A.8.16 Technological
Monitoring activities
Structured attributes from ISO/IEC 27002:2022 — control type · CIA properties · cybersecurity concept · operational capability · security domain. What do these mean?
Mapped NIST 800-53 r5 controls (21)
Our AI-authored reading (authority llm_unverified, under review) of how this ISO control and each NIST 800-53 control relate. Not an ISO or NIST product.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- AU-12mostlycovers — A.8.16's monitoring activities to detect anomalies and incidents directly accounts for the bulk of AU-12's audit generation, selection, and content requirements (as the operational mechanism that consumes and acts on those records), but a real residual remains in AU-12's upstream definition and configuration aspects that sit in AU-2.
- AU-2mostlycovers — A.8.16's requirement to detect anomalous behaviour and incidents is substantially met by au-2's identification, coordination, and specification of auditable events that directly support anomaly and incident detection, but a residual of au-2's narrower audit-function focus (e.g., exact parameter selection mechanics) sits outside A.8.16's broader monitoring intent.
- AU-6mostlyaligns with — Both require review and analysis of monitoring records to identify security events and support incident response and improvement activities.
- AU-6mostlycovers — A.8.16's mandate to monitor for anomalous behaviour and potential incidents directly accounts for the core of AU-6's review/analysis/reporting of audit records for indications of inappropriate/unusual activity and risk-based adjustment; residual exists in AU-6's explicit law-enforcement-informed trigger and specific reporting recipients not required by A.8.16.
- CA-7mostlycovers — A.8.16's requirement to detect anomalous behaviour and potential incidents accounts for the bulk of CA-7's continuous monitoring implementation and metrics, but leaves a residual on the organization-level strategy development and formal assessment frequencies that sit outside pure detection activities.
- SI-4mostlyaligns with — Both controls establish continuous monitoring against a defined baseline to detect anomalies, unauthorized access, and malicious activity, with alert generation and response procedures.
- SI-4mostlycovers — A.8.16's broad mandate to monitor for anomalous behaviour and potential incidents accounts for the bulk of SI-4's detection objectives (attacks, unauthorized connections/use), but leaves a residual slice of specific techniques, methods, and invocation/deployment details uncovered.
- AU-12partialaligns with — Both address the generation of audit records from network, system, and application sources to enable detection and investigation of security-relevant events.
- AU-2partialaligns with — Both specify the types of events and activities that must be captured by the monitoring system to support security objectives.
- CA-7partialaligns with — Both emphasize ongoing monitoring of security controls and system behavior to maintain situational awareness and support risk management.
Aligned NIST CSF 2.0 outcomes (19)
NIST CSF 2.0 outcomes this ISO control aligns with — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- DE.AE-02mostlyaligns with — Establishing a normal-behavior baseline and analyzing deviations from it provides the analytical foundation the CSF outcome seeks for understanding activities associated with potentially adverse events.
- DE.CM-01mostlycovers — The ISO control's emphasis on continuous, baseline-driven monitoring of network traffic, system activity, and security-tool logs directly fulfills the CSF outcome of monitoring networks and services to detect potentially adverse events.
- DE.CM-03mostlycovers — The ISO control's focus on tracking user access patterns, authentication attempts, and deviations from normal behavior aligns with the CSF outcome of monitoring personnel activity and technology usage.
- DE.CM-09mostlycovers — By requiring monitoring of hardware/software runtime behavior, resource utilization, and code integrity, the ISO control satisfies the CSF outcome of monitoring computing environments and their data for adverse events.
- DE.AE-06partialaligns with — The ISO control's automated alerting and communication of abnormal events to relevant personnel fulfills the CSF outcome of providing adverse-event information to authorized staff and tools.
- DE.AE-07partialaligns with — The ISO control integrates threat signatures, malicious IP lists, and known attack patterns into monitoring, which supports the CSF outcome of incorporating cyber threat intelligence into event analysis.
- PR.PS-04partialaligns with — Requiring generation and retention of event logs from systems, applications, and security tools directly supports the CSF outcome of making log records available for continuous monitoring.
- DE.AE-02implements — A.8.16's monitoring activities give operational effect to adverse-event analysis within the detection domain that DE.AE-02 names, but the CSF outcome does not cite monitoring specifically
- DE.AE-06implements — A.8.16's monitoring activities directly operationalize the provision of adverse-event information to staff/tools that DE.AE-06 requires; the link is within the detection/analysis domain but the CSF outcome does not name monitoring explicitly
- DE.AE-07implements — Assessed as NOT holding by the authoring instrument at v1.22-2026-08-29. This row records a tested non-relation; it is not a graded claim and carries no rationale, because the instrument produced none when the verb did not hold.
- PR.PS-04implements — A.8.16's monitoring activities give operational effect to generating and exposing logs specifically for continuous monitoring (PR.PS-04), as logging is a core technical means within the monitoring domain, though not the only one and not explicitly named by the control.
Related OWASP ASVS 5.0 requirements (13)
Application-security verification requirements (OWASP ASVS 5.0) this ISO control aligns with; links open the ASVS chapter. Our AI-authored analysis (authority llm_unverified, under review) — many ISO controls have no ASVS counterpart.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- V16.2.1mostlyaligns with — The ISO control's requirement to capture detailed event metadata (who, what, when, where) for security-relevant activities directly supports the ASVS mandate that every log entry contain sufficient context for later investigation.
- V16.3.1mostlyaligns with — Both documents require logging of all authentication attempts (successful and unsuccessful) together with contextual metadata, enabling detection and forensic review of credential-based attacks.
- V16.3.2mostlyaligns with — The ISO guidance to log successful and unsuccessful attempts to access protected resources aligns with the ASVS requirement to record failed (and, at L3, all) authorization decisions.
- V16.3.3partialaligns with — ISO's mandate to log attempts to bypass security controls and to monitor against a baseline of expected behaviour partially satisfies the ASVS requirement to log both the documented security events and any bypass attempts.
- V16.4.2partialaligns with — The ISO control's emphasis on protecting monitoring records for defined retention periods and ensuring they cannot be tampered with aligns with the ASVS requirement that logs be protected from unauthorized access and modification.
- V16.4.3partialaligns with — ISO's call for continuous, real-time or periodic monitoring with redundant alert paths and timely incident response partially maps to the ASVS requirement to transmit logs securely to a separate system for analysis and escalation.
- V2.4.1partialaligns with — The ISO requirement to detect anomalous resource usage and excessive or unusual access patterns supports the ASVS objective of implementing anti-automation controls that protect against data exfiltration via high-frequency calls.
Related weaknesses / CWE (43)
Weakness classes this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- CWE-1050finds — Monitoring can alert on resource abuse but does not eliminate the coding flaw.
- CWE-117finds — Monitoring activities rely on trustworthy logs but do not ensure log message integrity.
- CWE-1250finds — Monitoring can detect inconsistencies after they occur but does not prevent them by design.
- CWE-1320finds — Monitoring activities can detect disabled or suppressed outbound alerts.
- CWE-200finds — Continuous monitoring of access attempts and anomalous behaviour makes it harder for an attacker to keep unauthorized disclosure of sensitive data undetected.
- CWE-202finds — Monitoring can identify anomalous query patterns indicative of inference attacks.
- CWE-223finds — Monitoring activities rely on the very information whose absence defines the weakness.
- CWE-284finds — Detection of unauthorized access attempts and deviations from expected access patterns reduces the window in which improper access control can be exploited without notice.
- CWE-360finds — Monitoring activities may detect anomalies in event data but do not guarantee the trustworthiness of the source.
- CWE-385finds — Continuous monitoring may detect timing-based exfiltration but does not eliminate the channel itself.
- CWE-390finds — Monitoring activities can detect errors, yet without defined response procedures the weakness persists.
- CWE-400finds — Resource-utilization monitoring and alerting on bottlenecks or overloads limits the impact of denial-of-service or resource-exhaustion attacks.
- CWE-406finds — Monitoring activities can detect anomalous traffic volumes, yet detection alone does not enforce control.
- CWE-407finds — Monitoring activities can identify anomalous resource consumption indicative of algorithmic complexity attacks.
- CWE-409finds — Monitoring can detect anomalous resource usage but does not prevent the weakness.
- CWE-506finds — Checks that executed code has not been tampered with and monitoring for malware-associated activity reduce the likelihood that hidden malicious code remains active.
- CWE-507finds — Monitoring activities can identify Trojan Horse behavior but do not stop its introduction.
- CWE-509finds — Monitoring activities enable early detection of replicating malicious code.
- CWE-511finds — Monitoring activities may detect anomalous behavior triggered by a logic/time bomb.
- CWE-515finds — Monitoring can detect covert storage but does not eliminate the underlying weakness.
- CWE-69finds — Monitoring activities can flag anomalous ADS usage, providing partial mitigation through detection rather than prevention.
- CWE-74finds — Monitoring activities can identify active injection attacks after they occur.
- CWE-754finds — Monitoring may detect symptoms of unhandled conditions but does not eliminate the root weakness.
- CWE-755finds — Monitoring can surface unhandled exceptions but does not enforce proper handling.
- CWE-770finds — Baseline comparison of CPU, memory and bandwidth usage helps surface uncontrolled resource allocations before they cause service degradation.
- CWE-778finds — Mandating retention of monitoring records and real-time or periodic logging directly counters insufficient logging by ensuring security-relevant events are captured.
- CWE-779prevents — Monitoring activities can detect excessive logging but do not prescribe how much data should be logged.
- CWE-807finds — Monitoring can detect exploitation but does not stop the underlying weakness.
- CWE-91finds — Monitoring can detect exploitation but provides no preventive control over XML handling.
- CWE-912finds — Monitoring activities can detect anomalous behavior from hidden functions but do not eliminate the weakness.
Mitigated MITRE ATT&CK techniques (2531)
Adversary techniques (MITRE ATT&CK Enterprise) this ISO control helps mitigate; links open attack.mitre.org. Our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- T1001detects — A.8.16 explicitly includes monitoring of network traffic, anomalous behaviour, known attack characteristics, deviations in protocols, and patterns that can surface obfuscated C2 (including via baselines and signatures), but the clause sets scope by organisational requirements rather than mandating universal coverage of all obfuscation methods or platforms, leaving a large slice determined by the implementer.
- T1001responds — A.8.16 requires real-time/periodic monitoring, anomaly detection against baseline (including known attack patterns, unusual behaviour, and traffic), alert generation, and timely procedures to respond to positive indicators per 5.26; this surfaces and acts on realized T1001 C2 once underway, but scope is set by org requirements so coverage of obfuscated traffic is not guaranteed.
