slice of the full incident response workflow (containment/eradication) owned by 5.25/5.26.
- T1550.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including successful access, privilege use, configuration changes, and physical events), and identification of indicators of compromise such as probing or malware, which surfaces use of a stolen session cookie once the adversary authenticates and acts.
- T1550.004responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (e.g. via SIEM/UEBA/correlation), which surfaces the use of a stolen session cookie once it occurs and feeds the incident response process; this is genuine response but only a slice, as the control does not itself contain/eradicate the active session or actor.
- T1552detects — A.8.15 requires log analysis (with SIEM/UEBA/threat intel/correlation) and specific monitoring of access attempts, configuration changes, privilege use, file access/deletion, alarms, and anomalous behaviour, which surfaces the search activity and indicators of credential theft on covered systems.
- T1552.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including file-access, configuration changes, privilege use, and container/deployment logs), and identification of indicators of compromise such as probing or malware that surfaces credential-search activity.
- T1552.002detects — A.8.15 explicitly requires log analysis (with SIEM/UEBA/rules/threat intel/correlation) and monitoring of access attempts, privilege use, configuration changes, and anomalous behaviour to surface indicators of compromise such as registry queries for credentials.
- T1552.003detects — A.8.15 explicitly requires logging of shell-relevant events (user IDs, system activities, commands executed via utility programs/applications, privilege use, file accesses including history files) plus log analysis/monitoring for anomalous behaviour and indicators of compromise, which surfaces an adversary searching or exfiltrating a shell history file; the named remainder is that passive log analysis does not guarantee real-time detection of every stealthy read.
- T1552.004detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise, including review of file access (especially important files), privilege use, system activities, and correlation with threat intelligence — which surfaces adversaries searching for or accessing private key files on the estate.
- T1552.005detects — A.8.15 mandates logging of access attempts, privilege use, configuration changes, alarms, and anomalous behaviour plus explicit SIEM/IDS/UEBA correlation that surfaces queries to the metadata API (or SSRF to it) as indicators of compromise.
- T1552.006detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, threat intelligence, and correlation of logs (including successful/failed access, configuration changes, privilege use, and file access on SYSVOL) to surface anomalous behaviour and indicators of compromise such as enumeration of XML files or GPP credential access.
- T1552.007detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation, and review of access attempts/DNS/physical logs to surface indicators of compromise such as credential-gathering API calls in container environments.
- T1552.008detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of events such as access attempts, privilege use, configuration changes, and application transactions that would surface credential sharing or extraction in chat services.
- T1553detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, configuration changes, privilege use, alarms, and security system activation/deactivation to identify indicators of compromise and suspected incidents; this surfaces many T1553 methods (e.g. registry/file permission mods, cert abuse) but not all variants or platforms uniformly, and detection depends on what the organization chooses to log/analyze.
- T1553.001detects — A.8.15 explicitly requires log analysis and monitoring of events (including access attempts, configuration changes, privilege use, alarms from access-control systems, and anomalous behaviour via SIEM/IDS/UEBA) to identify indicators of compromise such as probing or malware-like activity; this surfaces Gatekeeper bypass attempts when they trigger observable events, but many bypass vectors (e.g. USB/cURL/no-quarantine-flag, first-launch-only checks, or stealthy file-attribute edits) produce no logged event at all.
- T1553.002detects — A.8.15 requires log analysis and monitoring (including of system activities, privilege use, configuration changes, alarms, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface code-signing certificate misuse or suspicious signed binaries post-execution, but this is scoped by what the organization chooses to log/analyze and does not inherently cover all signing events or pre-execution certificate acquisition.
- T1553.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules, correlation, and review of access attempts/changes/privileges to surface indicators of compromise; this can catch the registry modifications, DLL loads, or anomalous signature-validation behaviour that result from SIP/trust-provider hijacking, but only where those events fall inside the chosen logging scope and analysis rules — the control does not mandate instrumentation of every possible hijack vector.
- T1553.004detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, threat intelligence, and correlation of events (including privilege use, config changes, system activities, and anomalous behaviour) to identify indicators of compromise such as root-certificate installation; this surfaces the technique on monitored systems but is scoped by what the organization chooses to log/monitor and does not guarantee detection of every installation vector or platform.
- T1553.005detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including via SIEM/IDS/UEBA rules, DNS checks, and correlation), which can surface MOTW-bypass activity when it triggers observable events such as suspicious file access, privilege use, or malware-like behaviour, but the control does not mandate detection of the specific technique itself and many bypasses (e.g. silent local execution of untagged containers) produce no distinct loggable event.
- T1553.006detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and specific events such as changes to system configuration, use of privileges, and activation/deactivation of security systems; these directly surface the policy-modification commands, registry changes, and reboot artifacts named in T1553.006, with the bounded remainder being kernel-memory edits that may evade standard logging.
- T1554detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of events including binary changes, privilege use, configuration changes, and file access/deletion to surface indicators of compromise such as modified host binaries.
- T1555detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts (including to protected resources) to surface indicators of compromise such as credential access from password stores.
- T1555.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including successful/rejected access, privilege use, system changes), and identification of indicators of compromise such as probing or malware, which surfaces Keychain dumping via the security command or direct file reads on macOS.
- T1555.002detects — A.8.15 explicitly requires log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomalous behaviour detection, correlation of logs including successful/failed access and privilege use) that can surface indicators of a privileged process-memory read, but the control's scope is event logging rather than direct memory-access or process-injection telemetry, leaving a large slice of the technique unseen.
- T1555.003detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, correlation, and review of access attempts, privilege use, configuration changes, and process activity that surface browser credential theft (file reads of Login Data, SQL queries, memory searches, or related anomalies) in most cases.
- T1555.004detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, correlation of access/use-of-privilege/system events, and identification of indicators of compromise, which surfaces the enumeration, file reads, API abuse, backup extraction, and password-recovery actions described in T1555.004; the bounded remainder is fully stealthy in-memory or non-logged credential-manager access.
- T1555.004responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification explicitly surface credential-dumping activity (e.g. vaultcmd.exe, CredEnumerateA, file reads of .vcrd/.vpol) once underway, feeding the incident management process.
- T1555.005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and monitoring of access attempts, privilege use, configuration changes, and security system events, which surfaces password manager credential extraction or brute-force attempts in memory, files, or logs.
- T1555.006detects — A.8.15 explicitly requires logging of privilege use, successful/rejected access attempts, system activities, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the high-privileged access or API calls (get-secret-value, az key vault secret show, etc.) that realise T1555.006; the named remainder is stealthy or non-audited retrievals outside the chosen log scope.
- T1556detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including privilege use, config changes, access attempts, and security system activation), and identification of suspected incidents such as probing or malware that commonly accompany authentication process modification.
- T1556responds — A.8.15's log analysis, anomaly detection, and incident identification (e.g. via SIEM/UEBA/correlation) surface T1556 once it has run and feed the 5.25 incident management process for containment/eradication, but the control's core is recording/monitoring rather than active response actions and many T1556 variants (esp. on IaaS/SaaS/identity providers) leave no detectable log artifact at all
- T1556.001detects — A.8.15 explicitly requires logging of privilege use, system access attempts, configuration changes, security system activation, and log analysis (with SIEM/UEBA/IDS rules, anomalous behaviour detection, and correlation) that surfaces domain controller patching of LSASS as an indicator of compromise.
- T1556.002detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, and correlation of events (including successful/rejected access attempts, privilege use, configuration changes, and anomalous behaviour) to surface indicators of compromise such as a malicious password filter DLL registering or receiving plaintext credentials.
- T1556.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/rules, correlation of events (including successful/rejected access, privilege use, configuration changes, and security system activation), and identification of indicators of compromise such as probing or malware, which surfaces PAM modifications or anomalous authentication behavior on Linux/macOS systems.
- T1556.003responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/UEBA/IDS rules on access attempts, config changes, privilege use, and alarms) surface PAM modifications once they trigger observable events, enabling response; this is bounded by stealthy patches that produce no detectable log events.
- T1556.004detects — A.8.15 requires log analysis and monitoring (including of system activities, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface indicators of a backdoored network device image or its use, but this is post-compromise detection of effects rather than guaranteed discovery of the image patch itself, and many network device events fall outside standard logging scope.
- T1556.005detects — A.8.15 explicitly requires logging of privilege use, configuration changes, identity creation/modification, and anomalous behaviour via SIEM/UEBA/threat-intelligence analysis, which surfaces the setting of AllowReversiblePasswordEncryption (a privileged config change) and the resulting credential artefacts.
- T1556.006detects — A.8.15 explicitly requires logging of privilege use, configuration changes, successful/rejected access attempts, security system activation/deactivation, and log analysis (with SIEM/IDS/UEBA rules, anomaly detection, and correlation) that surfaces MFA modifications or bypasses as indicators of compromise or anomalous behaviour.
- T1556.007detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including successful/rejected access, privilege use, config changes, and identity creation/modification), and identification of indicators of compromise such as probing or backdoors, which surfaces the on-premises/cloud authentication tampering and credential-harvesting artifacts of T1556.007; the remainder is purely cloud-side modifications that leave no on-premises log trail.
- T1556.008detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes and logon events, plus analysis (SIEM/UEBA/rules) that surfaces anomalous credential-related activity, directly enabling detection of the malicious DLL registration and NPLogonNotify behavior on Windows systems.
- T1556.008prevents — A.8.15 mandates logging of successful/rejected access attempts, privilege use, configuration changes, and identity creation/modification plus protected immutable analysis; this surfaces the Registry-based registration and anomalous logon-notify behavior on targeted systems (servers/DCs) but does not stop the malicious DLL from being registered or receiving credentials.
- T1556.008responds — A.8.15 explicitly requires log analysis (including SIEM/IDS/UEBA rules, anomaly detection, correlation of successful/failed access and privilege-use events) to identify suspected incidents such as credential capture during logon, then feeds them into the incident management process (5.25) for response once underway.
- T1556.009detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including access attempts, privilege use, configuration changes and security system activation), and identification of suspected incidents such as probing — all of which surface modification or disablement of conditional access policies when those actions generate observable events on the monitored identity or IAM systems.
- T1557detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of logs (including DNS, network, access attempts, and physical events), and identification of indicators like probing or malware that surface AiTM behaviors such as DNS manipulation, ARP spoofing, or anomalous traffic flows.
- T1557responds — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and identification of suspected incidents (e.g. probing or malware) directly supports responding to an in-progress AiTM once underway, but only for detectable network/behavioral slices rather than the full technique (e.g. ARP poisoning or downgrade attacks may evade logging).
- T1557.001detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, DNS log checks for malicious C2, correlation of events, and identification of indicators like probing or anomalous activity, which surfaces LLMNR/NBT-NS/mDNS poisoning and relay attempts in network traffic.
- T1557.001prevents — A.8.15 mandates logging of network/resource access attempts, configuration changes, privilege use, alarms from access-control/IDS systems, and analysis of anomalous behaviour (including DNS logs and UEBA), which can surface LLMNR/NBT-NS/mDNS spoofing in flight or block some relay paths via timely detection and response; however, it does not stop the initial poisoning response or hash capture itself.
- T1557.002detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, DNS log checks for malicious C2, correlation of network events, and review of access attempts to surface anomalous behaviour and indicators of compromise; ARP cache poisoning produces observable network anomalies (gratuitous replies, duplicate MACs, unexpected traffic redirection) that fall inside those detection mechanisms.
- T1557.003detects — A.8.15 explicitly requires logging, analysis, and monitoring of network events, anomalous behavior, DNS queries to malicious servers, and correlation that surfaces rogue DHCP offers, unauthorized configuration changes, and AiTM indicators.
- T1557.003responds — A.8.15's log analysis and monitoring activities (SIEM/IDS/UEBA correlation, anomalous behaviour detection, review of access attempts and DNS logs) can surface DHCP spoofing once underway as an information security event or indicator of compromise, which then feeds incident handling; this is genuine but only a slice because the control is silent on containment/eradication steps that `responds` also requires and because many DHCP-spoofing artifacts sit outside the events it mandates logging.