- T1001.001detects — A.8.16 explicitly lists monitoring of network traffic, anomalous behaviour, known attack characteristics, deviations in protocols, and real-time pattern recognition that can surface junk-data C2; scope is set by organisational requirements rather than mandating universal deep-packet or protocol-specific decoding, leaving a genuine slice of implementations that miss it.
- T1001.002detects — A.8.16 requires monitoring of network traffic, anomalous behaviour patterns, known attack characteristics and deviations (including from baselines), which can surface steganographic C2 as an anomaly in traffic or behaviour, but the control's scope is set by organisational requirements rather than mandating detection of every hidden channel, leaving a genuine slice unreached.
- T1001.002responds — A.8.16 requires real-time/periodic monitoring, anomaly detection against baseline (incl. unusual network traffic, known attack patterns, malware-associated behaviour), alerting, and timely procedures to respond to positive indicators (explicitly referencing 5.26 incident response); this acts on steganographic C2 once underway to contain/eradicate but only for detectable cases, leaving many hidden instances (the technique's explicit purpose) unreached.
- T1001.003detects — A.8.16 explicitly lists monitoring of network traffic, anomalous behaviour patterns, known attack characteristics, deviations in standard protocols, and real-time signature/behaviour-based detection that can surface protocol impersonation when it deviates from the established baseline, but the clause's scope is set by organisational requirements rather than mandating universal coverage of all impersonation variants (e.g. perfectly mimicked trusted services).
- T1001.003prevents — A.8.16 mandates monitoring of network traffic, baselines, anomalous patterns (incl. protocol deviations, known attack characteristics, and malicious domains) plus real-time alerts, which can block or deter impersonated C2 that deviates from the established baseline; however the clause only sets scope by requirements and does not mandate universal deep-packet or protocol-validation mechanisms that would stop every malleable or perfectly mimicked instance.
- T1001.003responds — A.8.16's real-time/continuous monitoring of network traffic, anomalous patterns, known attack characteristics, and deviations (including protocol anomalies) surfaces impersonated C2 traffic once underway, enabling timely response per linked 5.26 procedures; mostly because scope is set by org requirements rather than mandating universal depth on all impersonation variants.
- T1003detects — A.8.16 explicitly lists monitoring of process injection, anomalous system behaviour, event logs, security tool outputs, resource use, and known attack patterns; T1003 (credential dumping) produces observable artifacts in exactly these categories (e.g. LSASS access, memory reads, Mimikatz-like patterns) that fall inside the defined baseline and alerting scope, with only a bounded remainder (stealthiest in-memory techniques on unmonitored hosts) outside.
- T1003responds — A.8.16 surfaces anomalous behaviour including process injection, unusual system behaviour, unauthorized access attempts, and deviations from baseline (all observable indicators of credential dumping in flight); alerts feed directly into 5.26 response procedures for containment and eradication once the technique is underway, with the named remainder being stealthy dumps that produce no detectable anomaly before completion.
- T1003.001detects — A.8.16 explicitly lists process injection, anomalous system behaviour, access to critical processes, security-tool logs, event logs, resource use, and real-time anomaly detection against baseline, all of which surface LSASS dumping or SSP tampering in flight or post-execution on monitored Windows hosts; the named remainder is execution outside the defined monitoring scope.
- T1003.001prevents — A.8.16's real-time baseline monitoring for anomalies (incl. process injection, unauthorized access, unusual behaviour, and code-tampering checks) can surface or block some LSASS dumping vectors before credential harvest succeeds, but the clause sets scope by organisational requirements rather than mandating universal LSASS protection, leaving many in-memory/registry/SSP techniques outside the covered slice.
- T1003.001responds — A.8.16 surfaces LSASS dumping or anomalous process/memory behaviour (explicitly names process injection and unusual system behaviour) in real time or near-real time, hands it to the 5.26 response procedure for containment/eradication once underway; the named remainder is post-exfiltration credential use that has already left the monitored estate.
- T1003.002detects — A.8.16 explicitly lists monitoring for process injection, anomalous system behaviour, security-tool logs (AV/IDS/IPS), event logs, resource use, and deviations from baseline (including unusual access and known attack patterns); these surface in-memory SAM extraction via tools such as Mimikatz that rely on process injection or registry access, though some purely file-based offline extraction after the fact sits outside real-time monitoring scope.
- T1003.002responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (incl. process injection, unauthorized access, malware-associated activity) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26, which matches the `responds` verb once the technique is underway; partial because the clause sets scope by business requirements rather than mandating universal coverage of all in-memory/registry SAM extraction methods.
- T1003.003detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access to protected resources (e.g. file systems), unusual system behaviour, and security-tool logs (e.g. IDS/IPS), which can surface T1003.003 in real time or near-real time when it deviates from baseline; scope is set by organisational requirements rather than mandating coverage of every NTDS-access vector (e.g. offline backup enumeration or volume-shadow methods outside monitored telemetry), so the slice caught is implementer-chosen rather than a bounded remainder.
- T1003.003responds — A.8.16's real-time/periodic anomaly detection, baseline comparison, and alert generation on indicators such as unauthorized access, process injection, or unusual file/system behaviour can surface an in-progress NTDS.dit access or copy attempt once it deviates from baseline, enabling timely response per linked 5.26 procedures; however, the control's scope is set by organizational requirements rather than mandating coverage of all domain-controller file-access vectors, leaving a genuine slice unreached.
- T1003.004detects — A.8.16 explicitly lists process injection, anomalous system behaviour, registry access patterns, unusual resource use, and known attack signatures as detectable anomalies, which can surface LSA Secrets dumping (especially via Mimikatz or registry reads), but the clause sets scope by organisational requirements so coverage of this specific technique is not mandated and remains a chosen slice.
- T1003.004responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (including process injection and unauthorized access), alerting, and timely response procedures to minimize adverse effects once an incident is underway, which can respond to LSA secrets dumping in flight via dedicated personnel and tuning, but only for observable indicators within the chosen monitoring scope rather than guaranteeing containment of every such event.
- T1003.005detects — A.8.16's monitoring of system logs, resource use, process anomalies, unauthorized access attempts, and explicit mention of process injection can surface T1003.005 execution (e.g. Mimikatz or tdbdump activity) when it deviates from baseline, but the clause sets scope by organizational requirements rather than mandating coverage of credential-cache access paths, leaving many implementations without relevant telemetry.
- T1003.006detects — A.8.16 explicitly lists monitoring for process injection, anomalous system behaviour, access to critical systems/servers, security tool logs (including IDS/IPS), event logs, and deviations from baseline (including unusual user/system behaviour), which surfaces the observable artifacts of a DCSync (replication API calls, anomalous DC access, lsadump-like behaviour) in most cases once it occurs on the monitored estate; the bounded remainder is pre-compromise reconnaissance or fully stealthy implementations that evade all listed indicators.
- T1003.006responds — A.8.16 requires real-time/periodic monitoring of network traffic, access to critical systems (incl. domain controllers), security-tool logs, anomalous behaviour (incl. process injection and unauthorized access), and dedicated trained personnel plus procedures to respond to alerts (cross-referenced to 5.26 incident response), which directly contains and eradicates an in-progress DCSync once its observable indicators appear; the named remainder is stealthy or sub-threshold executions that evade the tuned baseline before response is triggered.
- T1003.007detects — A.8.16 requires monitoring of system activity, process behavior, resource use, and anomalies (including process injection and deviations), which can surface proc filesystem access or memory scraping in real time or via logs when inside the chosen scope, but the clause explicitly sets scope by business requirements rather than mandating universal coverage of this Linux-specific technique.
- T1003.008detects — A.8.16 explicitly lists monitoring for access to critical files, unauthorized access attempts, anomalous system behaviour (including process injection), event logs, and deviations from baseline, which surfaces many instances of this file-dump technique in real time or near-real time; it is only partial because the clause lets the organization set its own scope and level, so an implementation that excludes host-file-access telemetry remains compliant yet misses the technique.
- T1003.008responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including unauthorized access attempts, process anomalies, and deviations from baseline), which surfaces the technique once underway so dedicated personnel can respond per linked procedures (5.26); partial because the clause sets scope by org requirements rather than mandating universal coverage of every credential-dump vector (e.g. non-monitored processes or non-anomalous root reads).
- T1005detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access to systems/information, unusual system behaviour, access to critical files/configs, and resource/performance deviations, which can surface T1005 activity when it deviates from the established baseline; however the clause sets scope by organisational requirements rather than mandating universal coverage of all local-system collection methods (e.g. quiet scripted searches matching normal admin patterns).
- T1006detects — A.8.16 explicitly lists monitoring for file system activity, unauthorized access, process injection, anomalous behaviour, and resource/performance deviations, which can surface many T1006 indicators (e.g. unusual volume I/O, shadow copy utilities, or deviations from baseline), but the technique is explicitly designed to bypass file system monitoring and the clause's scope is set by organizational requirements rather than mandating coverage of direct volume access.
- T1007detects — A.8.16 explicitly lists monitoring for anomalous behaviour, process injection, unusual system behaviour, resource use, and known attack characteristics, which can surface T1007's command-line discovery activity when it deviates from baseline; however the clause's scope is set by organisational requirements rather than mandating universal coverage of every discovery command, leaving a large slice of stealthy or in-policy executions undetected.
- T1008detects — A.8.16 requires monitoring of network traffic, anomalous behaviour, known attack patterns, and deviations (including process injection or protocol anomalies), which can surface fallback channel use when it produces observable deviations from baseline; however the clause explicitly sets scope by organisational requirements rather than mandating universal coverage of all possible alternate C2 channels, leaving a large slice of stealthy or novel implementations unseen.
- T1010detects — A.8.16 requires monitoring for anomalous behaviour (incl. process injection, unusual system behaviour, and deviations from baseline) and can surface T1010 when it triggers observable anomalies or is performed via monitored channels such as command/script interpreters, but the control's scope is set by organisational requirements rather than mandating coverage of all window-enumeration vectors, leaving a large slice of stealthy or in-process T1010 undetected.
- T1011detects — A.8.16 requires monitoring of network traffic, anomalous behaviour, and deviations (including unusual protocols or exfiltration-like patterns) against a baseline, which surfaces T1011 when it deviates from expected wired/enterprise channels, but scope is set by organisational requirements so non-monitored mediums (Bluetooth, cellular, etc.) remain unseen.
- T1011responds — A.8.16 requires real-time/periodic monitoring of network traffic (inbound/outbound), anomalous behaviour, and alerts with dedicated response personnel per 5.26; this surfaces and enables response to exfiltration once underway over alternate media, but only for monitored channels (e.g. not air-gapped Bluetooth/RF), making the coverage a chosen slice rather than bounded remainder.
- T1011.001detects — A.8.16 requires monitoring of network traffic, system activity, resource use, and anomalies (including deviations in protocols or malware-like behaviour), which can surface Bluetooth exfiltration when it produces observable anomalies inside the chosen monitoring scope, but the clause explicitly sets that scope by organisational requirements rather than mandating Bluetooth-specific coverage, leaving out-of-scope Bluetooth channels undetected.
- T1012detects — A.8.16 explicitly lists monitoring for anomalous behaviour, process injection, unauthorized access, system activity logs, baselines of normal behaviour, and real-time/periodic anomaly detection that can surface Registry queries when they deviate from the established baseline or match known malicious patterns, but the clause's scope is set by organisational requirements rather than mandating coverage of all Registry queries (especially stealthy or non-anomalous ones).
- T1014detects — A.8.16 explicitly lists process injection, anomalous system behaviour, code tampering checks, resource/performance deviations, and known attack patterns as monitoring targets, which surface many rootkit indicators in real time or near-real time; however the clause's scope is set by organisational requirements rather than mandating universal coverage of all kernel/bootkit/hypervisor techniques, leaving a genuine implementation-chosen slice.
- T1014prevents — A.8.16 requires monitoring for anomalous behaviour including process injection, unauthorized code execution, tampering, and deviations from baseline (explicitly naming process injection and related indicators), which can surface rootkit activity in real time or near-real time and thereby prevent the rootkit from remaining hidden or fully effective on monitored systems; however the clause sets scope by organisational requirements rather than mandating universal coverage of kernel/boot/firmware rootkits, leaving a genuine slice of the technique (especially lower-level or non-anomalous implementations) unreached.
- T1014responds — A.8.16's real-time/periodic monitoring, anomaly detection (including process injection and unusual behaviour), alerting, and procedures to respond to positive indicators directly enable containment/eradication once a rootkit is running and observed, but rootkits' stealth (API hooking, kernel/boot level) leaves substantial undetected execution before response.
- T1016detects — A.8.16 requires monitoring of network traffic, access, configuration files, event logs, resource use, and explicit anomalous behaviours including unauthorized scanning and deviations from baseline; this surfaces many instances of T1016 (especially CLI utilities, esxcli, anomalous access or scanning) once they produce observable artifacts, but the clause sets scope by organisational requirements rather than mandating universal coverage of every discovery command on every platform, leaving a genuine slice unseen.
- T1016.001detects — A.8.16 requires monitoring of network traffic, anomalous behaviour, known attack patterns, and deviations from baseline (including unusual system behaviour), which can surface Internet Connection Discovery when it matches monitored signatures or anomalies, but the clause's scope is set by organisational requirements rather than mandating universal coverage of this specific discovery technique.
- T1016.002detects — A.8.16 requires monitoring of network traffic, system logs, resource use, anomalous behaviour patterns and known attack characteristics (including process injection and deviations in protocols), which can surface Wi-Fi discovery commands, file accesses or API calls when they deviate from baseline; however the clause's scope is set by organisational requirements rather than mandating coverage of every local discovery technique, leaving a large slice of stealthy or low-signal instances (e.g. reading known profile files without triggering thresholds) outside guaranteed detection.
- T1018detects — A.8.16 explicitly monitors network traffic, access, configuration files, event logs, resource use, anomalous behaviour (including unusual scanning and deviations from baseline), and known attack patterns, which directly surfaces T1018's active (ping/net view/esxcli) and passive (hosts/ARP) discovery methods on covered platforms; the remainder is discovery occurring entirely outside the monitored estate or before any baseline is established.
- T1020detects — A.8.16 explicitly monitors outbound network traffic, anomalous behaviour patterns, known malicious domains/IPs, resource use, and deviations such as unusual data movement that match automated exfiltration signatures or baselines, surfacing the technique in flight on the organization's estate.
- T1020prevents — A.8.16's real-time/periodic monitoring of network traffic, anomalous behaviour, known attack patterns, and outbound activity (with alerts and response procedures) can surface and thereby stop some automated exfiltration before or during transfer, but the clause only sets a scoped monitoring requirement rather than mandating universal blocking mechanisms, leaving many variants (especially non-anomalous or post-breach C2/alternative-protocol transfers) untouched.
- T1020responds — A.8.16 requires real-time/near-real-time monitoring, anomaly detection against baseline (including outbound traffic, unusual behaviour, and known attack patterns), alert generation, and dedicated personnel/procedures to respond to positive indicators (explicitly referencing 5.26 incident response), which acts on an automated exfiltration event once underway to contain/eradicate it; partial because scope is set by business requirements rather than mandating universal coverage of all exfil channels or platforms.
- T1020.001detects — A.8.16 explicitly includes monitoring of inbound/outbound network traffic, baselines for anomalies, and known attack patterns, which can surface traffic mirroring/duplication when it deviates from the baseline or matches signatures, but the clause sets scope by organizational requirements rather than mandating universal coverage of all mirroring configurations or cloud-native features.
- T1021detects — Detection of anomalous remote access patterns and unauthorized attempts to protected resources can reveal lateral movement via remote services.
- T1021prevents — A.8.16's real-time/periodic monitoring of network traffic, access attempts, anomalous behaviour (incl. unauthorized access and process injection), baselines, and alerts can surface or constrain some T1021 executions (e.g. unusual RDP/SSH from unexpected locations or admin anomalies), but does not stop the technique from running when valid credentials are used against allowed remote services.
- T1021responds — A.8.16 configures real-time/periodic monitoring plus alerts for anomalous behaviour (including unauthorized access attempts, unusual user/system behaviour, and process injection) and requires dedicated trained personnel plus procedures to respond to positive indicators in a timely manner per 5.26, which bounds an in-progress T1021 remote login once detected; partial because the clause sets scope by business requirements rather than mandating universal coverage of all remote-service vectors or platforms.
- T1021.001detects — A.8.16 explicitly lists monitoring of inbound network/system traffic, access to systems/servers/critical apps, event logs, admin configs, resource use, and anomalous behaviour including unauthorized access attempts, unusual user/system behaviour, and process injection — all of which surface RDP logons (especially anomalous ones) once they occur.
- T1021.001prevents — A.8.16's real-time monitoring of network traffic, access attempts, anomalous behaviour, and known attack patterns (including unauthorized access to systems) can surface RDP logins that deviate from baseline, but does not stop the technique from executing when valid credentials are presented.
- T1021.001responds — A.8.16 requires real-time/periodic monitoring of network traffic, access attempts, logs, anomalous behaviour (including unauthorized access and deviations), and alert generation with dedicated response personnel; this surfaces and enables timely response to an in-progress RDP session using valid credentials, but the clause sets scope by business needs rather than mandating universal RDP-specific detection, leaving a slice of stealthy or non-anomalous sessions unaddressed.
- T1021.002detects — A.8.16 explicitly monitors access to systems/servers/critical apps, event logs, admin-level config files, resource use, anomalous behaviour (including unauthorized access attempts and deviations from baseline), and known attack patterns, which directly surfaces SMB/Windows Admin Shares abuse by valid admin accounts.
- T1021.002prevents — A.8.16's real-time/periodic monitoring of network traffic, access attempts, anomalous behaviour (incl. unauthorized access and deviations from baseline) can surface SMB admin-share activity in flight and thereby prevent successful technique completion in monitored environments, but the clause sets scope by org requirements rather than mandating universal instrumentation, leaving substantial unmonitored slices (e.g. non-baselined or out-of-scope hosts).
- T1021.002responds — A.8.16's real-time/periodic monitoring, anomaly detection (including unauthorized access and unusual behaviour), alerting, and procedures to respond to positive indicators directly enable containment/eradication once SMB share abuse is underway, but the clause's scope is set by organisational requirements rather than mandating universal coverage of all SMB/RPC lateral movement.
- T1021.003detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, unusual system behaviour, network traffic, and admin-level activity, which can surface DCOM lateral movement when it deviates from baseline; however the clause sets scope by organisational requirements rather than mandating instrumentation that necessarily sees DCOM/RPC calls, leaving a slice determined by the implementer.
- T1021.003prevents — A.8.16's real-time/periodic monitoring of network traffic, access attempts, anomalous behaviour (including process injection and unauthorized access), and baselines can surface DCOM lateral movement but does not stop the technique from running when a valid privileged account is used.
- T1021.004detects — A.8.16 explicitly lists monitoring for access to systems/servers, event logs, anomalous user/system behaviour, unauthorized access attempts, and deviations such as process injection or unusual protocols, which surfaces many (but not all) SSH logins performed by valid accounts when they deviate from the established baseline of normal access patterns, times, or locations.
- T1021.005detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access attempts, unusual system behaviour, network traffic, and known attack patterns, which can surface VNC-based remote control when it deviates from baseline; however the clause sets scope by organisational requirements rather than mandating universal coverage of all VNC sessions or brute-force attempts on VNC ports.
- T1021.005responds — A.8.16 requires real-time/periodic monitoring of network traffic, access attempts, anomalous behaviour (including process injection and unauthorized access), baselines, and alerts with dedicated response personnel; this surfaces and enables containment of an in-progress VNC session once underway, though the initial connection and some actions may complete before response.
- T1021.006detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unusual system behaviour, unauthorized access attempts, and deviations in protocols, which can surface WinRM-based lateral movement when it deviates from the established baseline of normal access patterns, but the control's scope is set by organisational requirements rather than mandating coverage of all WinRM usage.
- T1021.006prevents — A.8.16 requires monitoring (incl. network traffic, access to systems/servers, admin configs, event logs, anomalous behaviour baselines, and explicit indicators such as unauthorized access attempts, process injection, and deviations in protocols) that can surface WinRM-based lateral movement from valid accounts in real time or near-real time, but the clause only sets scope and detection capability rather than a mechanism that stops the technique from executing.
- T1021.006responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (including process injection, unauthorized access, unusual behaviour), alert generation, and dedicated trained personnel with procedures to respond to positive indicators (explicitly referencing 5.26 incident response), which acts on an in-flight WinRM technique once underway; partial because scope is set by organisational requirements rather than mandating universal coverage of all WinRM usage.
- T1021.007detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access attempts, unusual user/system behaviour, access to critical systems, and real-time/periodic alerts tuned to a baseline, which surfaces T1021.007 logins via valid/federated accounts when they deviate from expected patterns; partial because scope is set by organisational requirements rather than mandating coverage of all cloud CLI, web console, or token-based access across every platform.
- T1021.007responds — A.8.16 configures monitoring (including access logs, anomalous behaviour, and real-time alerts) to surface the login and subsequent actions once underway, enabling timely response per linked procedures in 5.26; partial because the clause sets scope by organisational requirements rather than mandating universal coverage of all cloud federation paths or token-based logins.