- T1557.004detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, unusual network activity (including DNS, usage reports, physical logs, and correlation), which surfaces evil twin Wi-Fi deception and its follow-on effects after the fact; it is not full because the control's scope is set by organisational requirements and does not mandate instrumentation that would reliably catch all rogue-AP or probe-response tricks on every network segment or device.
- T1558detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, identity creation/modification/deletion, and log analysis (with SIEM/UEBA/threat intel/correlation) that surfaces anomalous Kerberos activity such as unusual ticket requests or klist usage as indicators of compromise.
- T1558responds — A.8.15's log analysis, anomaly detection, and incident identification (e.g. via SIEM/UEBA/correlation) surface Kerberos ticket theft or forgery once underway as an information security event, enabling response under 5.25; it does not contain/eradicate the actor or technique itself.
- T1558.001detects — A.8.15 explicitly requires logging, protection, and analysis of events including privilege use, system access attempts, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation to identify indicators of compromise such as forged Kerberos tickets or KDC interactions.
- T1558.001responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. anomalous behavior, probing) for further investigation under incident management, which responds once a golden ticket is used; it does not contain/eradicate the technique itself.
- T1558.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of logs (including successful/rejected access, privilege use, configuration changes), and identification of suspected incidents such as probing — which surfaces silver ticket use after the fact even without KDC interaction.
- T1558.002responds — A.8.15 requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and feeding suspected incidents (e.g. probing or anomalous access) into the incident management process (5.25), which directly enacts the containment/eradication steps that `responds` names once the silver-ticket technique is underway; the remainder is that silver tickets need no KDC interaction and produce no central authentication events, so many forgeries stay outside the logged events the clause actually analyzes.
- T1558.003detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, and alarms, plus log analysis (SIEM/UEBA/rules/threat intel) and monitoring of anomalous behaviour to identify indicators of compromise such as Kerberoasting ticket requests or unusual SPN activity.
- T1558.003responds — A.8.15 requires log analysis, anomaly detection, correlation and identification of suspected incidents (including probing or malware) to feed the incident management process (5.25); this surfaces Kerberoasting TGS requests or anomalous SPN activity once underway for containment/eradication, but the core technique (offline cracking of captured hashes) leaves no live event on the estate and many instances go undetected until after credential use.
- T1558.004detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, and security-system alarms plus SIEM/IDS/UEBA-driven analysis to surface anomalous behaviour and indicators of compromise; AS-REP roasting produces observable Kerberos AS-REQ/AS-REP traffic patterns, LDAP enumeration, and cracking artefacts that fall inside those logged and analysed events.
- T1558.005detects — A.8.15 explicitly requires log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of access/privilege/use events, DNS and physical logs) that surface the collection and use of stolen ccache tickets as indicators of compromise or anomalous activity.
- T1558.005responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation, and incident identification explicitly surface the theft of ccache files (or related Kerberos anomalies) once underway, feeding directly into the incident management process for containment/eradication.
- T1559detects — A.8.15 explicitly requires logging, protection, and analysis of events including system activities, privilege use, process/resource access attempts, anomalous behaviour via SIEM/UEBA/IDS correlation, and indicators of compromise, which surfaces IPC abuse (e.g. anomalous COM/DDE/sockets/pipes activity) in monitored environments.
- T1559.001detects — A.8.15 explicitly requires logging of system activities, privilege use, process/resource access, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces COM abuse (DLL/EXE method calls, scheduled-task objects, etc.) as events or indicators of compromise; the named remainder is in-process COM activity that produces no observable log entry.
- T1559.001responds — A.8.15's log analysis, anomaly detection, correlation, and explicit tie-in to incident identification/investigation (5.25) enable response actions once COM-based execution is underway and logged; partial because many COM abuse vectors (in-process, fileless, or pre-compromise) produce no observable event for the logging facility to act on.
- T1559.002detects — A.8.15 explicitly requires logging of system activities, privilege use, application transactions, configuration changes, and anomalous behaviour via SIEM/UEBA/IDS correlation plus specific monitoring of successful/failed resource access and DNS, which surfaces DDE-based command execution (including Office/CSV poisoning and DCOM invocation) as an information security event or indicator of compromise.
- T1559.003detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, application transactions, alarms, and anomalous behaviour via SIEM/IDS/UEBA rules plus correlation, which surfaces XPC service abuse (including malicious requests to root daemons and improper validation) as an information security event or indicator of compromise on macOS.
- T1560detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and correlation of events (including file access, utility use, and outbound connections) that surface the pre-exfil compression/encryption step on monitored systems.
- T1560.001detects — A.8.15 requires log analysis and monitoring (including of utility use, file access/deletion, system activities, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface the use of archiving utilities like tar/zip/7-Zip during collection, but this is limited to events that generate observable logs and does not guarantee detection of all instances or variants (e.g. obfuscated or non-logged use).
- T1560.002detects — A.8.15 requires log analysis and monitoring (including SIEM/IDS/UEBA rules, anomalous behaviour detection, and correlation of events such as file access/deletion, privilege use, and network activity) that can surface the use of archival libraries or resulting compressed/encrypted blobs when they produce observable artifacts, but this is limited to chosen monitoring scope and does not guarantee detection of in-process library calls themselves.
- T1560.003detects — A.8.15 mandates log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access/use patterns that can surface custom archival (e.g. unusual process behavior, file creation, or outbound prep activity) when it falls inside the monitored scope, but does not guarantee coverage of custom in-memory or non-logged implementations.
- T1561detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, file access/deletion, security system activation, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces disk-wipe indicators (MBR overwrites, mass file deletion, erase commands) after they occur.
- T1561recovers — A.8.15 requires determining logging purposes, recording events (incl. configuration changes, privilege use, file access/deletion), protecting logs against tampering/overwriting, and performing log analysis/correlation to identify incidents; this supports post-wipe recovery investigations and evidence gathering but does not itself restore wiped disk data or system availability.
- T1561responds — A.8.15's log analysis, correlation, anomaly detection (including physical logs), and explicit tie to feeding the incident management process (5.25) enable containment/eradication once disk-wipe activity is underway, with the named remainder being fully completed wipes that have already destroyed recoverability before response begins.
- T1561.001detects — A.8.15 explicitly requires logging, analysis, and monitoring of events including system activities, configuration changes, privilege use, file access/deletion, security system activation, and anomalous behaviour via SIEM/UEBA/correlation to identify incidents such as malware or destructive activity; this surfaces disk-wipe indicators post-execution across the named platforms with only bounded remainder for fully stealthed or pre-log events.
- T1561.001recovers — A.8.15 requires determining logging purposes, recording events (including system activities, configuration changes, privilege use, file access/deletion), protecting logs from tampering or loss, and performing analysis/correlation to identify incidents such as destructive malware; this directly supports post-wipe recovery investigations and evidence gathering per its stated purpose, though it does not itself restore wiped data (that is A.8.13).
- T1561.001responds — A.8.15's log analysis, correlation, and identification of suspected incidents (e.g. malware or probing) feeds the incident management process (5.25) for response once disk-wipe is underway, but does not itself contain or eradicate the active technique.
- T1561.002detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, security system activation/deactivation, and anomalous behaviour via SIEM/UEBA/threat-intelligence analysis, which surfaces disk-structure-wipe indicators (MBR/partition corruption, format commands, boot failures) after the fact; the named remainder is pre-compromise adversary reconnaissance or execution on unmonitored/offline systems.
- T1561.002recovers — A.8.15 requires determining logging purposes, recording events (including system changes, privilege use, configuration changes, and security system activation/deactivation), protecting logs for integrity, and performing analysis to identify incidents; this supports post-wipe recovery investigations and evidence collection per its purpose and 5.28/5.25 references, but does not itself restore wiped disk structures or system availability.
- T1561.002responds — A.8.15's log analysis, correlation, and identification of suspected incidents (including anomalous behavior that can precede or accompany destructive wipers) enables response actions once the technique is underway, but the control itself performs only detection/analysis and does not contain or eradicate.
- T1563detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, configuration changes, session-related events (log-on/off, identity changes), and mandates analysis with SIEM/UEBA/correlation/threat intel to surface anomalous behaviour and indicators of compromise, which directly detects hijacking of preexisting remote sessions (SSH/RDP/telnet) after the fact.
- T1563responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (including anomalous remote access patterns) and feed them into the incident management process (5.25) for response, but does not itself perform containment or eradication of an active hijacking.
- T1563.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including successful/rejected access, privilege use, configuration changes, and physical logs), and identification of indicators of compromise such as probing or anomalous behaviour, which surfaces SSH session hijacking in flight or post-facto on Linux/macOS systems.
- T1563.001prevents — A.8.15 mandates logging of access attempts, privilege use, configuration changes, and security system activation/deactivation plus protected analysis that can surface anomalous SSH-agent or session behavior before lateral movement succeeds, but does not stop the hijack itself (especially root-level agent/socket compromise) and the control's focus is recording/review rather than enforcement.
- T1563.001responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (including anomalous behaviour and probing) for further investigation under incident management (5.25), which matches the `responds` verb once the hijack is underway; extent is partial because it surfaces the event for response but does not itself contain or eradicate the active session.
- T1563.002detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, system activities, alarms from access control systems, and log analysis (with SIEM/IDS/UEBA rules, anomalous behaviour detection, and correlation) that surfaces RDP session hijacking indicators such as tscon.exe use or unexpected session takeovers.
- T1563.002prevents — A.8.15 mandates logging of access attempts, privilege use, session events and configuration changes plus protected immutable analysis that can surface RDP hijacking (tscon.exe use, anomalous sessions) before or during execution, but does not stop the native technique from running.
- T1563.002responds — A.8.15 requires log analysis, anomaly detection, correlation, and identification of suspected incidents (including probing or unauthorized access patterns that can surface RDP hijacking), then feeds them into the incident management process (5.25) for response once the technique is underway.
- T1564detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts, configuration changes, privilege use, and physical events to surface hidden artifacts or isolated regions as indicators of compromise.
- T1564responds — A.8.15's log analysis and monitoring explicitly surface suspected incidents (e.g. probing, anomalous behavior, indicators of compromise) for further investigation under incident management (5.25), which is the core of `responds`; it does not contain/eradicate the hiding technique itself and coverage is limited to detectable artifacts rather than isolated regions or all evasion methods.
- T1564.001detects — A.8.15 explicitly requires log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation of access and file events, physical logs) that surface hidden-file usage as an IOC when it triggers logged events, but the control does not mandate instrumentation that would reveal the hiding act itself when no other logged action occurs.
- T1564.002detects — A.8.15 explicitly requires logging of user/account creation/modification/deletion, privilege use, system configuration changes, and log analysis (with SIEM/UEBA/correlation) that surfaces anomalous hidden-user artifacts after they are created.
- T1564.003detects — A.8.15 explicitly requires logging of system activities, privilege use, process/application execution, configuration changes, and anomalous behaviour via log analysis (SIEM/UEBA/threat intel/correlation), which surfaces hidden-window techniques (e.g. -WindowStyle Hidden, plist/UIElement, hidden desktop, off-screen registry edits) once they execute on monitored systems.
- T1564.004detects — A.8.15 explicitly requires log analysis and monitoring for anomalous behaviour, indicators of compromise, and correlation of events (including file access/deletion and system activities), which can surface NTFS attribute abuse when it triggers observable artifacts, but this is limited to what is logged/analyzed and does not guarantee detection of stealthy or non-logged uses.
- T1564.005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of logs (including file access/deletion, system changes, and physical events), and identification of indicators of compromise or suspicious activity that can surface hidden file system usage when it produces observable events.
- T1564.006detects — A.8.15 requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and specific monitoring (e.g. DNS, access attempts, physical logs) that can surface virtualization artifacts, shared-folder activity, or anomalous VM behavior when inside monitored scope, but the technique's core evasion (hiding artifacts from tools unable to monitor inside the instance, plus hidden ESXi VMs) leaves substantial unmonitored residue.
- T1564.007detects — A.8.15 requires log analysis and monitoring for anomalous behaviour, indicators of compromise, and correlation of events (including file access, application transactions, and security system activity), which can surface VBA-stomping artifacts in Office documents when they trigger observable events, but the control does not mandate inspection of compiled p-code, module streams, or document internals where the hidden payload primarily resides.
- T1564.008detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of logs (including successful/rejected access, privilege use, config changes, alarms), and identification of suspected incidents such as probing or malware — which surfaces the creation or effect of malicious email-hiding rules as anomalous mailbox or mail-flow activity.
- T1564.009detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspicious events (including via SIEM, UEBA, trend analysis, and correlation of logs from systems, applications, and physical access), which can surface resource-fork abuse when it produces observable artifacts in file activity, execution, or extended attributes; however, the control is silent on macOS-specific resource forks, does not mandate the particular sensors or commands needed to reliably catch hidden/obfuscated forks, and the technique can be crafted to avoid generating logged events.
- T1564.010detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, correlation of process-related events (including privilege use, system activities, and application transactions), and review of access attempts, which can surface many process-spoofing artifacts post-execution; however, the control is silent on in-memory PEB inspection or real-time process-memory monitoring that would catch the core overwrite technique itself.
- T1564.011detects — A.8.15 requires log analysis and monitoring (including of system activities, privilege use, process-altering events, alarms from security tools, and anomalous behaviour via SIEM/UEBA/correlation) that can surface the use of nohup, SilentlyContinue or similar commands when they appear in logs or deviate from baselines, but this is limited to observable events rather than the in-memory signal-ignoring technique itself and depends on which events an organization chooses to log/analyze.
- T1564.012detects — A.8.15 requires log analysis and monitoring (including of file access, alarms, security system activity, and anomalous behaviour via SIEM/IDS/UEBA) that can surface use of well-known AV exclusions or related discovery, but does not mandate coverage of all such artifacts or the specific technique itself.
- T1564.013detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspicious events (including via SIEM, UEBA, correlation, and review of access attempts, system activities, and physical logs), which can surface the use or effects of bind mounts as anomalous process or filesystem behaviour; however, the control does not mandate instrumentation that would reliably observe the mount command or kernel-level overlay itself, leaving a large slice of stealthy instances undetected.
- T1564.014detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including via SIEM, UEBA, trend/pattern analysis, and correlation of events such as file access, privilege use, and security system activity), which can surface xattr abuse when it triggers observable events, but does not mandate inspection of xattrs themselves and leaves many stealthy uses (no visible file change, no logged command) undetected.
- T1565detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access/configuration/privilege events to surface indicators of compromise including data manipulation that alters integrity or hides activity.
- T1565responds — A.8.15 requires log analysis and correlation to identify suspected incidents (including anomalous data changes that could be T1565) and routes them to incident management (5.25) for response, but the control itself stops at detection/analysis rather than performing containment or eradication.
- T1565.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and correlation of events (including file access/deletion, configuration changes, privilege use, and alarms) to surface indicators of compromise such as data manipulation at rest.
- T1565.001responds — A.8.15's log analysis and monitoring explicitly surface anomalous behaviour, indicators of compromise, and suspected incidents (including data manipulation that threatens integrity), feeding into incident management (5.25) for response once the technique is underway; this is genuine but only a slice because the control stops at detection/analysis and does not itself perform containment or eradication.
- T1565.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of logs (including network/DNS/physical), and identification of suspected incidents such as probing or malware that would surface T1565.002 activity; the remainder is stealthy manipulations that produce no observable event.
- T1565.003detects — A.8.15 requires log analysis (including SIEM/UEBA rules, anomalous behaviour detection, and correlation of access/config/privilege events) that can surface runtime data manipulation when it produces observable indicators in logs, but the technique's core binary modification or in-memory alteration often leaves no log artefact until downstream effects appear, and the clause's scope is limited to events the organization has chosen to log.
- T1566detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (e.g. reviewing access attempts, correlating logs, UEBA, checking for malicious outbound), which surfaces phishing delivery and follow-on activity once it reaches the estate; it does not observe pre-delivery adversary acquisition or external infrastructure.
- T1566responds — A.8.15's log analysis and monitoring explicitly identify suspected phishing-driven incidents (e.g. malware from attachments/links, probing) for further investigation under incident management, which is the core of `responds`; it is bounded to post-delivery detection rather than containment/eradication actions themselves.
- T1566.001detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, correlation, and review of access attempts, DNS logs, and physical events to surface indicators of compromise such as malware or probing, which directly catches spearphishing attachment delivery and execution artifacts.
- T1566.001responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (e.g. malware infection from attachments) once underway for further investigation per incident management, which is the core of `responds`; partial because it surfaces the event but does not itself contain or eradicate the technique or actor.
- T1566.002detects — A.8.15 explicitly requires logging of access attempts, privilege use, configuration changes, alarms, security system activation, and anomalous behaviour via SIEM/IDS/UEBA/correlation, which surfaces spearphishing link delivery, clicks, downloads, and consent-phishing indicators as security events or IOCs.
- T1566.002responds — A.8.15 requires log analysis and correlation (including of email, access, and anomalous events) to identify suspected incidents such as probing or malware, then feeds them into the incident management process (5.25) for response; this surfaces and acts on realized spearphishing once underway but does not contain/eradicate the actor's foothold or the delivered payload itself.
- T1566.003detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM/IDS rules, anomalous behaviour detection, and correlation of events such as access attempts or unusual activity) that can surface indicators of spearphishing via service when those indicators appear in enterprise logs, but the technique occurs on third-party/non-enterprise services outside organizational visibility and control.
- T1566.003responds — A.8.15 requires log analysis and correlation (including of application, network, physical, and third-party service events) to identify suspected incidents such as probing or malware delivery, then feeds them into the incident management process (5.25) for response; this acts on the technique once underway but only after delivery and only where observable in the logged channels, leaving the social-engineering rapport-building and personal-service vectors largely unseen.
- T1566.004detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM/IDS rules, anomalous behaviour detection, and correlation of events such as access attempts or alarms) that can surface indicators of vishing-driven compromise after the call, but the control's scope is limited to system/application logs and does not address voice-channel events themselves.
- T1566.004responds — A.8.15 requires log analysis and monitoring to identify suspected incidents (including anomalous behaviour, alarms, and indicators of compromise) and feed them into the incident management process (5.25), which is the core of `responds`; it is partial because voice phishing is primarily a social-engineering/pre-compromise technique whose key indicators often sit outside technical logs (phone calls, urgency, impersonation) and the clause's coverage is therefore a slice rather than the bulk with a bounded remainder.
- T1567detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/threat intel, correlation of events (including network activity, DNS, and outbound connections to malicious servers), and identification of indicators of compromise, which surfaces T1567 exfiltration over common web services when it deviates from baseline patterns.
- T1567responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/correlation, and explicit tie to incident identification/investigation (5.25) enable response once exfiltration is underway, but only for the detectable slice that produces observable events rather than the full technique (covert use of legitimate SSL/TLS web services may leave no distinct indicator).
- T1567.001detects — A.8.15 requires log analysis and monitoring (including DNS, outbound connections, anomalous behaviour, UEBA, and correlation) that can surface exfiltration to a code repo via API/HTTPS as unusual activity or an indicator of compromise, but this is a slice dependent on what the organization chooses to log/monitor rather than a bounded remainder, and many shapes (e.g. covert use of a popular internal repo) remain unseen.
- T1567.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/threat intel, and monitoring of outbound connections (including to cloud services) plus correlation of events to identify exfiltration as an information security incident.
- T1567.002responds — A.8.15 requires log analysis, anomaly detection, correlation, and identification of suspected incidents (including outbound connections and unusual activity) to feed the incident management process (5.25); this surfaces and enables response to exfiltration once underway, but the clause itself performs none of the containment/eradication actions that define the core of `responds` on this lane.
- T1567.003detects — A.8.15 requires log analysis and monitoring (including DNS, outbound connections to malicious servers, UEBA, SIEM/IDS rules, and correlation) that can surface anomalous exfiltration to known text storage sites like Pastebin as an indicator of compromise; this is a genuine but minority slice of the technique because the control depends on what the organization has chosen to log/monitor and on threat intel for the specific sites, leaving many stealthy or novel uses undetected.
- T1567.003responds — A.8.15's log analysis, correlation, anomalous-behaviour detection (including outbound connections, UEBA, SIEM/IDS rules) and incident-identification steps act on an exfiltration event once underway to surface it for containment and eradication.
- T1567.004detects — A.8.15 requires log analysis and monitoring (including DNS, outbound connections to malicious servers, anomalous behaviour, UEBA, SIEM/IDS rules, and correlation) that can surface webhook exfiltration when it produces observable events in logs, but the control's scope is limited to the organization's own estate and many webhook deliveries (especially to external SaaS like Discord/Slack) can blend with normal HTTPS traffic without triggering the listed indicators.
- T1567.004responds — A.8.15 requires log analysis and correlation (including of network, application, and physical events) plus identification of suspected incidents for further investigation under the incident management process; this surfaces webhook exfiltration when it produces detectable anomalies in logs but does not itself contain or eradicate the actor once the technique is underway.
- T1568detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, DNS log review for malicious C2 connections, and correlation to identify indicators of compromise, which surfaces dynamic resolution behaviors such as unusual domain/IP patterns.
- T1568responds — A.8.15's log analysis and monitoring explicitly surface anomalous C2-related activity (DNS queries to suspicious domains, outbound connections, UEBA patterns, threat intel correlation) once the dynamic resolution technique is underway, feeding into incident response (5.25); this is genuine response support but only a slice, as the control stops at detection/analysis and does not itself contain or eradicate the running C2 channel.
- T1568.001detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour including outbound connections to malicious C2 servers via DNS logs, which directly surfaces the rapidly changing IPs and short-TTL resolutions characteristic of Fast Flux DNS.
- T1568.001prevents — A.8.15 requires logging of DNS-related events, successful/rejected access attempts, network activity, and analysis (including DNS logs for outbound connections to malicious servers) which can surface and thereby block the use of fast-flux domains before C2 succeeds, but does not stop adversaries from registering/rotating the flux itself.
- T1568.001responds — A.8.15's log analysis and monitoring explicitly cover DNS logs for outbound connections to malicious C2 servers (including flux patterns via correlation, UEBA, threat intel and SIEM/IDS rules), enabling incident identification and hand-off to 5.25 response; this is genuine response once the technique is underway, but only a slice (DNS-focused detection and follow-up) while the control does not contain/eradicate the flux infrastructure itself.
- T1568.002detects — A.8.15 explicitly requires log analysis, anomaly detection via UEBA/SIEM/IDS rules, DNS log examination for outbound C2 connections to malicious domains, and correlation to identify indicators of compromise such as probing or malware callbacks, which surfaces DGA-driven C2 traffic in practice.
- T1568.002responds — A.8.15's log analysis, correlation, anomaly detection (e.g. DNS logs to malicious C2), and incident identification explicitly surface and feed into response for realized DGA C2 events once underway, but this is only one slice of full incident response (containment/eradication lives in 5.25/5.26).
- T1568.003detects — A.8.15 explicitly requires log analysis and monitoring (including DNS logs for outbound connections to malicious C2, correlation, UEBA, and anomaly detection) that surfaces the unusual DNS responses and calculated C2 traffic this technique produces.
- T1568.003responds — A.8.15's log analysis, correlation, SIEM/IDS/UEBA rules, and incident identification explicitly surface anomalous DNS/C2 patterns (including calculated ports or outbound connections to malicious infrastructure) once the technique is underway, feeding the incident management process.
- T1569detects — Logging service-creation events and the execution of system utilities reveals attempts to abuse legitimate services for code execution.
- T1569responds — A.8.15's log analysis and monitoring activities (SIEM/UEBA rules, anomalous behaviour detection, correlation) can surface service-abuse events once underway as indicators of compromise, enabling response, but this is only a slice of the technique's execution surface rather than containment/eradication itself.
- T1569.001detects — A.8.15 explicitly requires logging of system activities, privilege use, process launches, configuration changes and anomalous behaviour, then mandates analysis (SIEM/UEBA/rules) that surfaces launchctl abuse as an indicator of compromise; the named remainder is events on unmonitored macOS endpoints or before logging is enabled.