- T1021.008detects — A.8.16 explicitly lists monitoring for access to systems/servers/critical apps, unauthorized access attempts, anomalous user/system behaviour (including process injection and deviations), and real-time/continuous anomaly detection against a baseline, which surfaces many T1021.008 indicators in IaaS environments; however the clause's scope is set by organizational requirements rather than mandating coverage of all cloud-native VM console methods, leaving a genuine slice unreached.
- T1025detects — A.8.16 explicitly lists monitoring of system/resource activity, access to systems/servers, event logs, baselines of normal behaviour, and anomalous indicators including unauthorized access and unusual system behaviour, which can surface T1025 activity on a monitored host; extent is partial because the clause sets scope by organisational requirements rather than mandating universal coverage of removable-media access events.
- T1027detects — A.8.16 explicitly lists monitoring for anomalous behaviour, malware-associated activity, known attack characteristics, unusual system behaviour (including process injection), and deviations in protocols or baselines, which can surface many T1027 indicators (e.g. encoded payloads, obfuscated commands, anomalous resource use); however the clause sets scope by organisational requirements rather than mandating universal coverage of all obfuscation forms or platforms, leaving a genuine slice unreached.
- T1027.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour, malware-associated activity, known attack characteristics, unusual system behaviour (including process injection), resource use anomalies, and signatures/behaviour patterns that can surface binary padding as an evasion or size-related anomaly, but the clause's scope is set by organisational requirements rather than mandating universal coverage of on-disk file alterations or large-file evasion.
- T1027.002detects — A.8.16 explicitly lists monitoring for process injection, anomalous behaviour, known attack characteristics, deviations in protocols, and code-tampering checks, which surface many (but not all) packing artifacts and in-memory unpacking; custom or novel packers explicitly designed to evade detection fall outside the baseline-driven, signature/pattern-based monitoring described.
- T1027.003detects — A.8.16 explicitly lists monitoring for anomalous behaviour, malware-associated activity, known attack characteristics, process injection, deviations in protocols, and resource/performance anomalies, which can surface some steganography uses (e.g. unusual exfil images, embedded command patterns, or resource spikes), but the technique's core goal is evasion of detection and most implementations remain outside the clause's configurable scope and signature/pattern recognition.
- T1027.003responds — A.8.16's real-time/periodic anomaly detection, baseline monitoring for malware-associated activity, process injection, unauthorized access, and alert-driven response procedures can surface and trigger timely handling of steganography once the hidden payload manifests in observable traffic, logs, or system behaviour, but the technique's stealth (hiding in innocuous media) leaves a large undetected slice before any response is possible.
- T1027.004detects — A.8.16 explicitly lists monitoring for process injection, unauthorized code execution, anomalous system behaviour, and integrity checks on running code against a baseline, which surfaces many post-compilation artifacts of T1027.004; it does not directly observe the compile step itself or all delivery vectors (e.g. encrypted source in phishing).
- T1027.005detects — A.8.16 explicitly lists monitoring for malware-associated activity, known attack characteristics, anomalous behaviour (including process injection), security tool logs (AV/IDS/IPS), and baseline deviations that surface signature-based detection or quarantine events; this catches many instances of indicator removal in flight or on reuse, but the clause's scope is set by organisational requirements rather than mandating universal coverage of all tools or post-remediation variants, leaving a genuine slice unreached.
- T1027.005responds — A.8.16's real-time/continuous monitoring, anomaly detection (incl. malware signatures, known attack patterns), alerting, and procedures to respond to positive indicators in a timely manner (cross-referenced to 5.26) enable containment/eradication once the technique is detected in flight; partial because the clause sets scope by org requirements rather than mandating universal depth, and the technique's post-quarantine modification can occur outside monitored execution or before detection thresholds are met.
- T1027.006detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection), unauthorized access/traffic, and real-time/periodic analysis of network/application/system activity with alerts; this surfaces many HTML smuggling indicators (e.g. anomalous JS blobs, unusual downloads, deobfuscation) once they reach monitored scope, but the clause sets scope by org requirements so coverage of inbound web content or client-side smuggling is an implementer-chosen slice rather than a bounded remainder.
- T1027.006prevents — A.8.16's real-time/periodic monitoring of network traffic, web filters, anomalous behaviour patterns, known attack characteristics and deviations (including in protocols and resource use) can surface HTML smuggling attempts or the subsequent deobfuscation/drop, but the control's scope is set by organisational requirements rather than mandating universal detection of all obfuscated MIME/Blob payloads, leaving a large slice of delivery vectors unaddressed.
- T1027.006responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unusual system behaviour, malware-associated activity, and deviations from baseline), which surfaces HTML smuggling once the deobfuscated payload executes or drops on the endpoint; this is containment/eradication response once underway, but the technique's pre-execution smuggling past content filters and its use of benign MIME types sit outside the named monitoring scope.
- T1027.007detects — A.8.16 explicitly lists process injection, anomalous system behaviour, malware-associated activity, and deviations in standard protocols as detectable via real-time/continuous monitoring against a behavioural baseline, which can surface dynamic API resolution at runtime; however the clause's scope is set by organisational requirements rather than mandating universal coverage of every obfuscated call, leaving a genuine slice of stealthy or non-anomalous resolutions unseen.
- T1027.008detects — A.8.16 requires monitoring for anomalous behaviour and known attack characteristics (including process injection and malware patterns), which can surface stripped payloads when they produce observable anomalies or match signatures, but the clause's scope is set by organisational requirements and does not mandate detection of stripped human-readable content itself
- T1027.009detects — A.8.16 explicitly lists monitoring for process injection, anomalous system behaviour, malware-associated activity, unauthorized code execution/tampering, and deviations from baseline (including resource use and known attack patterns), which surfaces many embedded-payload cases once they trigger observable anomalies or injection; it does not guarantee detection of every concealment method or dormant embedded payload before execution.
- T1027.010detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unusual system behaviour, known attack characteristics, and deviations in standard protocols, which can surface many forms of command obfuscation in real time or via logs; however the clause's scope is set by organisational requirements rather than mandating universal coverage of all obfuscation variants (e.g. novel syntax or encoding in unmonitored interpreters), making the coverage a chosen slice rather than a bounded remainder.
- T1027.010prevents — A.8.16's real-time/periodic monitoring of traffic, logs, baselines, known attack patterns, anomalous behaviour (incl. process injection) and signatures can surface many obfuscated commands as deviations, but the technique's explicit purpose is to impede exactly such signature- and pattern-based detection, leaving a large slice of novel or sufficiently mutated obfuscations undetected.
- T1027.011detects — A.8.16 explicitly lists monitoring of event logs, system/network activity, resource use, process anomalies, and deviations such as process injection or malware-associated behavior, which can surface many fileless storage artifacts (esp. Registry, WMI, event logs, shared-memory anomalies); however the clause's scope is set by organizational requirements rather than mandating coverage of all fileless formats or the obfuscated/encrypted payloads themselves, leaving a large implementer-chosen slice uncovered.
- T1027.011responds — A.8.16 requires real-time/periodic monitoring of logs (incl. event logs, system activity, anomalies like process injection or malware patterns), baselines, and alerts with dedicated response personnel and procedures that feed 5.26 incident response; this catches and acts on realized fileless storage artifacts (esp. in event logs, resource anomalies, or known patterns) once underway, but only for monitored scopes and does not guarantee containment of all stealthy/encrypted fileless cases.
- T1027.012detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unusual system behaviour, malware-associated activity, and deviations in protocols; LNK icon smuggling produces observable artifacts (e.g. anomalous external URL fetches on LNK invocation, unexpected downloads, or post-compromise script/LNK execution) that fall inside the baseline-and-anomaly model when the monitoring scope includes relevant host, network or application telemetry, but the clause sets scope by organisational requirements rather than mandating coverage of this specific vector, leaving a large slice of implementations that would miss it.
- T1027.013detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, malware-associated activity, process injection, deviations in protocols, and resource/performance anomalies, which can surface many T1027.013 artifacts at runtime or via logs; however the control's scope is set by organisational requirements rather than mandating coverage of static file signatures or all encoding layers, leaving a genuine slice of pre-execution obfuscated files on disk outside the monitored baseline.
- T1027.014detects — A.8.16 explicitly lists process injection, malware-associated activity, anomalous behaviour, and signature/behaviour pattern recognition in its monitoring scope, which surfaces many polymorphic executions once they deviate from baseline; however the clause's scope is set by organisational requirements rather than mandating universal coverage of all mutation variants, leaving a genuine slice (especially early or low-signal mutations) unreached.
- T1027.014prevents — A.8.16's baseline-driven anomaly detection (including process injection, unauthorized code execution, malware-associated behaviour and real-time alerts) can stop polymorphic execution from proceeding when it deviates from the established normal, but the technique's explicit purpose is evading exactly the signature-based and pattern-based tools the control relies on, leaving a large unaddressed slice.
- T1027.014responds — A.8.16's real-time/periodic anomaly detection, baseline comparison, and alert/response procedures (including to 5.26) surface and enable containment of polymorphic execution once underway (e.g. via process injection signatures, unauthorized code execution, or unusual behaviour), but the control's scope is set by organisational requirements rather than mandating universal coverage of all polymorphic mutations.
- T1027.015detects — A.8.16 explicitly lists monitoring for anomalous behaviour patterns, malware-associated activity, known attack characteristics, process injection, and deviations in protocols or system behaviour, which can surface many uses of compression when they produce observable anomalies or signatures, but the control's scope is set by organisational requirements rather than mandating coverage of all compression (e.g. benign-looking archives, self-extracting payloads, or fileless registry storage may remain undetected).
- T1027.016detects — A.8.16 explicitly lists process injection, anomalous code execution, malware-associated behaviour and deviations from baseline as detectable anomalies, which can surface junk-code patterns at runtime; it does not guarantee detection of the static obfuscation itself before execution or in all code-analysis contexts.
- T1027.017detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection), network/application traffic, security tool logs, and real-time/periodic anomaly detection against baselines, which can surface SVG smuggling when it triggers observable patterns such as malicious script execution or anomalous downloads/redirects; however the clause sets scope by organisational requirements rather than mandating detection of every smuggling vector or file-format parser differential, leaving a large slice of stealthy or non-anomalous cases undetected.
- T1027.017responds — A.8.16's real-time/periodic monitoring, anomaly detection (including process injection, unauthorized access, malware-associated activity), alerting, and procedures to respond to positive indicators directly enable containment/eradication once SVG smuggling has begun and is observed as anomalous behavior, but scope is set by organizational requirements so coverage of this specific technique is not guaranteed.