- T1569.001responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including via SIEM/IDS/UEBA rules and correlation), which surfaces launchctl abuse once underway for further investigation under incident management, but does not itself contain or eradicate it.
- T1569.002detects — A.8.15 explicitly requires logging and analysis of service-related events (use of privileges, system activities, configuration changes, alarms from access control/IDS, anomalous behaviour via SIEM/UEBA/correlation) that surface abuse of the service control manager, with the named remainder being events outside the chosen monitoring scope or before analysis occurs.
- T1569.002prevents — A.8.15 mandates logging of privilege use, system configuration changes, service-related events and anomalous behaviour, which can prevent some abuse of the service control manager by increasing the chance of detection before or during execution; however, it does not stop the technique from running.
- T1569.002responds — A.8.15's log analysis, anomaly detection, correlation, and incident identification (e.g. via SIEM/IDS rules, UEBA, and review of access/system changes) surface service execution as a suspected incident for further handling, but this is after the fact with no containment/eradication act asserted by the control itself
- T1569.003detects — A.8.15 explicitly requires logging, analysis, and monitoring of system activities, privilege use, configuration changes, service activation/deactivation, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces systemctl abuse when it triggers those logged events.
- T1569.003prevents — A.8.15's logging of privilege use, system activities, configuration changes, and security system activation (plus analysis for anomalous behaviour) can surface or deter some systemctl abuse patterns but does not stop the technique from executing.
- T1570detects — A.8.15 explicitly requires logging, protection, and analysis of events including file access/deletion, privilege use, system activities, network connections, anomalous behaviour via SIEM/UEBA/correlation, and indicators of compromise, which surfaces lateral tool/file transfers once they occur.
- T1570responds — A.8.15's log analysis, anomaly detection, and incident identification (e.g. via SIEM/UEBA/correlation of file-access and privilege-use events) enable response once lateral tool transfer is underway, but this is only a slice of the full technique (many transfers use native tools or protocols that may not trigger logged anomalies).
- T1571detects — A.8.15 explicitly requires logging of network addresses/protocols, access attempts, configuration changes, and anomalous behaviour via log analysis (SIEM/UEBA/threat intel/correlation), which surfaces non-standard port usage as an indicator of compromise; the named remainder is fully encrypted/obfuscated C2 that evades the logging facility itself.
- T1571responds — A.8.15's log analysis and monitoring explicitly surface anomalous network activity (including non-standard ports via DNS, firewall, UEBA and correlation), feeding incident identification and response per 5.25, but this is detection feeding response rather than the containment/eradication act itself.
- T1572detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, DNS log examination for malicious C2, correlation of events, and identification of probing or indicators of compromise, which surfaces protocol tunneling (including SSH, DoH) when it generates observable network or system events.
- T1572prevents — A.8.15 mandates logging of access attempts, configuration changes, privilege use, network activity and alarms plus analysis to surface anomalous behaviour; this can prevent some tunneling (e.g. by catching unusual SSH/DoH flows or privilege escalation for tunnel setup) but leaves the bulk of encapsulation, blending and routing techniques untouched.
- T1572responds — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including network anomalies, probing, or C2 patterns that protocol tunneling produces), then subjects them to further investigation as part of incident handling; this is the core of `responds` once the technique is underway, but remains partial because the clause stops at detection/analysis/hand-off and does not itself perform containment or eradication.
- T1573detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including via SIEM, UEBA, DNS logs, and correlation), which surfaces encrypted C2 channels when they produce observable anomalies; however, well-implemented encryption per the technique often evades detection in standard logs, limiting coverage to a slice rather than a bounded remainder.
- T1573.001detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and events such as outbound connections to malicious C2 servers (via DNS logs, UEBA, SIEM, etc.), which surfaces many symmetric-C2 implementations once they produce observable traffic patterns; it does not instrument or surface the cryptography itself when the algorithm is used only for concealment inside otherwise-allowed channels.
- T1573.002detects — A.8.15 requires log analysis and monitoring (including DNS, network traffic patterns, UEBA, SIEM/IDS rules, and correlation) that can surface anomalous C2 using asymmetric crypto (e.g. unusual TLS handshakes or outbound connections), but this is limited to observable artifacts after the fact and does not cover all implementations or pre-encryption behaviors.
- T1574detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including privilege use, config changes, process/file activity, and alarms), and identification of indicators of compromise or incidents, which surfaces most hijack-execution-flow techniques once they produce observable artifacts.
- T1574.001detects — A.8.15 explicitly requires logging of security-relevant events (privilege use, config changes, system access attempts, alarms from IDS/AV, anomalous behaviour via SIEM/UEBA/correlation) plus dedicated log analysis to surface indicators of compromise; this directly surfaces most DLL sideloading/hijacking/substitution behaviours once they execute, though some fully in-memory or pre-execution variants remain outside log visibility.
- T1574.001responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification directly support responding to a realized DLL-hijacking event once underway, but the clause stops at detection/analysis and hands off to 5.25 incident handling for containment/eradication.
- T1574.004detects — A.8.15 explicitly requires logging of system activities, privilege use, process/file access, security system events, and log analysis (with SIEM/UEBA/IDS rules, anomalous behaviour detection, and correlation) that surfaces dylib loading anomalies or unexpected library loads on macOS, though it does not guarantee coverage of every possible weak-link or @rpath hijack variant.
- T1574.005detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including via SIEM, UEBA, correlation, and review of access attempts, privilege use, system changes, and file operations), which surfaces the file-permission abuse and binary replacement during installer execution on Windows.
- T1574.006detects — A.8.15 explicitly requires log analysis and monitoring for anomalous behaviour, indicators of compromise, and correlation of events (including process, library, privilege-use and configuration-change logs), which surfaces dynamic-linker hijacking once it occurs.
- T1574.007detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of events (including privilege use, configuration changes, process execution via command interpreters, and file access), and identification of indicators of compromise such as probing or malware, which surfaces most PATH hijacking attempts once they trigger observable events.
- T1574.008detects — A.8.15 explicitly requires logging and analysis of events including successful/rejected access attempts, privilege use, system configuration changes, application transactions, anomalous behaviour via SIEM/UEBA/threat intel, and correlation of logs (including physical), which surfaces search-order hijacking artifacts such as unexpected executables, anomalous process execution, and indicators of compromise.
- T1574.009detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, configuration changes, file access/deletion, alarms, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces the registry/service/shortcut writes, anomalous executable placement, and resulting execution that realise T1574.009; the named remainder is events outside the chosen logging scope or before analysis occurs.
- T1574.010detects — A.8.15 explicitly requires logging and analysis of privilege use, system configuration changes, service-related events, anomalous behaviour via SIEM/UEBA/IDS correlation, and indicators of compromise, which surfaces the hijacking of service binaries running at elevated (e.g. SYSTEM) permissions.
- T1574.011detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, configuration changes, service-related events, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces Registry permission abuse and hijacked service paths when they trigger or are reviewed.
- T1574.012detects — A.8.15 explicitly requires log analysis, SIEM/IDS rules, UEBA, trend/pattern analysis, threat intelligence, and correlation of events (including process, privilege use, system configuration changes, and anomalous behaviour) to surface indicators of compromise such as a malicious COR_PROFILER DLL load or registry modification.
- T1574.013detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation of events (including process, system, privilege-use and application activity), and identification of indicators of compromise such as malware or probing, which surfaces the in-memory hijack when it produces observable execution, Windows messages or related artifacts under a legitimate process.
- T1574.013responds — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and incident identification explicitly feed the incident management process (5.25) that contains and eradicates an in-progress hijack once its indicators appear in logs.
- T1574.014detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of events (including process, configuration changes, privilege use, and application activity), and identification of indicators of compromise such as malware or probing, which surfaces AppDomainManager hijacking when it generates observable events.
- T1578detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including config changes, privilege use, resource access, and security system activation), and identification of suspected incidents such as probing — which surfaces T1578's modifications to cloud compute infrastructure (create/delete/modify instances, VMs, snapshots) after they occur.
- T1578responds — A.8.15 requires log analysis and correlation (including of privileged use, config changes, and security system events) to identify suspected incidents for further investigation under the incident management process, which is the core of `responds`; it is only partial because the clause stops at identification/analysis and does not itself perform containment or eradication.
- T1578.001detects — A.8.15 requires log analysis and monitoring (including of configuration changes, privilege use, resource access attempts, and anomalous behaviour via SIEM/UEBA/correlation) that can surface snapshot creation as suspicious activity or an indicator of compromise, but this is scoped by what the organization chooses to log/monitor and does not guarantee detection of the technique itself.
- T1578.002detects — A.8.15 explicitly requires logging, analysis, and monitoring of events including system activities, configuration changes, privilege use, resource access, and anomalous behaviour (with SIEM/UEBA/threat intel correlation), which surfaces creation of a new cloud instance as a detectable deviation from baseline.
- T1578.003detects — A.8.15 explicitly requires logging, protection, and analysis of events including system activities, privilege use, configuration changes, resource access/deletion, alarms, and anomalous behaviour via SIEM/UEBA/threat intel, which surfaces the deletion of a cloud instance (and its forensic loss) as an indicator of compromise or incident.
- T1578.003recovers — A.8.15 requires determining what to log (including system activities, privilege use, configuration changes, and resource access/deletion), protecting logs against deletion or overwrite, archiving for retention/evidence, and analyzing for incidents; this enables recovery of forensic evidence and correlation for post-deletion investigation in many but not all cases (e.g., fully ephemeral or unlogged instances leave no recoverable artifacts).
- T1578.003responds — A.8.15's log analysis, correlation, and identification of suspected incidents (including anomalous behavior or probing) enables response once deletion is underway or complete, but does not contain/eradicate the actor or address non-recoverable evidence loss itself.
- T1578.004detects — A.8.15's log analysis, correlation, UEBA, SIEM/IDS rules, and review of access/configuration/privilege events can surface anomalous reversion activity (e.g. snapshot restore or ephemeral reset) after it occurs, but only where those events are both logged and fall inside the chosen analysis scope; many cloud snapshot/API calls sit outside that scope or lack the required attributes.
- T1578.005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/threat intel, and monitoring of configuration changes, privilege use, system activities and resource-access events that surface modifications to quotas, policies, VM sizes or region settings; the bounded remainder is stealthy or pre-compromise changes that produce no observable event on the victim estate.
- T1580detects — A.8.15 requires log analysis and monitoring (including of successful/failed access, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface cloud discovery API calls or unusual enumeration by a compromised account; this is a genuine but minority slice of T1580 activity, which also occurs via legitimate CLI/tools without triggering logs or via pre-compromise reconnaissance outside the organization's estate.
- T1583.008detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM/IDS rules, anomalous behaviour detection, DNS logs, and correlation) that can surface malvertising indicators such as suspicious ad-driven traffic or domains, but the control's scope is limited to events inside the organization's own systems and does not reach the adversary's pre-compromise ad purchase or the ad network's external evasion techniques.
- T1584detects — A.8.15 requires log analysis and monitoring (SIEM/IDS/UEBA/correlation) that surfaces anomalous behavior, indicators of compromise, and suspected incidents including probing, botnet C2, and infrastructure misuse, but only for events that reach the organization's own logged systems and networks.
- T1584.001detects — A.8.15 requires log analysis and monitoring (including DNS logs, anomalous outbound connections, UEBA, trend/pattern analysis, and correlation) that can surface domain hijacking, subdomain takeovers, or shadowing as indicators of compromise or anomalous behavior, but this is scoped by what the organization chooses to log/monitor and does not guarantee detection of all registration or DNS hijacks (especially pre-compromise or external ones).
- T1584.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA, DNS log review for outbound connections to malicious C2 servers, and correlation to identify suspected incidents such as probing or malware, which surfaces post-compromise use or alteration of a compromised third-party DNS server; it is only partial because the control's scope is set by organizational requirements and does not mandate universal DNS-specific instrumentation or detection of silent pre-compromise subdomain creation.
- T1584.003detects — A.8.15 requires log analysis and monitoring (including of system access attempts, configuration changes, privilege use, network activity, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface indicators of a third-party VPS compromise, but this is scoped by what the organization logs/monitors and does not inherently cover adversary-acquired external VPSes used in PRE.
- T1584.004detects — A.8.15 requires log analysis and monitoring (SIEM/IDS/UEBA/correlation) that surfaces anomalous activity, indicators of compromise, and events such as configuration changes, privilege use, or outbound connections to malicious infrastructure, which can reveal third-party server compromise in post-exploitation or C2 scenarios; it is partial because the control's scope is limited to what the organization logs/monitors in its own environment and does not inherently detect adversary compromise of external third-party servers used in pre-compromise targeting.
- T1584.005detects — A.8.15 requires log analysis and monitoring (including DNS logs for C2, anomalous outbound connections, UEBA, threat intel) that can surface botnet-related activity or IOCs once systems are compromised and the botnet is in use; this is genuine detection but only a slice, as the technique's core (adversary compromise/build/takeover of third-party systems on PRE platforms) occurs entirely outside the organization's estate and visibility.
- T1584.005responds — A.8.15's log analysis, anomaly detection (e.g. outbound C2, botnet patterns via UEBA/threat intel), and incident identification explicitly feed into the 5.25 incident management process that contains and eradicates an active botnet once underway.
- T1584.006detects — A.8.15 requires log analysis and monitoring (SIEM/UEBA/IDS correlation, anomalous behaviour review, DNS logs, physical logs) that can surface indicators of web-service compromise or abuse in expected noise, but this is scoped to what the organization logs/monitors and does not guarantee detection of pre-positioning on third-party PRE platforms.
- T1584.007detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspicious events (including outbound connections, unusual activity, and correlation), which can surface serverless compromise or its use for C2/proxying when those behaviours are logged and fall inside the analysis scope; it is not guaranteed to catch stealthy or novel serverless abuse that blends with legitimate cloud traffic.
- T1584.008detects — A.8.15 requires log analysis and monitoring (including of network appliances, configuration changes, privilege use, alarms, and anomalous outbound connections) that can surface compromise of third-party network devices or their downstream use in C2/proxy activity, but this is scoped by what the organization logs/analyzes and does not inherently cover unmanaged third-party edge devices lacking host defenses.
- T1585.002detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM rules, anomalous behaviour detection, and correlation of access/identity events) that can surface creation of accounts or related suspicious patterns, but this is scoped to organizational systems and does not inherently cover adversary-created external disposable email accounts on PRE platforms.
- T1586detects — A.8.15 requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts and events that can surface indicators of account compromise (e.g. brute-force, anomalous logons, privilege use), but this is scoped to what the organization chooses to log/monitor and does not inherently detect pre-compromise reconnaissance, credential purchases, or third-party persona development on external services.
- T1586.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of events (including access attempts, privilege use, configuration changes, and physical logs), and identification of suspected incidents such as probing; this surfaces T1586.001 when its compromise methods (phishing, brute-force, credential use) or downstream effects produce observable logs, but the control's scope is limited to what the organization logs/monitors and does not guarantee detection of all pre-compromise reconnaissance or third-party account activity.
- T1586.002detects — A.8.15 requires log analysis and monitoring (including of access attempts, privilege use, configuration changes, anomalous behaviour via SIEM/UEBA/threat intel, and correlation) that can surface indicators of email account compromise such as suspicious logons or outbound activity, but this is scoped by what the organization chooses to log/monitor and does not inherently cover pre-compromise reconnaissance, credential purchases, or the PRE platform itself.
- T1586.003detects — A.8.15's log analysis, monitoring activities, anomaly detection via SIEM/UEBA/IDS rules, and correlation of events (including access attempts, privilege use, configuration changes, and outbound connections) can surface indicators of cloud-account compromise or its downstream use, but this is scoped to what the organization chooses to log/monitor and does not inherently cover pre-compromise reconnaissance, credential theft, or third-party cloud-provider logs.
- T1587.001detects — A.8.15's log analysis and monitoring explicitly surface indicators of compromise, anomalous behaviour and suspected incidents (including malware-related events such as probing or infections), but this is post-development/pre-targeting detection of the malware's use rather than detection of the PRE technique of developing the malware itself.
- T1587.002detects — A.8.15 requires log analysis and monitoring (including SIEM/IDS/UEBA rules, anomalous behaviour detection, and correlation of events such as privilege use, configuration changes, and security system activation) that can surface creation or use of a self-signed code-signing certificate as an indicator of compromise, but this is limited to observable post-creation events on monitored systems and does not address the PRE phase or certificate development itself.
- T1587.003detects — A.8.15 requires log analysis and monitoring (including of system activities, privilege use, configuration changes, alarms, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface creation or use of a self-signed certificate as an indicator, but this is limited to post-creation observable events on monitored systems and does not address the PRE technique's offline creation step.
- T1588detects — A.8.15 requires log analysis and monitoring to identify unusual activity, anomalous behaviour, indicators of compromise, and suspected incidents (including malware or probing), which can surface adversary acquisition of capabilities when it produces observable artifacts in the monitored environment; this is a genuine but minority slice of the pre-attack technique whose core (purchase, download, or theft) is often invisible to the organization's logs.
- T1588.001detects — A.8.15 requires log analysis and monitoring (SIEM/IDS/UEBA/threat intel/correlation) that surfaces indicators of compromise including malware-related activity, but this is scoped to post-acquisition operational use on victim systems rather than the pre-compromise acquisition activity itself on adversary infrastructure.
- T1588.002detects — A.8.15's log analysis and monitoring activities (SIEM/IDS/UEBA rules, anomalous behaviour detection, correlation of access/use/privilege events) can surface acquisition or testing of tools when those actions produce observable logs, but the pre-compromise acquisition step itself (buy/steal/download outside monitored systems) is largely outside the logging scope.
- T1588.003detects — A.8.15 requires log analysis and monitoring (including of privilege use, configuration changes, alarms, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface acquisition or use of stolen certificates as an indicator, but this is limited to post-compromise observable events on covered systems and does not address pre-targeting purchase or third-party theft outside monitored scope.
- T1588.004detects — A.8.15 requires log analysis and monitoring (SIEM/IDS/UEBA rules, anomalous behaviour detection, DNS logs, correlation) that can surface certificate acquisition, domain hijacking or suspicious CA interactions as indicators of compromise; this is genuine but only a slice because the technique is pre-compromise, external, and often leaves no detectable log on the victim's systems until later stages.
- T1588.005detects — A.8.15 requires log analysis and monitoring (SIEM/IDS/UEBA/threat intel/correlation) that can surface indicators of exploit acquisition, forum monitoring, or related anomalous behavior as an information security event, but this is indirect, post-facto, and depends on what the organization chooses to log/analyze rather than a dedicated mechanism for the pre-attack technique itself.
- T1588.006detects — A.8.15 requires log analysis and monitoring (SIEM/IDS/UEBA rules, anomalous behaviour detection, correlation) that can surface adversary activity such as scanning vulnerability databases or targeting research systems, but only when that activity produces observable events inside the monitored scope; the pre-compromise reconnaissance itself is not instrumented by default.
- T1588.007detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including via SIEM, UEBA, threat intel, and correlation), which can surface AI-assisted reconnaissance, phishing content generation, or anomalous script/payload activity when it produces observable events in logs; it does not guarantee detection of all pre-compromise or non-logged uses of public LLMs.
- T1589detects — A.8.15 requires log analysis and monitoring (SIEM/UEBA/IDS correlation, anomalous login/access patterns, successful/rejected access attempts) that can surface T1589 indicators such as probing of auth services or unusual credential-enumeration behavior, but only after the fact and only for the subset of T1589 that touches monitored systems rather than purely external OSINT or phishing-for-info.
- T1589.001detects — A.8.15's log analysis and monitoring requirements surface anomalous credential-gathering behaviors (e.g. phishing attempts, unusual access patterns, or leaked credential indicators in logs) as potential IOCs, but this is limited to observable events within the organization's monitored scope and does not address pre-compromise external gathering like dark web purchases or site compromises.
- T1590detects — A.8.15 requires log analysis and monitoring (including DNS logs, network patterns, UEBA, SIEM/IDS rules, and correlation) that can surface anomalous reconnaissance activity such as active scanning or unusual queries indicative of T1590, but this is scoped by what the organization chooses to log/monitor and does not guarantee detection of all passive or external data-set methods on the PRE platform.
- T1590.001detects — A.8.15 requires log analysis and monitoring (including DNS logs, anomalous outbound connections, UEBA, SIEM/IDS rules, and correlation) that can surface domain reconnaissance activity such as WHOIS lookups, passive DNS queries, or probing of name servers, but this is scoped to what the organization has chosen to log/monitor and does not inherently cover all external/pre-compromise discovery methods on the PRE platform.
- T1590.002detects — A.8.15 requires log analysis and monitoring (including DNS logs for outbound connections to malicious infrastructure, correlation, UEBA, and anomaly detection) that can surface reconnaissance activity such as DNS queries or zone transfers, but this is scoped by what the organization chooses to log/monitor and does not guarantee detection of passive or external open-source DNS gathering.
- T1590.003detects — A.8.15 requires log analysis and monitoring (including correlation, UEBA, DNS logs, anomalous access patterns, and physical events) that can surface reconnaissance activity aimed at discovering network trust dependencies, but only for the subset that produces observable events inside the monitored scope rather than purely passive OSINT or pre-compromise elicitation.
- T1590.004detects — A.8.15's log analysis and monitoring activities (SIEM/IDS rules, UEBA, DNS log review for malicious C2, correlating logs from network/physical events) surface anomalous reconnaissance behaviors that can reveal network topology gathering, but this is scoped to what is logged/monitored rather than all possible collection methods (e.g. passive web searches).
- T1590.005detects — A.8.15 requires log analysis and monitoring (including DNS logs, network patterns, UEBA, SIEM/IDS rules, and correlation) that can surface anomalous activity tied to IP reconnaissance such as scanning or outbound connections, but this is scoped by what the organization chooses to log/monitor and does not systematically detect passive/public data-set gathering of IP blocks.
- T1590.006detects — A.8.15 requires log analysis and monitoring (including of alarms from access control/IDS, anomalous behaviour, DNS logs, and correlation) that can surface reconnaissance activity such as active scanning or exposed appliance details, but this is scoped to chosen events and does not guarantee detection of all T1590.006 vectors such as passive website searches or phishing for information.
- T1591.004detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and suspected incidents (including via UEBA, SIEM, IDS, and correlation of access/identity events), which can surface reconnaissance activity that reveals roles, but the control is scoped to logged events on organizational systems and does not address external OSINT, social media, or phishing-for-information channels where much of T1591.004 occurs.
- T1592detects — A.8.15 requires log analysis and monitoring of events (including access attempts, configuration changes, alarms, and anomalous behaviour via SIEM/UEBA/correlation) that can surface T1592 indicators such as scanning, probing, or unusual user-agent patterns, but only after the fact and only for the subset of collection methods that produce observable logs rather than passive OSINT or pre-compromise exposure.
- T1592.001detects — A.8.15 requires log analysis and monitoring (including of system activities, configuration changes, privilege use, alarms, security system activation, and anomalous behaviour via SIEM/UEBA/correlation) that can surface reconnaissance for hardware details when it triggers logged events or patterns, but the control's scope is limited to post-event logs on the victim and does not address pre-compromise external sources or the PRE platform.
- T1592.002detects — A.8.15 requires log analysis and monitoring (including SIEM/IDS/UEBA correlation of events such as access attempts, configuration changes, privilege use, security system activation, and anomalous behaviour) that can surface reconnaissance activity aimed at discovering host software and defensive components, but only for the subset of T1592.002 that produces observable events inside the logged scope; passive collection from public data, metadata, or pre-compromise phishing leaves no detectable log trail.
- T1592.004detects — A.8.15 requires log analysis and monitoring (including correlation, UEBA, DNS logs, physical events, and anomaly detection) that can surface reconnaissance activity such as active scanning, phishing responses, or exposed config data in logs, but only for the subset of T1592.004 collection methods that produce observable events inside the monitored scope; many pre-compromise or external data-set methods leave no detectable log trail.