- T1027.018detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection), and deviations in standard protocols, which can surface some Unicode-based concealment when it produces observable runtime or network anomalies; however the clause's scope is set by organisational requirements rather than mandating detection of invisible characters in files/scripts, so most static or pre-execution uses remain outside the covered slice.
- T1029detects — A.8.16 requires monitoring of network traffic, baselines of normal behaviour (including usual times/locations/frequency of access), anomalous patterns and real-time/periodic alerts; this surfaces scheduled exfiltration when it deviates from the baseline or matches known malicious patterns, but the clause sets scope by organisational requirements rather than mandating universal coverage of all scheduled transfers, leaving a slice determined by the implementer.
- T1029responds — A.8.16 requires real-time/periodic monitoring for anomalies (including unusual traffic/behaviour patterns and outbound network activity), dedicated personnel to respond to alerts, and explicit procedures to respond to positive indicators in a timely manner per 5.26; this directly matches the `responds` verb once the scheduled exfiltration (or its parent exfil technique) is underway and triggers an anomaly, but is only a slice because the control's scope, baseline, and alerting thresholds are set by the organization and may miss stealthy or low-volume scheduled transfers that blend with normal activity.
- T1030detects — A.8.16 explicitly lists monitoring of network traffic, baselines for normal behaviour, anomalous patterns, and real-time/periodic tools that can surface deviations including unusual transfer characteristics, but the control's scope is set by organisational requirements rather than mandating detection of every stealthy chunked exfil below thresholds, leaving a large slice of T1030 implementations unseen.
- T1030responds — A.8.16 requires real-time/periodic monitoring of network traffic, anomalous behaviour (incl. unusual patterns), alerts on thresholds, and timely response procedures once an indicator is surfaced; this can respond to chunked exfiltration that still deviates from baseline or triggers other observables, but the technique is explicitly designed to stay under common size thresholds so the detection/response surface is limited.
- T1033detects — A.8.16 requires monitoring of access, logs, anomalous behaviour, and unusual user/system activity (including deviations from baseline), which can surface T1033 execution via commands like whoami or anomalous session queries; however the clause explicitly sets scope by organisational requirements rather than mandating universal coverage of all discovery commands or process-enumeration artefacts, leaving a large slice of T1033 realisations outside any given conforming implementation.
- T1036detects — A.8.16 explicitly lists process injection, anomalous behaviour, baseline deviations, unauthorized code execution and monitoring of system/network/application activity (including logs from security tools), which surfaces many T1036 indicators post-execution; however the control's scope is set by organisational requirements rather than mandating coverage of all masquerading vectors (e.g. file metadata manipulation or container image masquerading may fall outside chosen scope), making the coverage a chosen slice rather than a bounded remainder.
- T1036responds — A.8.16's real-time/continuous monitoring, anomaly detection (incl. process injection, unauthorized access, malware-like activity), alerting, and procedures to respond to positive indicators directly address an in-flight masquerading technique once underway, containing or eradicating it; partial because scope is set by org requirements rather than mandating universal coverage of all masquerading vectors (e.g. metadata tricks or file-type deception may fall outside chosen baselines/tools).
- T1036.001detects — A.8.16 explicitly lists monitoring for code tampering (f), process injection and anomalous behaviour (d,e,i), security-tool logs, baselines of normal execution, and real-time signature/pattern recognition, which surfaces invalid-code-signature files that deviate from expected signed binaries on Windows/macOS.
- T1036.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection), file/registry activity via logs and baselines, and real-time alerts, which can surface RTLO-disguised filenames or execution anomalies in some cases, but the control's scope is set by organisational requirements and does not mandate coverage of all display-layer or non-executing filename tricks across every tool or platform.
- T1036.003detects — A.8.16 explicitly lists monitoring for process injection, anomalous behaviour, known attack characteristics, unusual system behaviour, and deviations from baseline (including resource use and executed code integrity), which surfaces many renamed-utility executions; it does not guarantee coverage of every rename variant, path-based evasion, or non-monitored process.
- T1036.004detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized access attempts, and deviations from baseline (including unusual resource use or process termination) as detectable anomalies, which can surface masquerading tasks/services when they deviate from established norms; however the control's scope is set by organisational requirements rather than mandating coverage of every task/service name or description field, leaving a large slice of stealthy identical-name cases undetected.
- T1036.004responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (including process injection, unauthorized access, unusual system behaviour) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26; this bounds impact once a masquerading task/service is detected as anomalous, but the clause's scope is set by organisational requirements rather than mandating detection of all name/description masquerading, leaving a large slice unreached.
- T1036.005detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized access attempts, and baseline deviations (including resource use and executed code integrity) among the anomalies it surfaces in real time; these catch many T1036.005 artifacts once running, but the clause's scope is set by organisational requirements rather than mandating universal coverage of every masquerading placement, leaving a genuine slice unreached.
- T1036.006detects — A.8.16 explicitly lists monitoring for process injection, anomalous file execution, unusual system behaviour, and deviations from baseline (including resource use and authorised code execution), which surfaces the double-click execution of a disguised binary as an anomaly; it does not guarantee coverage of every filename-space variant or non-monitored endpoint.
- T1036.007detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, malware-associated activity, unauthorized access/execution, and deviations from baseline (with real-time tools, alerts, and trained response), which surfaces many double-extension tricks once the disguised file reaches the monitored system or triggers execution anomalies; it does not cover the pre-execution filename masquerading itself when the file is at rest or in transit outside those scopes.
- T1036.008detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, known attack characteristics, unusual system behaviour, and deviations in standard protocols or file handling that can surface masqueraded files when they deviate from the established baseline of signatures, extensions, or execution patterns, but the clause sets scope by business requirements rather than mandating universal file-type or magic-byte validation so what is caught is an implementer-chosen slice
- T1036.008prevents — A.8.16's real-time/periodic monitoring of traffic, file access, logs, signatures, anomalous behaviour (incl. process injection, unauthorized access, malware patterns) and baseline deviations can surface masqueraded files during transfer/storage/execution, thereby preventing the technique from succeeding in many cases, but the clause sets scope by org requirements rather than mandating universal detection of all header/extension/icon/content changes.
- T1036.009detects — A.8.16 explicitly lists process injection and unusual system behaviour as items to baseline and alert on, which can surface many PPID-breaking techniques in real time; however the clause's scope is set by organisational requirements rather than mandating host-level process-tree instrumentation, so some stealthy double-fork or daemon detachments on Linux/macOS can remain outside the chosen monitoring slice.
- T1036.009prevents — A.8.16 requires monitoring for anomalous behaviour including process injection, unusual system behaviour, and deviations from baseline (explicitly naming process injection in its examples), which can surface double-fork/daemonization attempts that break process trees; however the clause sets scope by organisational requirements rather than mandating universal instrumentation of every process tree, so only a chosen slice is covered.
- T1036.009responds — A.8.16's real-time/continuous monitoring and alerting on anomalous behaviour (including process injection, unusual system behaviour, and deviations from baseline) surfaces the PPID-break technique once it runs, enabling timely response per linked 5.26 procedures; partial because scope is set by organisational requirements rather than mandating universal process-tree instrumentation.
- T1036.010detects — A.8.16 requires monitoring for anomalous behaviour including unusual user/system activity, unauthorized access attempts, and deviations from baseline (e.g. access patterns, account-related events in logs), which can surface masquerade accounts as anomalies; however the clause sets scope by business requirements rather than mandating universal account-name scrutiny, leaving many implementations without coverage for this specific post-creation naming technique.
- T1036.011detects — A.8.16 explicitly lists process injection and anomalous system behaviour (including deviations from baseline) among the monitored items, and the technique produces observable anomalies in /proc/<PID>/cmdline, ps output, and process memory that fall inside the clause's scope when host telemetry is collected; however the clause sets monitoring scope by organisational requirements rather than mandating universal deep host/process inspection, so some conformant implementations see none of it.
- T1036.012detects — A.8.16 explicitly lists monitoring of network traffic, anomalous behaviour patterns, known attack characteristics, unusual system behaviour (including process injection), and deviations in standard protocols, which can surface browser fingerprinting/spoofing when it produces detectable anomalies against the established baseline; however the clause's scope is set by organisational requirements rather than mandating universal coverage of all fingerprinting variants, leaving a large slice of stealthy or low-signal cases unreached.
- T1037detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized access attempts, unusual boot/logon patterns, resource anomalies, and real-time/periodic monitoring of system activity, logs, and baselines as detection targets, which surface many (but not all) T1037 executions; the remainder is implementation-scope choices that can omit certain platforms or script types.
- T1037.001detects — A.8.16 explicitly lists process injection, anomalous user/system behaviour, access attempts, and baseline deviation monitoring (including event logs, resource use, and real-time alerts), which can surface logon script execution at logon; however the clause sets scope by organisational requirements rather than mandating universal coverage of registry or logon-initialization artefacts, leaving a slice determined by the implementer.
- T1037.001responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (including process injection, unauthorized access, unusual logon patterns) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26, which directly matches the `responds` verb once the logon-script persistence technique is underway; partial because the clause sets scope by business requirements rather than mandating universal coverage of every possible logon-script artifact.
- T1037.002detects — A.8.16 explicitly lists process injection, anomalous user/system behaviour, admin-level config file access, and baseline-deviation monitoring (including login-time activity), which can surface a Login Hook plist modification or its root-privileged script execution; scope is implementer-defined so only a slice of possible realisations is guaranteed to be caught.
- T1037.002prevents — A.8.16's baseline monitoring of system config files, admin activity, resource use, anomalous behaviour (incl. process injection and deviations), and real-time/periodic checks can surface or constrain a Login Hook modification on macOS, but the clause sets scope by org requirements rather than mandating universal prevention of the plist edit or hook execution.
- T1037.003detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access attempts, unusual system behaviour, and deviations in protocols, which surfaces network logon script execution as an anomaly once it runs; scope is set by organisational requirements rather than mandating coverage of all logon-script artefacts, leaving a genuine slice unreached.
- T1037.004detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, unusual system behaviour, admin-level config file changes, and resource/performance deviations, which can surface RC script tampering or its post-reboot effects in scope; however the clause sets scope by organisational requirements rather than mandating universal coverage of all RC files or boot artefacts, leaving a slice determined by the implementer.
- T1037.005detects — A.8.16 explicitly lists monitoring for process injection, anomalous boot-time behaviour, unauthorized access to system files/directories, and deviations from baseline (including unusual startup activity), which surfaces T1037.005 when it runs; scope is set by the implementer so only a chosen slice is guaranteed.
- T1037.005responds — A.8.16 configures monitoring (incl. anomalous boot-time behaviour, process execution, unauthorized access, and malware-like activity) to generate alerts on realized T1037.005 persistence, with dedicated response personnel and procedures that contain/eradicate once underway; partial because the clause sets scope by org requirements rather than mandating universal coverage of this deprecated macOS mechanism.