- T1593.003detects — A.8.15 requires log analysis and monitoring (including of successful/unsuccessful access attempts, configuration changes, alarms, and anomalous behaviour via SIEM/UEBA/correlation) that can surface reconnaissance activity against public code repositories when it triggers observable events on monitored systems, but the control's scope is limited to an organization's own logs and does not inherently observe adversary searches of third-party public repositories.
- T1594detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including via web-related logs like DNS, access attempts, and physical monitoring), which can surface T1594 reconnaissance after or during its occurrence on victim web assets, but only for the monitored slice rather than the technique universally.
- T1595detects — A.8.15 explicitly requires logging, analysis, and monitoring of network events including alarms from intrusion detection, outbound connections to malicious servers, anomalous patterns, and correlation of logs to identify probing of firewalls and other indicators of active scanning reconnaissance.
- T1595responds — A.8.15's log analysis and monitoring explicitly surface scanning/probing events (e.g. firewall probes, DNS logs for outbound C2, anomalous access attempts) once underway and feed them into incident response (5.25), but this is only a slice: pre-compromise external scanning often leaves no detectable artifact on the victim estate until after the fact, and the control's core is logging rather than active containment/eradication.
- T1595.001detects — A.8.15 requires log analysis and specific monitoring (e.g. reviewing access attempts to protected resources, checking DNS logs for malicious outbound, correlating logs) that can surface scanning of the organization's own IP blocks once it reaches monitored estate, but the technique occurs entirely pre-compromise on external/public ranges with no guaranteed internal footprint or event on the organization's systems.
- T1595.001responds — A.8.15 requires analysis of logs (including network/DNS/IDS events) to identify and investigate suspected incidents such as probing of firewalls; this engages the administrative/follow-up half of incident response (evidence collection, root cause, recording) once the pre-compromise scan produces observable artifacts on the estate, but containment/eradication is empty as the scan itself is not an intrusion.
- T1595.002detects — A.8.15 requires log analysis and monitoring (including of access attempts, alarms, network connections to malicious servers, and correlation with threat intelligence) that can surface vulnerability scanning activity once it reaches the organization's estate, but the technique occurs pre-compromise on external infrastructure with no guaranteed observable artifact on the monitored domain.
- T1595.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, DNS log review for malicious outbound connections, correlation of logs, and identification of probing or suspected incidents, which surfaces wordlist scanning activity on the organization's infrastructure.
- T1595.003responds — A.8.15 requires log analysis and monitoring (including of access attempts, alarms, anomalous behaviour, and correlation) that surfaces suspected probing or scanning events once underway so they can be identified and handed to incident management (5.25) for containment/eradication; this is the core of `responds` with a named remainder of stealthy/pre-filtered scans that evade the configured rulesets.
- T1596detects — A.8.15 requires log analysis and monitoring (including DNS logs, network patterns, UEBA, threat intel correlation) that can surface anomalous reconnaissance activity such as unusual queries to open technical databases, but this is limited to observable network or system events within the monitored scope rather than directly detecting all passive/open-source searches.
- T1597.001detects — A.8.15 requires log analysis and monitoring (including correlation, UEBA, threat intelligence use, and review of access attempts/alarms) to identify anomalous behavior and suspected incidents, which can surface adversary searches of threat-intel vendor data when those searches produce observable events in monitored logs; this is a genuine but minority slice because the technique is primarily reconnaissance performed externally/pre-compromise with no guaranteed logged footprint inside the organization's systems.
- T1598detects — A.8.15 requires log analysis and monitoring (including of access attempts, alarms, anomalous behaviour, DNS logs, UEBA, and correlation) that can surface phishing-for-information activity once it has reached the target environment, but this is scoped by what the organization chooses to log/monitor and does not inherently cover pre-delivery social engineering, spoofing, or callback channels on the PRE platform.
- T1598.001detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM/IDS rules, anomalous behaviour detection, and correlation of events such as access attempts or unusual activity) that can surface spearphishing messages or related indicators when they trigger observable logs, but this is limited to events inside the monitored scope and does not inherently cover third-party/non-enterprise services or pre-compromise social engineering lures.
- T1598.002detects — A.8.15 requires log analysis and monitoring (including SIEM/IDS/UEBA rules, anomalous behaviour detection, DNS logs, and correlation) that can surface spearphishing indicators such as suspicious attachments, unusual email patterns or outbound connections, but does not guarantee coverage of all social-engineering lures or pre-delivery reconnaissance on PRE platforms.
- T1598.003detects — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, correlation, and review of access attempts/DNS logs/physical events to surface indicators of compromise such as phishing-related probing or anomalous behavior, but does not guarantee detection of all delivery vectors (e.g. QR codes on mobile, tracking pixels, or BitB spoofing outside monitored scopes).
- T1598.004detects — A.8.15 requires log analysis and monitoring (including UEBA, SIEM/IDS rules, anomalous behaviour detection, and correlation of events such as access attempts or alarms) that can surface vishing indicators like spoofed calls, urgent pretexts, or anomalous voice-related activity when those events reach logged systems or networks, but the control is silent on voice channels themselves and most vishing occurs outside monitored digital logs.
- T1599detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including via SIEM, UEBA, DNS logs, traffic patterns, and correlation), which surfaces boundary device compromise and unauthorized traffic bridging as detectable events on the network perimeter.
- T1599.001detects — A.8.15 explicitly requires log analysis and monitoring of events including configuration changes, use of privileges, network activity, anomalous behaviour, DNS logs for outbound connections to malicious infrastructure, and correlation with threat intelligence — all of which surface malicious NAT modifications on boundary devices once they occur.
- T1600detects — A.8.15 requires log analysis and monitoring (including anomalous behaviour, configuration changes, privilege use, alarms from IDS/access control, and correlation with threat intelligence) that can surface indicators of device compromise or weakening of encryption, but does not mandate coverage of network-device firmware, hardware crypto, or the specific sub-techniques, leaving a large unscoped remainder.
- T1600.001detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspicious events (including configuration changes and use of privileges), which can surface the CLI commands or image modifications that reduce key space, but only where those actions produce observable logs within the monitored scope.
- T1600.002detects — A.8.15 requires log analysis and monitoring (including of configuration changes, privilege use, system activities, alarms, and anomalous behaviour via SIEM/UEBA/correlation) that can surface the disabling of crypto hardware as an indicator of compromise, but this is scoped by what the organization chooses to log/monitor and does not guarantee coverage of network device firmware or hardware-specific events.
- T1601detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and security events (including configuration changes, privilege use, and system activities), which surfaces T1601 modifications to a device OS image when those actions produce observable loggable events; the coverage is partial because many embedded network-device modifications (especially in-memory or on unmonitored boot images) leave no log trail at all.
- T1601.001detects — A.8.15 requires log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and review of access/configuration/privilege events that can surface indicators of a network-device OS patch (e.g. config changes, privilege use, file modifications, or anomalous commands), but this is limited to observable events on monitored systems and does not guarantee detection of in-memory patches or stealthy bootloader-based modifications on network devices.
- T1601.002detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspicious events (including configuration changes, use of privileges, and system activities), which can surface a downgrade but only where it produces observable artifacts in the defined log scope; the technique's core act (replacing boot image on an embedded/network device) is not guaranteed to be logged or flagged.
- T1602detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of access attempts, configuration changes, privilege use, and network activity that would surface an adversary querying or exfiltrating from a configuration repository.
- T1602.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules, correlation of logs (including network events and configuration changes), and identification of indicators like probing, which surfaces SNMP MIB queries as anomalous network or access activity on managed devices.
- T1602.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of configuration changes, privilege use, access attempts, and network activity that would surface a configuration dump via management protocols.
- T1606detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of events (including privilege use, configuration changes, access attempts, and identity creation/modification), and identification of indicators of compromise or suspicious activity that would surface forged web credential generation and use.
- T1606responds — A.8.15 requires log analysis and correlation (including of access attempts, privilege use, configuration changes, alarms, and anomalous behaviour) to identify suspected incidents such as probing or unauthorized access, which feeds the incident response process (5.25) once forgery has occurred; it does not contain or eradicate the forged credential or actor once the technique is underway.
- T1606.001detects — A.8.15 requires log analysis and monitoring (SIEM/UEBA/IDS rules, anomalous behaviour detection, correlation of access attempts and events) that can surface forged-cookie use after the fact when it triggers observable logs or anomalies, but the control's scope is limited to events on the organization's own estate and does not guarantee detection of all forgery vectors (especially SaaS-side or pre-authentication generation).
- T1606.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including successful/rejected access, privilege use, identity changes, and security system events), and identification of indicators of compromise such as probing or anomalous behavior, which surfaces forged SAML token usage across the technique's platforms and post-authentication effects.
- T1608detects — A.8.15 mandates log generation, protection, and analysis (including SIEM/UEBA/threat-intel correlation) that can surface anomalous staging activity on monitored infrastructure or outbound transfers, but the control's scope is limited to events the organization can observe and does not reach adversary-controlled external staging infrastructure (PRE platform).
- T1608.002detects — A.8.15 requires log analysis and monitoring (SIEM/IDS/UEBA/threat intel/correlation) that can surface anomalous uploads or staging activity on adversary-controlled infrastructure when it intersects monitored systems, networks or logs, but this is limited to observable post-facto events on the victim side or within organizational scope rather than the adversary's pre-targeting upload on external/pre infrastructure.
- T1608.003detects — A.8.15 requires log analysis and monitoring (including of configuration changes, privilege use, system activities, alarms, and anomalous behaviour via SIEM/UEBA/threat intel) that can surface certificate installation on adversary infrastructure or C2-related activity, but this is limited to post-installation observables on monitored systems and does not address pre-targeting installation on acquired/compromised infrastructure outside the organization's visibility.
- T1608.004detects — A.8.15 requires log analysis, anomaly detection via SIEM/IDS/UEBA, DNS log checks for malicious C2, correlation, and identification of suspected incidents (e.g. probing), which surfaces drive-by staging and delivery activity when it triggers observable events on monitored systems; this is a genuine but minority slice because the technique is pre-compromise infrastructure preparation on adversary-controlled assets outside the organization's visibility.
- T1608.005detects — A.8.15 requires log analysis and monitoring (SIEM/IDS/UEBA rules, anomalous behaviour detection, DNS logs, correlation) that can surface indicators of link-target setup such as phishing infrastructure or cloned sites, but this is limited to observable post-setup events on owned systems and does not systematically detect all pre-phish infrastructure (e.g. IPFS, external shortening services, or domain purchases).
- T1608.006detects — A.8.15 requires log analysis and monitoring (including UEBA, trend/pattern analysis, threat intel, DNS logs, and correlation) to surface anomalous activity and indicators of compromise; this can catch post-poisoning artifacts such as unusual inbound traffic, cloaking behavior in logs, or suspicious search referrals, but the core SEO manipulation (keyword stuffing, planted links, in-site gaming on PRE platforms) occurs outside monitored systems and leaves no guaranteed detectable event.
- T1609detects — A.8.15 explicitly requires logging, analysis, and monitoring of system activities, privilege use, configuration changes, resource access attempts, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces container admin commands such as docker exec or kubectl exec when they occur within the monitored scope.
- T1610detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and security events (including container deployment via privileged/vulnerable images, workload changes, or unusual API/activity), but this is limited to events that generate observable logs within the organization's estate and does not cover all adversary means of deploying containers (e.g. external image builds or pre-compromise registry activity).
- T1611detects — A.8.15 requires log analysis and monitoring (including SIEM/IDS/UEBA rules, anomalous behaviour detection, correlation of events such as privilege use, configuration changes, and access attempts) that can surface many container/host escape indicators post-facto, but does not mandate coverage of all listed vectors (e.g. kernel module loads, unshare/keyctl syscalls, docker.sock abuse, or hypervisor escapes in ESXi) and stops at identification rather than guaranteeing detection of every instance.
- T1612detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/rules, correlation of events (including system activities, privilege use, file access, configuration changes, and network activity), and identification of indicators of compromise or suspicious behavior that can surface a local container image build containing malware.
- T1613detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and specific monitoring of events (including container-relevant ones such as system activities, privilege use, configuration changes, resource access, and physical monitoring) that surface T1613 indicators like anomalous API queries or dashboard access in container environments.
- T1614detects — A.8.15 requires log analysis and monitoring (including of system activities, configuration changes, network connections, anomalous behaviour, and correlation with threat intelligence) that can surface the execution of location-discovery techniques such as locale queries, metadata access, or outbound geolocation lookups, but only where those actions produce observable events inside the chosen logging and analysis scope.
- T1614.001detects — A.8.15 explicitly requires log analysis and monitoring of events (including system activities, configuration changes, privilege use, and anomalous behaviour via SIEM/UEBA/correlation) that can surface the registry/API/locale queries used by T1614.001, but only when those queries produce observable events inside the chosen logging scope; many language-discovery actions (especially in-process or non-audited) remain unseen.
- T1615detects — A.8.15 requires log analysis and monitoring (including of system activities, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation) that can surface Group Policy discovery commands or related anomalies, but this is scoped by what the organization chooses to log/monitor and does not guarantee coverage of all discovery methods or post-collection analysis.
- T1619detects — A.8.15 explicitly requires log analysis and monitoring of events including successful/rejected resource access attempts, privilege use, configuration changes, and anomalous behaviour (with SIEM/UEBA/threat intel correlation) which surfaces cloud storage enumeration via APIs as an indicator of compromise.
- T1620detects — A.8.15 explicitly requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, unusual activity (including via UEBA, SIEM, IDS, DNS logs, and correlation), which surfaces in-memory reflective loading when it produces observable process or system anomalies; the named remainder is fully fileless cases that leave no detectable footprint in the listed events.
- T1620responds — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS correlation, and incident identification explicitly surface reflective loading once it has executed in a benign process (as an in-memory IOC or anomalous behavior), feeding the incident response process; it does not contain or eradicate the running payload itself.
- T1621detects — A.8.15 explicitly requires logging of successful/rejected access attempts, privilege use, alarms from access control systems, and log analysis (with SIEM/IDS/UEBA/threat intel) to identify anomalous behaviour and indicators of compromise such as repeated login attempts or MFA fatigue patterns.
- T1621prevents — A.8.15 requires logging of access attempts (successful/rejected), privilege use, alarms from access-control systems, and analysis to surface anomalous patterns such as repeated MFA requests that signal fatigue attacks; this constrains the technique on monitored systems but does not stop the generation of MFA prompts themselves.
- T1622detects — A.8.15's log analysis and monitoring explicitly surface anomalous behaviour, indicators of compromise, and events such as privilege use or process anomalies that can include debugger-evasion artifacts (e.g. OutputDebugStringW flooding, SEH exceptions, or unusual API calls), but the control does not mandate instrumentation of the specific low-level debugger checks or PEB/TracerPID reads themselves.
- T1647detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, file accesses/deletions, security system activation, and log analysis (with SIEM/UEBA/threat intel) that surfaces anomalous plist modifications as indicators of compromise or incidents.
- T1648detects — A.8.15 requires log analysis and monitoring of events (including system activities, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation) that can surface serverless function creation/invocation and related cloud events, but this is scoped by what the organization chooses to log/monitor and does not guarantee coverage of all serverless abuse vectors or platforms.
- T1648responds — A.8.15 requires log analysis and correlation (including of cloud/application events, alarms, configuration changes, privilege use, and anomalous behaviour via SIEM/UEBA) to identify suspected incidents for further investigation under incident management, which matches the `responds` verb once the serverless abuse is underway; it is only partial because the control is silent on containment/eradication steps and many T1648 invocations (e.g. stealthy persistence via event triggers in SaaS/Office Suite) leave no detectable log trail within its listed events.
- T1649detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including access attempts, privilege use, configuration changes, and security system events), and identification of suspected incidents such as probing or malware that would surface certificate theft or anomalous enrollment/CA activity.
- T1649responds — A.8.15's log analysis, anomaly detection, correlation, and explicit direction to identify suspected incidents (e.g. probing) and feed them into the incident management process (5.25) directly enacts the `responds` verb once certificate theft/forgery is underway.
- T1650detects — A.8.15 requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts plus physical logs to surface indicators of compromise, which can reveal acquired footholds (e.g. unexpected backdoors, external remote services, or anomalous privileged use) after they exist; it is scoped to what the organization chooses to log/monitor so only a slice of broker-acquired access is surfaced.
- T1651detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including privileged use, configuration changes, system access attempts, and cloud-relevant admin actions), and identification of indicators of compromise or incidents, which surfaces T1651 abuse of cloud management services when logged.
- T1651responds — A.8.15's log analysis, anomaly detection, correlation, and identification of suspected incidents (e.g. via SIEM/IDS/UEBA) enable response once the cloud admin command execution is underway, but this is limited to detection feeding incident handling rather than containment/eradication itself.
- T1652detects — A.8.15 requires logging of system activities, privilege use, configuration changes, and anomalous behaviour plus explicit SIEM/UEBA/correlation analysis that can surface driver-enumeration commands or registry/driver-file accesses as indicators of compromise; this is genuine detection but only a slice because the clause's scope is set by what the organisation chooses to log/monitor and many of the cited discovery utilities produce no observable event unless those exact items are deliberately instrumented.
- T1653detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, configuration changes, alarms, security-system activation/deactivation, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces abuse of powercfg, altered timeouts, deleted shutdown files, or prevented hibernation as security events or indicators of compromise
- T1654detects — A.8.15 mandates log analysis (including SIEM/IDS/UEBA rules, anomaly detection, correlation, and review of access attempts, alarms, and physical events) that surfaces log enumeration and related anomalous behavior in real time or post-facto.
- T1657detects — A.8.15's log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access/financial-relevant events (e.g. privilege use, config changes, resource access) can surface indicators of financial theft campaigns (ransomware extortion, BEC transfers, unauthorized movements), but this is scoped to observable events within the logging policy and does not cover non-logged social engineering, external cryptocurrency exploits, or unmonitored platforms.
- T1657responds — A.8.15's log analysis, anomaly detection, and explicit direction to treat suspected incidents (e.g. probing, malware) as part of incident management (5.25) enables response once financial theft techniques are underway, but only for the detectable subset that produces observable events rather than the full technique surface (social engineering, BEC, extortion demands).
- T1659detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including network/DNS/physical logs), and identification of suspected incidents such as probing or malware, which surfaces T1659-style content injection from upstream or ISP channels as anomalous behavior.
- T1659responds — A.8.15's log analysis, anomaly detection, correlation, and explicit tie to feeding the incident management process (5.25) let it respond to realized content-injection events once underway, but only for the detectable slice observable in the listed events and not the upstream ISP-level channel compromise itself.
- T1665detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of events (including network/DNS/physical logs), and identification of suspected incidents such as probing of firewalls or outbound connections to malicious C2-like servers, which surfaces T1665's traffic manipulation, filtering, and hiding artifacts.
- T1665responds — A.8.15's log analysis, correlation, and identification of suspected incidents (including anomalous network behaviour and probing) enable response actions once T1665 is underway, but the control stops at detection/analysis and does not itself perform containment or eradication.
- T1666detects — A.8.15 requires log analysis, anomaly detection via SIEM/UEBA/threat intel, and explicit review of successful/unsuccessful access attempts, privilege use, configuration changes, and identity creation/modification — all of which surface the API calls and hierarchy alterations named in T1666 after they occur, but only where those events are both logged and fall inside the organization's chosen analysis scope (e.g. not adversary-created external subscriptions or severed accounts that generate no victim logs).
- T1667detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation of logs (including email-related events such as access attempts, alarms, and unusual activity patterns), and identification of suspected incidents such as probing; this surfaces email bombing as anomalous volume or spam patterns in most cases, though coverage depends on whether email-specific logs are in scope.
- T1667responds — A.8.15 requires log analysis and correlation (including of email-related events, alarms, and anomalous patterns) to identify suspected incidents such as probing or overload, which feeds the incident management process (5.25) for response once the bombing is underway; it does not itself contain or eradicate the flood.
- T1668detects — A.8.15's log analysis and monitoring explicitly surface anomalous activity, indicators of compromise, and events such as configuration changes, privilege use, malware-related alarms, and suspicious access that can reveal an adversary performing exclusive-control actions (e.g. patching, disabling services, or removing other malware).
- T1669detects — A.8.15 requires log analysis and monitoring (including of network activity, access attempts, configuration changes, alarms, and anomalous behaviour via SIEM/IDS/UEBA/correlation) that can surface Wi-Fi connection events or follow-on sniffing/AiTM, but this is scoped by what the organization chooses to log/monitor and does not guarantee detection of proximity-based or bridged wireless access itself.
- T1671detects — A.8.15 explicitly requires logging of privilege use, configuration changes, identity creation/modification/deletion, access attempts, and anomalous behaviour via SIEM/UEBA/threat-intelligence-driven analysis, which surfaces the creation, consent-granting, or co-opting of malicious OAuth integrations as indicators of compromise.
- T1673detects — A.8.15 requires log analysis and monitoring of events (including system activities, privilege use, configuration changes, and anomalous behaviour via SIEM/UEBA/correlation) that can surface VM enumeration commands or GUI access after the fact; this is genuine but only a slice, as the control's scope is set by what the organization chooses to log/monitor and does not mandate coverage of hypervisor-specific discovery like esxcli on ESXi.
- T1674detects — A.8.15 explicitly requires logging and analysis of events including successful/rejected access attempts, privilege use, system configuration changes, alarms from access control/IDS, anomalous behaviour via SIEM/UEBA/correlation, and indicators of compromise such as malware or probing, which surfaces most forms of input injection (keystroke simulation, HID, PowerShell launch) once executed.
- T1675detects — A.8.15 explicitly requires logging of system activities, privilege use, configuration changes, resource access attempts, and anomalous behaviour via SIEM/UEBA/correlation, which surfaces the ESXi admin APIs and guest command execution as security events or indicators of compromise.
- T1677detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and correlation of events (including config changes, privilege use, file access/deletion, and security system activation) to surface indicators of compromise; this catches many poisoning indicators post-execution but is silent on build-specific pipeline telemetry or pre-execution detection of malicious PRs/forks, leaving a large slice of the SaaS technique unreached.
- T1678detects — A.8.15 requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and specific monitoring (e.g. of system activities, scheduled tasks, privilege use, and network behavior) that can surface many time-based delay techniques once they execute, but this is scoped by what the organization chooses to log/monitor and does not guarantee coverage of all variants (e.g. API hammering or sandbox-specific sleeps).
- T1679detects — A.8.15 explicitly requires log analysis, anomaly/behaviour detection, SIEM/IDS/UEBA rules, correlation, and review of access attempts plus physical events to surface indicators of compromise such as selective ransomware activity that leaves system files untouched.
- T1680detects — A.8.15 explicitly requires logging and analysis of system activities, privilege use, configuration changes, resource access attempts, and anomalous behaviour (including via SIEM/UEBA/correlation), which surfaces the commands, CLI calls and API invocations used in T1680 across its platforms; the named remainder is pre-compromise discovery on third-party IaaS infrastructure outside the organization's logging scope.
- T1681detects — A.8.15's log analysis, anomaly detection via SIEM/IDS/UEBA, correlation, and review of events (including outbound connections, unusual activity, and indicators of compromise) can surface an adversary querying threat vendor data or related IOCs when that activity produces observable logs, but this is limited to what the organization's own monitored logs actually capture and is not inherent to the technique's PRE platform reconnaissance nature.
- T1682detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise, which can surface T1682 queries to public AI services when they produce observable network, application or usage anomalies inside the monitored scope; the remainder is that most such queries are indistinguishable from legitimate traffic and fall outside the clause's predetermined rules or UEBA patterns.
- T1683.002detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour, indicators of compromise, and suspected incidents (including via UEBA, SIEM, IDS, and correlation), which can surface use of synthetic audio-visual content when it produces observable artifacts in supported techniques such as phishing or social engineering; this is limited to a slice because the control is silent on media authenticity detection and most T1683.002 activity (e.g. offline generation on PRE) leaves no logged trace.