- T1039detects — A.8.16 explicitly lists monitoring of network traffic, access to systems/servers/shares, file system access attempts, anomalous user/system behaviour, and real-time/continuous tools that surface deviations from baseline, which would flag T1039 activity on monitored shares; partial because scope is set by the organization’s chosen requirements rather than mandating universal coverage of all network shares or all platforms.
- T1040detects — A.8.16 explicitly requires monitoring of inbound/outbound network traffic, access logs, security tool outputs (IDS/IPS/firewalls), anomalous behaviour patterns (including known attack characteristics and deviations), and real-time/continuous tools that surface indicators, which directly detects network sniffing in flight on monitored segments; the named remainder is sniffing on unmonitored interfaces, cloud mirroring outside scope, or passive captures that produce no observable anomaly.
- T1040responds — A.8.16 requires real-time/periodic monitoring of network traffic, anomalous behaviour (incl. unauthorized access/scanning and known attack patterns), dedicated alert response personnel, and timely procedures that align with 5.26 incident response, which can contain/eradicate an in-flight sniffing event once detected; partial because the clause sets scope by org requirements (not mandating universal coverage of all sniffing vectors like cloud mirroring or device CLI captures) and its core is detection/alerting rather than guaranteed containment/eradication.
- T1041detects — A.8.16 explicitly requires monitoring of outbound network traffic, anomalous behaviour patterns, known malicious domains/IPs, and deviations from baseline (including unusual system/network behaviour), which surfaces exfiltration hidden in legitimate C2 channels; the remainder is traffic that perfectly mimics the baseline without triggering any signature or anomaly threshold.
- T1041prevents — A.8.16 requires monitoring of network traffic, anomalous behaviour, known malicious patterns/IPs, and deviations from baseline (including unusual outbound activity), which can block some exfiltration-over-C2 realisations before completion; it does not stop the adversary from establishing the C2 channel or encoding data into it.
- T1041responds — A.8.16 requires real-time/continuous monitoring of network traffic, anomalous behaviour (incl. known attack patterns and deviations from baseline), plus dedicated trained personnel and procedures to respond to alerts (explicitly referencing 5.26 incident response), which directly acts on an exfiltration event once underway to contain/eradicate it.
- T1046detects — Detection of unauthorized scanning of business applications, systems and networks limits the adversary's ability to discover network services without triggering alerts.
- T1046prevents — A.8.16 mandates monitoring (incl. network traffic, anomalous scanning, unauthorized access attempts, and known attack patterns) that can block or alert on many forms of port/vuln scanning in real time, but the control is scoped by org requirements rather than mandating universal coverage, and passive/baseline-based detection does not stop all discovery techniques (e.g. mDNS/Bonjour or offline wordlist scans).
- T1046responds — A.8.16's real-time/periodic monitoring, anomaly detection (including unauthorized scanning and known attack patterns), alerting, and procedures to respond to positive indicators directly engage T1046 once the scan is underway on the monitored estate, enabling timely containment; partial because scope is set by business requirements (not all scanning surfaces as observable anomalies, especially in unmonitored cloud/on-prem segments or non-baseline Bonjour/mDNS activity).
- T1047detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unusual system behaviour, resource use, admin-level activity, event logs, security-tool logs and known attack characteristics; WMI abuse (local or remote) produces observable artifacts across those exact vectors on Windows, so the control surfaces the technique in flight.
- T1047responds — A.8.16 surfaces anomalous WMI usage (e.g. via process injection signatures, unusual system behaviour, admin-level access, or resource anomalies) once underway and feeds it to 5.26 response procedures, but the control itself performs none of the core respond actions (contain/eradicate) and many T1047 executions (especially remote or non-signatured) fall outside its scoped monitoring.
- T1048detects — A.8.16 explicitly requires monitoring of network traffic (inbound/outbound), anomalous behaviour patterns, known attack characteristics, unusual system behaviour, and resource/performance deviations; these directly surface T1048 exfiltration over alternate protocols (e.g. FTP/SMTP/DNS/SMB spikes, curl usage, or non-C2 channel anomalies) once the baseline is established and tools are tuned, with the bounded remainder being fully obfuscated/encrypted cases or activity outside the chosen monitoring scope.
- T1048prevents — A.8.16 mandates monitoring of network traffic, anomalous behaviour patterns, known attack characteristics and outbound activity against a baseline, which can block some exfiltration attempts in real time via alerts and response; however the clause only sets scope and does not mandate preventive blocking mechanisms, leaving many alternate-protocol or obfuscated exfiltrations (especially cloud-console or non-monitored vectors) untouched.
- T1048responds — A.8.16's real-time/periodic monitoring of network traffic, anomalous behaviour, known attack patterns and alerts (with dedicated response personnel and procedures feeding 5.26) surfaces and enables response to exfiltration events once underway, but only for the subset observable in monitored traffic or baselines (e.g. unusual protocols or volumes) while many alternate-channel, encrypted, or console/API exfils fall outside its scope.
- T1048.001detects — A.8.16 explicitly requires monitoring of network traffic, anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection and protocol deviations), and baseline deviations, which directly surfaces exfiltration over non-C2 symmetric-encrypted channels when it deviates from the established baseline.
- T1048.001responds — A.8.16 surfaces anomalous exfiltration (e.g. unusual traffic patterns, unexpected protocols, or deviations from baseline) in real time or near-real time and feeds it to the 5.26 response procedure for containment/eradication; the technique has already run and produced outbound data, so this is genuine response once underway, but only a slice (network-layer observables inside the chosen monitoring scope) while many symmetric non-C2 exfil shapes (e.g. covert channels inside permitted HTTPS) remain unseen.
- T1048.002detects — A.8.16 explicitly lists monitoring of outbound/inbound network traffic, anomalous behaviour patterns, known malicious IPs/domains, and deviations such as unusual system behaviour, which can surface exfiltration over asymmetric encrypted non-C2 protocols (e.g. HTTPS to alternate locations) when inside the organisation-defined scope; however the clause sets that scope by business requirements rather than mandating universal coverage of all such traffic, leaving a genuine slice unseen.
- T1048.002responds — A.8.16 configures monitoring (including network traffic, anomalous behaviour, known attack patterns, and real-time alerts) to surface and enable timely response to exfiltration events once underway, with personnel and procedures to contain impact per 5.26; mostly because scope is set by organisational requirements rather than mandating universal coverage of all asymmetric exfil channels.
- T1048.003detects — A.8.16 explicitly requires monitoring of outbound/inbound network traffic, anomalous behaviour patterns, known attack characteristics, and deviations from baseline (including unusual system/network behaviour), which surfaces most instances of unencrypted non-C2 exfiltration over HTTP/FTP/DNS while the technique is in flight; the bounded remainder is fully obfuscated or low-volume cases that stay inside the chosen monitoring scope.
- T1048.003prevents — A.8.16 requires monitoring of outbound network traffic, anomalous behaviour, known attack patterns and deviations from baseline (including unusual protocols or data exfiltration indicators), which can block some instances of unencrypted non-C2 exfiltration before completion; it does not stop the technique from being attempted or succeeding in all cases.
- T1048.003responds — A.8.16's real-time/periodic monitoring, anomaly detection (including unusual outbound traffic, known attack patterns, and deviations from baseline), alerting, and procedures to respond to positive indicators directly engage an exfiltration event once underway for containment and eradication, but only for the observable slice (network traffic, logs, resource use) while leaving non-monitored protocols, obfuscated embedding, or non-network exfil untouched.
- T1049detects — A.8.16 requires monitoring of network traffic, system activity, resource use, and anomalies (including process injection or deviations in protocols), which can surface T1049's discovery commands (netstat, lsof, who, etc.) when they produce observable network or behavioral deviations from baseline, but the clause sets scope by organizational requirements rather than mandating universal coverage of all such queries across every platform or execution context.
- T1052detects — A.8.16 explicitly lists monitoring of removable-media access, USB/storage device activity, anomalous resource use, and deviations such as unauthorized data movement that would surface physical exfiltration attempts, but the clause's scope is set by organizational requirements and therefore leaves out air-gapped or unmonitored systems where this technique is most relevant.
- T1052.001detects — A.8.16 explicitly lists monitoring of USB-related vectors (outbound traffic, device access, resource use, anomalous behaviour such as unauthorized access or unusual system activity) and requires real-time/periodic tools with alerts, which surfaces T1052.001 when it occurs within the chosen monitoring scope; partial because the clause lets the organization set that scope by business needs, so USB monitoring is not mandated everywhere and air-gapped or out-of-scope devices remain unseen.
- T1052.001responds — A.8.16 requires real-time/periodic monitoring of network/system/application traffic, access, logs, resource use, and anomalies (including malware-like activity and unauthorized access), plus dedicated response to alerts; this surfaces and enables response to USB exfiltration once underway in monitored environments, but the air-gapped/hop scenario and physical USB focus leave a large unmonitored slice.
- T1053detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unusual resource use, unplanned terminations, and deviations from baseline (including scheduled activity patterns) as detectable; these surface many but not all T1053 instances (e.g. stealthy remote scheduling under admin context or one-time trusted-process masking can evade the listed signatures and baselines).
- T1053responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (incl. process injection, unusual system behaviour, unauthorized access, malware patterns) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26, which directly matches the `responds` verb once the scheduled-task technique is underway; partial because the clause sets scope by business requirements rather than mandating universal detection of every T1053 variant (e.g. container or network-device scheduling outside monitored baselines).
- T1053.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour (including process injection, unusual system behaviour, unauthorized access, and deviations from baseline), which surfaces many but not all T1053.002 executions (e.g. those using at for persistence or lateral movement that stay within normal-looking scheduled activity).
- T1053.002responds — A.8.16's real-time/periodic anomaly detection, baseline comparison, and explicit callouts (process injection, unauthorized access, malware-like activity, unplanned terminations) surface an in-flight at-scheduled malicious task or its effects, triggering alerts for the incident response process (5.26); partial because the clause sets scope by business requirements rather than mandating universal coverage of every at invocation across all platforms and privilege boundaries.
- T1053.003detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, unusual system behaviour, admin-level config file changes, and deviations from baseline (e.g. unusual scheduled activity), which surfaces many but not all T1053.003 uses; scope is set by the organization so coverage of cron abuse is an implementer-chosen slice rather than a bounded remainder.
- T1053.005detects — A.8.16 explicitly lists monitoring of system/network activity, event logs, admin configuration files, resource use, process anomalies, and known attack patterns including process injection and deviations; scheduled task creation/abuse produces observable artifacts (new tasks, registry changes, schtasks.exe execution, anomalous scheduled activity) that fall inside the defined baseline-monitoring and alerting scope on Windows.