- T1684detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts, alarms, privilege use, and suspicious activity to identify indicators of compromise and security events, which surfaces social engineering once the prompted user action (e.g. credential disclosure, MFA change, or malicious execution) produces observable logs.
- T1684.001detects — A.8.15 requires log analysis and monitoring (SIEM/UEBA/IDS correlation, anomalous behaviour review, DNS logs, physical logs) that can surface impersonation indicators such as anomalous access, unusual email patterns or spoofed sender activity once the technique is in flight; it does not guarantee detection of every social-engineering vector or pre-delivery reconnaissance.
- T1684.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation of logs (including DNS, access attempts, and physical events), and identification of suspected incidents such as probing or malware, which surfaces spoofed emails that produce observable artifacts in mail logs, headers, authentication failures, or anomalous sending patterns.
- T1685detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of logs (including from security systems and physical monitoring), and identification of suspected incidents such as probing or malware, which surfaces tampering with logging agents, event log modifications, or disabled sensors/telemetry as described in T1685.
- T1685prevents — A.8.15 requires protection of logs against deletion, alteration, deactivation, and overwriting (via append-only, hashing, access controls, and synchronized time sources), which directly stops many of the technique's sub-actions against logging agents, event logs, syslog, and SIEM pipelines, but leaves untouched the broader tampering of EDR/IDS/AV, sensors like ETW/Sysmon, configuration files outside logs, update mechanisms, and non-log defensive tools.
- T1685.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation, and monitoring of successful/failed access, DNS, physical events, and suspected incidents to surface tampering or disablement of logging itself.
- T1685.001prevents — A.8.15's determination of what must be logged, protection of the logging facility against disablement/alteration/deletion, prohibition on users (including privileged) deleting their own logs, and requirements for synchronized protected logs directly counters the T1685.001 techniques of stopping the EventLog service, altering auditpol/registry settings, or clearing policies; the bounded remainder is non-Windows platforms and logs outside the organization's defined scope.
- T1685.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation, and identification of suspected incidents (e.g. probing), which surfaces the disable/modify action when it affects observable events or leaves detectable gaps.
- T1685.002prevents — A.8.15's requirements to protect logs against deletion/deactivation, unauthorized changes, failure to record, and overwriting (via append-only, hashing, etc.) plus mandatory logging of access attempts, privilege use, and config changes directly stop many of the described modifications and bypasses, but the control is silent on cloud-specific integrations, licensing, or command-level toggles and cannot reach an adversary who already holds sufficient privileges to alter the logging configuration itself.
- T1685.003detects — A.8.15 requires log analysis and monitoring to identify anomalous behaviour and indicators of compromise (including via SIEM, UEBA, correlation, and review of access/security events), which can surface the spoofed-UI technique when it produces detectable discrepancies in logs or monitored signals, but the control has no view of purely visual UI fakery that leaves no log trail.
- T1685.004detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of logs (including successful/rejected access, privilege use, config changes, and security system activation), and identification of suspected incidents such as probing or malware — all of which surface attempts to disable or modify auditd rules, kill the daemon, or alter /etc/audit/* files when those actions are themselves logged and reviewed.
- T1685.004prevents — A.8.15 requires determining what to log, protecting logs against deletion/alteration/failure (via append-only, hashing, etc.), and analyzing them to identify incidents, which directly counters disabling or modifying auditd/rules on Linux; however, it is a policy-and-configuration mandate whose actual enforcement depends on implementation rigor and does not itself block root-level hooking or service-kill techniques.
- T1685.004responds — A.8.15 requires log protection (no deletion/deactivation by users, append-only mechanisms, integrity via hashing) and analysis to identify incidents once underway, which responds to the technique's effects but does not cover all vectors like kernel hooking or pre-modification of rules.
- T1685.005detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of logs (including security/audit events), and identification of suspected incidents such as probing or malware that would surface the clearing of Windows Event Logs.
- T1685.005prevents — A.8.15 explicitly requires protecting logs against deletion, editing, deactivation, overwriting, or unauthorized changes (via append-only/read-only mechanisms, crypto hashing, privilege restrictions, and retention), which directly stops the T1685.005 clearing actions on Windows Event Logs; mostly because the control is a set of requirements whose completeness depends on implementation rigor and does not name every possible clearing vector (e.g. direct .evtx deletion in all scenarios).
- T1685.005responds — A.8.15 explicitly requires protecting logs against deletion/alteration (no user permission to delete own-activity logs, append-only/read-only mechanisms, cryptographic hashing), detecting the clearing via analysis/monitoring of anomalous events, and subjecting suspected incidents (including log-clearing as an indicator of compromise) to incident response per 5.25, which matches the `responds` verb of containment/eradication once the technique is underway.
- T1685.006detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, correlation, and review of access attempts/alarms to surface suspected incidents such as log tampering that would be visible in protected logs or their absence.
- T1685.006prevents — A.8.15 explicitly requires protecting logs against deletion/editing/overwriting (including by privileged users), using append-only/read-only mechanisms, cryptographic hashing, and retention policies, which directly stops the adversary action of clearing /var/log/* files on Linux/macOS.
- T1685.006responds — A.8.15 requires log protection (no deletion by actors, append-only mechanisms, cryptographic hashing) plus explicit identification of suspected incidents (e.g. probing, anomalous activity) for further investigation under the incident management process, which directly enacts containment/eradication once the clearing technique is underway.
- T1686detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules and patterns, correlation of events (including changes to system configuration, use of privileges, alarms from access control systems, and activation/deactivation of security systems), and identification of indicators of compromise such as probing of firewalls, which surfaces T1686 behaviors after they occur.
- T1686prevents — A.8.15 mandates logging of configuration changes, privilege use, security system activation/deactivation and alarms, plus protected logs that cannot be deleted or altered by the actor; this surfaces or constrains many T1686 behaviors (especially post-privilege tampering) but does not stop the adversary from disabling or modifying the firewall itself.
- T1686responds — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification directly surface firewall tampering once it has occurred (the technique has run), feeding the incident response process, but this is only a detection slice that does not itself contain or eradicate the actor's changes.
- T1686.001detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of configuration changes, privilege use, security system activation/deactivation, and physical events to surface indicators of compromise such as firewall rule modifications.
- T1686.002detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, and monitoring of configuration changes, privilege use, security system activation/deactivation, and firewall-related events to surface suspected incidents such as probing or rule manipulation.
- T1686.003detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA rules, correlation of logs (including successful/rejected access attempts, configuration changes, privilege use, alarms from access control systems, and activation/deactivation of security systems), and identification of suspected incidents such as probing of firewalls, which surfaces T1686.003 activity after it occurs.
- T1686.003responds — A.8.15's log analysis, anomaly detection, correlation, and explicit identification of incidents (e.g. probing of firewalls) followed by further investigation directly enacts the `responds` verb once the firewall modification is underway.
- T1687detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/IDS/UEBA/threat intel, monitoring of access attempts/alarms/security system activation, and correlation to identify suspected incidents including probing or malware that can represent defense-impairment activity.
- T1688detects — A.8.15 requires log analysis and monitoring (including of system configuration changes, privilege use, boot-related events via alarms/IDS, and anomalous behaviour via SIEM/UEBA/correlation) that can surface safe-mode boots and related Registry/BCD tampering as indicators of compromise, but this is scoped by what the organization chooses to log/monitor and does not guarantee coverage of all safe-mode abuse vectors.
- T1689detects — A.8.15 explicitly requires log analysis (with SIEM/UEBA/rules/threat intel/correlation) and monitoring of events including privilege use, configuration changes, system activities, and anomalous behaviour to surface indicators of compromise such as a downgrade that impairs logging or security controls.
- T1690detects — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/rules, correlation, and review of access attempts plus security-system events to surface indicators of compromise; this surfaces the technique when it produces observable anomalies or is itself logged as a configuration change/privilege use, but the core in-memory HIST* or Set-PSReadLineOption manipulations often leave no detectable event and fall outside the clause's named detection scope.
Prevented OWASP Web Top 10 (2025) risks (28)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A01finds — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, and correlation to surface suspected incidents including access-control violations (e.g. rejected attempts, privilege use, configuration changes), but this is post-facto discovery only and does not cover design-time or code-level access-control defects such as path traversal, IDOR or CSRF that never reach logs.
- A01mitigates — logging and its analysis can detect and limit the realized impact of some broken-access-control events (e.g. via alarms on privilege use, configuration changes, or anomalous access patterns) but does not bound or reduce the consequence of the majority of the category (path traversal, IDOR, CSRF, missing function-level checks)
- A02finds — A.8.15 explicitly requires log analysis (with SIEM/IDS/UEBA/threat-intel rules, anomaly detection, DNS/firewall review, correlation) that surfaces misconfigurations as security events or indicators of compromise, but this is only one slice of the broad A02 class (e.g. it catches runtime symptoms of weak defaults or exposed surfaces but does not discover static config flaws like unhardened framework defaults or cloud IAM gaps before they are exercised).
- A02mitigates — logging and its analysis can detect anomalous behavior resulting from a misconfiguration (e.g. via alarms, access attempts, configuration changes) and thereby limit the realized consequence or duration of an incident, but the weakness itself (the exposed configuration) remains untouched
- A05finds — A.8.15 explicitly requires log analysis, SIEM/IDS/UEBA rules, anomaly detection, and correlation to identify security events and indicators of compromise, which surfaces many injection attempts (e.g. probing, anomalous queries, outbound C2) after they occur; it does not discover injection flaws in code or untriggered weaknesses.
- A05mitigates — A.8.15's log analysis, anomaly detection, SIEM/IDS correlation and incident identification can surface realized injection (e.g. outbound C2 from command injection or anomalous SQL patterns) and thereby limit further damage, which is mitigation of consequence; it does not stop the untrusted input from reaching or succeeding at the interpreter boundary itself.
- A07finds — A.8.15 explicitly requires log analysis, anomaly detection via SIEM/UEBA/IDS rules, correlation, and review of access attempts (including successful/failed logons and privilege use) to surface suspected incidents, which discovers many authentication failures such as brute-force or anomalous credential use; it does not discover design defects like weak reset flows or flawed session management that are not expressed in observable events.
- A07mitigates — A.8.15's log analysis, anomaly detection, and correlation of access attempts (including failed logons, privilege use, and alarms) can surface indicators of brute-force, credential stuffing, or hijacking after they occur, bounding the realized consequence without stopping the authentication weakness itself.
- A08finds — A.8.15's log analysis and monitoring sections surface anomalous activity, indicators of compromise, and suspected incidents that can include integrity failures (e.g. unsigned updates or CI/CD anomalies via correlated logs, UEBA, or threat intel), but this is indirect, post-facto, and limited to detectable events rather than systematically finding the class's core weaknesses like insecure deserialization.
- A08mitigates — A.8.15's log analysis, anomaly detection, and correlation (including physical logs and threat intel) can surface indicators of integrity failures such as unsigned updates or CI/CD tampering after they occur, thereby bounding consequences, but does not limit the realization of the weakness itself.
- A09mitigates — A.8.15 directly protects log integrity, prevents deletion/alteration by users (including privileged), mandates synchronized protected logging of security events, and requires analysis to identify anomalies/incidents, which bounds the realized impact of missing or tampered logs without preventing the logging failure itself.
- A10finds — A.8.15 explicitly requires log analysis (including SIEM/IDS/UEBA rules, anomaly detection, trend analysis, and correlation of events such as access attempts, configuration changes, and alarms) to identify unusual activity or indicators of compromise that can represent mishandled exceptions or logic-flaw errors, but this is only one slice of the broad A10 class (e.g., it surfaces runtime leaks or fail-open states via logs but does not inspect code for inconsistent error paths or fail-open auth design).
- A10mitigates — Logging and its analysis can detect anomalous states or leaked information from mishandled exceptions after they occur, thereby bounding the consequence, but does not address fail-open behavior, inconsistent states, or prevent the mishandling itself.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.