- T1053.005responds — A.8.16's real-time/periodic anomaly detection, baseline monitoring for unusual behaviour (incl. process injection, unauthorized access, hidden artifacts), alerting and dedicated response procedures directly enable containment/eradication once a scheduled-task technique is underway, but only for the observable subset (e.g. visible tasks, logs, resource anomalies) while hidden tasks and non-anomalous creations remain outside scope.
- T1053.006detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection), resource/performance deviations, and real-time/periodic analysis of system, network and application activity; systemd timer creation, activation via systemctl, or anomalous scheduled execution can surface as anomalies or events in logs/configs, but the clause sets scope by organisational requirements rather than mandating universal coverage of all timer activity, leaving a slice determined by the implementer
- T1053.007detects — A.8.16 requires monitoring of system/network/application activity, baselines, anomalies (incl. process injection, unauthorized access, unusual behaviour), and security-tool logs, which can surface container-orchestration job scheduling in scope; the clause sets the monitoring scope by org requirements rather than mandating universal depth, so only a chosen slice of T1053.007 (e.g. Kubernetes CronJob creation) is caught.
- T1053.007responds — A.8.16 configures monitoring (including process injection, anomalous behaviour, resource use, and alerts) to surface an in-flight T1053.007 job once scheduled and executing, enabling the dedicated response personnel and procedures (cross-referenced to 5.26) to contain/eradicate it; partial because the clause sets scope by business needs rather than mandating universal coverage of all container-orchestration artefacts.
- T1055detects — Monitoring for process injection and other unusual system behaviour provides visibility into stealthy code execution techniques.
- T1055prevents — A.8.16 explicitly lists process injection as an anomalous behaviour to baseline and alert on (and requires monitoring of code execution integrity), which can stop some injections from completing or succeeding when the monitoring system is in scope, but the clause only sets requirements for scope and does not mandate the instrumentation depth that would catch all platform-specific or in-process variants.
- T1055responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (including explicit examples of process injection and related indicators), dedicated trained personnel, alert generation, and timely procedures to respond to positive indicators per 5.26, which directly enacts the containment/eradication act that `responds` names once the technique is underway.
- T1055.001detects — A.8.16 explicitly lists process injection and anomalous behaviours (unauthorised code execution, unusual system behaviour, resource deviations) among the monitored indicators, with real-time/periodic tools and baselines that can surface it; however the clause sets scope by organisational requirements rather than mandating universal host-level instrumentation, so some implementations remain conformant yet blind to in-process injection.
- T1055.001prevents — A.8.16 requires monitoring (incl. process injection as an explicit anomaly, code execution authorization checks, baselines of normal behaviour, and real-time/periodic detection) that can stop some but not all instances of the technique from completing or succeeding; scope is set by the implementer rather than mandating universal coverage, leaving a slice prevented and the bulk dependent on what the organization actually instruments.
- T1055.001responds — A.8.16 configures real-time/periodic monitoring and alerting on process-injection signatures, anomalous behaviours (explicitly naming process injection), and deviations from baseline, enabling dedicated personnel to respond via defined procedures (cross-referenced to 5.26) once the technique is underway.
- T1055.002detects — A.8.16 explicitly lists process injection and anomalous behaviours (e.g. unusual system behaviour, process injection, deviations in protocols, resource use) among the items to baseline and monitor for in real time, but the clause sets scope by organisational requirements rather than mandating universal host-level instrumentation, so only the slice inside the chosen scope is detected.
- T1055.002prevents — A.8.16 explicitly lists process injection and anomalous behaviour (including deviations in protocols, resource use, unauthorized code execution) as items to baseline and monitor for in real time; this constrains the technique's successful execution in monitored environments but does not stop the injection itself from occurring, matching the partial precedent of A.8.16 vs T1055 in the event-lane anchors.
- T1055.002responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour including process injection, with dedicated trained personnel and procedures to respond to positive indicators (see 5.26) once the technique is underway, containing and eradicating it; mostly because scope is set by organisational requirements rather than mandating universal coverage of all injection variants.
- T1055.003detects — A.8.16 explicitly lists process injection and anomalous system behaviour (plus real-time/baseline monitoring of system activity, resource use, and security-tool logs) as things its monitoring system should surface, but the clause sets scope by organisational requirements rather than mandating universal host-level instrumentation, so only a chosen slice of T1055.003 executions is guaranteed to be detected.
- T1055.003prevents — A.8.16 requires monitoring (incl. process injection, anomalous behaviour, code tampering, resource use, and real-time alerts against a baseline) that can stop some instances of T1055.003 from completing or succeeding, but the clause sets scope by organisational requirements rather than mandating universal coverage of all in-process hijacking vectors.
- T1055.003responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour including process injection, unplanned terminations, unusual system behaviour and deviations from baseline; this surfaces the T1055.003 event once underway so dedicated personnel can respond per linked 5.26 procedures, exactly the act `responds` names.
- T1055.004detects — A.8.16 explicitly lists process injection and anomalous behaviour (including deviations in protocols, unplanned terminations, malware-associated activity) among the items to baseline and monitor in real time, which surfaces T1055.004 when its observable effects fall inside the organisation-defined scope; that scope is not mandated to include all in-process execution, so the coverage is a chosen slice rather than a bounded remainder.
- T1055.004prevents — A.8.16 requires monitoring (incl. process injection, anomalous behaviour, code execution, baselines) that can surface APC injection in flight but does not stop the technique from running or succeeding; the clause sets scope by org requirements rather than mandating universal prevention.
- T1055.004responds — A.8.16 configures real-time/periodic monitoring (incl. process injection as an explicit anomaly, system behaviour deviations, security-tool logs, resource use, and alerts) that surfaces the technique once underway so dedicated personnel can respond per linked 5.26 procedures; the named remainder is injection into unmonitored processes outside the scoped baseline.
- T1055.005detects — A.8.16 explicitly lists process injection and anomalous behaviour (including deviations in protocols and resource use) among the monitored items and baseline anomalies, with real-time tools and alerts that can surface TLS callback injection when it falls inside the organisation-chosen scope; that scope is not mandated to include all in-process memory manipulation, so the coverage remains a chosen slice rather than a bounded remainder.
- T1055.005prevents — A.8.16 requires monitoring for anomalous behaviour including process injection and deviations, which can surface TLS callback injection attempts in real time or periodically when they match the baseline or signatures, thereby preventing some (but not all) successful executions depending on scope, tooling and detection lag.
- T1055.005responds — A.8.16's real-time/periodic monitoring of system behaviour, process activity, resource use, known attack patterns and explicit anomalies such as process injection surfaces the technique once it is underway; dedicated trained personnel and procedures then respond per 5.26, containing/eradicated the actor's foothold while the remainder (impact already realised before detection) is left for recovery controls.
- T1055.008detects — A.8.16 explicitly lists process injection and anomalous system behaviour as items to baseline and monitor for in real time, which surfaces T1055.008 when its observable signatures fall inside the chosen scope; the clause sets that scope by organisational requirements rather than mandating universal host-level instrumentation, so only a chosen slice is guaranteed to be detected.
- T1055.008prevents — A.8.16 requires monitoring (incl. process injection, anomalous behaviour, code tampering, resource use, and real-time baselines/alerts) that can block some ptrace-based injections before completion, but the clause sets scope by organisational requirements rather than mandating universal instrumentation, leaving many legitimate debugging or unmonitored processes as an implementer-chosen slice
- T1055.008responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour including process injection (explicitly listed), with dedicated trained personnel and procedures to respond to positive indicators per 5.26, containing/eradicate the in-flight T1055.008 once underway; mostly because scope is set by organisational requirements rather than mandating universal host-level visibility of all ptrace calls.
- T1055.009detects — A.8.16 explicitly lists process injection and anomalous system behaviour as items to baseline and monitor for in real time, but the clause sets scope by organisational requirements rather than mandating host-level instrumentation that would necessarily observe /proc filesystem enumeration or memory-map overwrites on Linux.
- T1055.009prevents — A.8.16 requires monitoring of system/network activity, process anomalies, resource use, and explicit examples including process injection; this can block the technique when the baseline flags the /proc enumeration or memory overwrite in real time, but the clause sets scope by business requirements rather than mandating universal process-level instrumentation, leaving Linux proc-memory cases outside chosen scopes unaddressed.
- T1055.009responds — A.8.16 surfaces anomalous behaviour including process injection (explicitly listed) via real-time/periodic monitoring of system activity, memory use, and logs, feeding into 5.26 response procedures for containment/eradication once underway; partial because scope is set by organisational requirements rather than mandating universal host-level visibility of /proc-based injection on all Linux systems.
- T1055.011detects — A.8.16 requires monitoring for anomalous behaviour (including explicit mention of process injection) and can surface EWM injection when host telemetry is in scope, but the clause sets the monitoring scope by business requirements rather than mandating instrumentation that necessarily sees in-process EWM manipulation.
- T1055.011prevents — A.8.16 requires monitoring for anomalous behaviour including process injection and deviations in standard protocols, which can surface EWM injection in flight; however the clause sets scope by organisational requirements rather than mandating universal instrumentation, so only the slice inside the chosen monitoring baseline is prevented from succeeding undetected.
- T1055.011responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour including process injection, unplanned terminations, unusual system behaviour, and deviations from baseline; this surfaces the T1055.011 event once underway so dedicated personnel can respond per linked 5.26 procedures, exactly as the verb requires.
- T1055.012detects — A.8.16 explicitly lists process injection and anomalous system behaviour (including deviations in standard protocols) among the monitored indicators, and requires real-time/continuous monitoring tools that can surface such anomalies against a baseline; however the clause sets scope by organisational requirements rather than mandating universal host-level instrumentation, so some implementations remain conformant yet blind to in-process hollowing.
- T1055.012prevents — A.8.16 requires monitoring for anomalous behaviour including process injection and deviations in standard protocols, which surfaces hollowing when it deviates from the established baseline of normal process creation/execution; however the control sets its own scope by business requirements rather than mandating universal coverage of every possible hollowing variant or platform, leaving a slice uncovered.
- T1055.012responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour including process injection, unplanned terminations, unusual system behaviour, and deviations from baseline; this surfaces the hollowing technique once underway so dedicated personnel can respond per linked 5.26 procedures, with the named remainder being injection variants that fall outside the chosen monitoring scope.
- T1055.013detects — A.8.16 explicitly lists process injection and anomalous behaviour baselines as monitoring targets, and the technique is a form of process injection that produces observable anomalies in process/memory behaviour, but the clause sets scope by organisational requirements rather than mandating universal deep host instrumentation, so only a chosen slice is guaranteed to be detected.
- T1055.013prevents — A.8.16 mandates monitoring for anomalous behaviour including process injection and deviations in standard protocols, which can surface process doppelgänging when it deviates from the established baseline of normal process and resource behaviour; however the control only sets a scope-determined requirement rather than mandating universal instrumentation that would stop the technique from running.
- T1055.013responds — A.8.16's real-time/periodic monitoring of system behaviour, process anomalies, resource use, and known attack patterns (including explicit mention of process injection) surfaces the technique once underway, enabling timely response per linked 5.26 procedures; mostly because scope is set by organisational requirements rather than mandating universal coverage of every doppelgänging variant.
- T1055.014detects — A.8.16 explicitly lists process injection and anomalous system behaviour (including deviations in standard protocols or resource use) among the monitored anomalies, and requires real-time/continuous tooling that can surface such deviations from a baseline; however the clause's scope is set by organisational requirements rather than mandating host-level instrumentation that would reliably catch VDSO-specific syscall stub hijacking or GOT patching, leaving a large slice of Linux implementations conformant yet blind to it.
- T1055.014prevents — A.8.16 requires monitoring for anomalous behaviour including process injection and deviations in standard protocols, which can surface VDSO hijacking in real time when it matches the baseline or known attack patterns, but the control only sets scope and does not mandate instrumentation that would stop the technique from executing.
- T1055.014responds — A.8.16 requires real-time/periodic monitoring of system behaviour, process anomalies, resource use, and explicit indicators such as process injection, with dedicated personnel and procedures to respond to alerts (cross-referenced to 5.26 incident response), but its scope is set by organisational requirements rather than mandating universal coverage of VDSO hijacking mechanics on all Linux processes.
- T1055.015detects — A.8.16 explicitly lists process injection and anomalous system behaviour (including deviations in protocols and resource use) among the monitored anomalies, and requires real-time/continuous tooling that can surface such activity; however the control's scope is set by organisational requirements rather than mandating universal host-level instrumentation, so ListPlanting variants that avoid monitored APIs or run in unmonitored processes remain unseen.
- T1055.015prevents — A.8.16 requires monitoring of system behaviour, process activity, resource use, and anomalies (including explicit mention of process injection), which can surface ListPlanting before or during execution and thereby constrain some attack paths; however the clause sets scope by organisational requirements rather than mandating universal instrumentation of every list-view control, window message, or in-process callback, so only a slice is reached.
- T1055.015responds — A.8.16 configures real-time/periodic monitoring of system behaviour, process activity, resource use, known attack patterns (explicitly naming process injection), and anomalies, then generates tuned alerts for dedicated trained personnel to respond to under 5.26 procedures; this directly enacts the containment/eradication act that `responds` names once the ListPlanting technique is underway, with the named remainder being injection variants falling outside the chosen monitoring scope.
- T1056detects — A.8.16 explicitly lists monitoring for process injection, anomalous user/system behaviour, unauthorized access attempts, and baseline deviations that can surface many input-capture realisations (especially transparent hooking or resource anomalies), but its scope is set by organisational requirements rather than mandating coverage of all input-capture vectors such as deceptive web portals or credential API hooks on every platform.
- T1056responds — A.8.16 explicitly requires real-time/periodic monitoring for anomalous behaviour (including process injection, unauthorized access, keystroke logging) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26, which bounds impact once input capture is underway; partial because the clause sets scope by business requirements rather than mandating universal coverage of every input-capture variant on every platform.
- T1056.001detects — A.8.16 explicitly lists keystroke logging as an anomalous behaviour to baseline against and detect in real time via monitoring tools, covering the dominant in-host methods while the named remainder (e.g. custom drivers on network devices outside chosen monitoring scope) is bounded by the clause's own scoping language.
- T1056.001prevents — A.8.16 explicitly configures monitoring to detect and alert on keystroke logging as anomalous behaviour (listed under unusual system behaviour), which constrains many common keylogging implementations (API hooks, drivers, registry mods) by raising timely alerts that enable response before credential capture succeeds; it does not stop the technique from running at all.
- T1056.001responds — A.8.16 surfaces keystroke logging as anomalous behaviour (explicitly listed) and hands it to the 5.26 response procedure for containment/eradication once underway; partial because the clause sets monitoring scope by business requirements rather than mandating universal coverage of all keylogging variants (e.g. raw hardware buffer reads or network-device hooks may fall outside chosen telemetry).
- T1056.002detects — A.8.16 requires monitoring for anomalous behaviour (incl. process injection, unusual system behaviour, unauthorized access attempts, and deviations from baseline), which surfaces some GUI input capture instances in real time or via logs/alerts, but scope is set by the organization so many implementations miss it entirely.
- T1056.002prevents — A.8.16's real-time/periodic monitoring of system behaviour, processes, resource use, and anomalies (including process injection and unauthorized access) can surface GUI input capture attempts that deviate from baseline, but the control only sets a monitoring scope chosen by the organization and does not mandate mechanisms that stop the technique from running.
- T1056.002responds — A.8.16's real-time/periodic monitoring of system behaviour, processes, access attempts, and anomalies (including process injection and unauthorized access) can surface a spoofed GUI credential prompt once it appears and is executed, enabling alert/response per linked 5.26 procedures; this is genuine but only a slice because many mimicry variants are designed to look like legitimate OS/browser prompts and the clause's scope is set by organisational requirements rather than mandating universal capture of all GUI events.
- T1056.003detects — A.8.16 explicitly lists monitoring for access to critical applications, unauthorized access attempts, anomalous user/system behaviour (including process injection and deviations), event logs, and real-time/periodic anomaly detection against a baseline, which surfaces many instances of web portal credential-capture code; however the clause's scope is set by organisational requirements rather than mandating coverage of every external portal or all post-compromise admin-installed modifications, leaving a genuine slice unreached.
- T1056.003responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (incl. unauthorized access attempts, unusual behaviour, and known attack patterns), alerting, and timely procedures to respond to positive indicators (explicitly referencing 5.26 incident response), which directly acts on the technique once it is underway to contain/eradicate it; partial because the clause sets scope by business needs rather than mandating universal coverage of all web portals or all credential-capture variants.
- T1056.004detects — A.8.16 explicitly lists process injection and anomalous system behaviour (including deviations in standard protocols) among the monitored anomalies, and credential API hooking is a form of inline/IAT/LD_PRELOAD hooking that produces observable deviations; however the clause sets scope by organisational requirements rather than mandating universal deep instrumentation of every API call or library preload, so only a chosen slice is covered.
- T1056.004prevents — A.8.16's baseline monitoring for anomalies explicitly lists process injection and deviations in standard protocols/behaviour, which directly surfaces many hooking implementations (inline/IAT/LD_PRELOAD) before credential capture succeeds, but the control only sets scope per business needs and does not mandate coverage of all in-process API redirection on all platforms.
- T1056.004responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection and deviations in protocols) and requires timely response procedures to minimize adverse effects once an incident is underway, but the clause's scope is set by organisational requirements rather than mandating coverage of credential API hooking specifically.
- T1057detects — A.8.16 explicitly lists monitoring of process injection, anomalous system behaviour, resource use, event logs, security-tool output and deviations from a normal baseline, all of which surface Process Discovery (T1057) when it occurs on monitored hosts; the remainder is the bounded slice of platforms or processes outside the organisation's chosen monitoring scope.
- T1057responds — A.8.16's real-time/periodic anomaly detection, baseline monitoring for unusual behaviour (including process injection), alerting, and procedures to respond to positive indicators directly enable containment/eradication once Process Discovery is underway as anomalous activity, but the clause sets scope by business needs rather than mandating universal coverage of all discovery methods.
- T1059detects — Monitoring for anomalous command execution, process injection and deviations from standard protocol use can flag unauthorized use of command-line interpreters.
- T1059prevents — A.8.16 requires monitoring for anomalous behaviour including process injection, unusual system behaviour, malware-associated activity, and deviations in standard protocols, which can surface many interpreter-abuse indicators in real time and enable timely response that stops the technique from completing its full effect; however the clause sets scope by organisational requirements rather than mandating universal coverage of every interpreter or platform, leaving a genuine slice (e.g. non-monitored interpreters or pre-baseline abuse) unreached.
- T1059responds — A.8.16 configures monitoring to surface anomalous behaviour (incl. process injection, malware patterns, unusual system behaviour) once the interpreter abuse is underway and generates tuned alerts for dedicated personnel to respond to, but the clause itself performs detection rather than the containment/eradication act named by `responds` and its scope is set by organisational requirements rather than mandating coverage of every interpreter abuse vector.
- T1059.001detects — A.8.16 requires monitoring of network/system/application traffic, event logs, resource use, baselines of normal behaviour, and explicit anomalous indicators including process injection and deviations in standard protocols; this surfaces many (but not all) PowerShell abuse patterns in real time or near-real time, yet the clause's scope is set by organisational requirements rather than mandating universal coverage of every in-memory or non-powershell.exe invocation.
- T1059.001prevents — A.8.16's baseline-driven anomaly detection (including process injection, unauthorized code execution, unusual system behaviour, and resource anomalies) can surface or block some PowerShell abuse patterns in real time, but the control sets scope by organisational requirements rather than mandating universal prevention of the interpreter or its .NET interfaces, leaving the dominant legitimate-use slice untouched.
- T1059.001responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (incl. process injection, unusual behaviour, malware patterns), alerting, and timely response procedures to minimize adverse effects once the technique is underway, but scope is set by org requirements so coverage of all PowerShell abuse (esp. in-memory, non-powershell.exe) is not guaranteed.
- T1059.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unusual system behaviour, deviations in protocols, resource use, and known attack patterns, which can surface AppleScript abuse when it produces observable anomalies (e.g. via osascript, NSAppleScript calls, or launched reverse shells); however the clause sets scope by organisational requirements rather than mandating universal coverage of all script execution vectors, leaving a slice determined by the implementer (per A.8.16 event-lane anchor).
- T1059.002prevents — A.8.16's baseline-driven anomaly detection (including process injection, unusual behaviour, unauthorized access, and command/script interpreter activity) can surface many AppleScript abuse vectors in real time, but the control only sets a scoped monitoring requirement rather than mandating universal coverage of every execution path (osascript, NSAppleScript, Mail rules, Automator, etc.), leaving a slice determined by the implementer's chosen scope.
- T1059.002responds — A.8.16 requires real-time/periodic monitoring of system/network/application behaviour, resource use, process termination, malware patterns and anomalous activity (including process injection and deviations), plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26; this surfaces and acts on AppleScript abuse once underway (e.g. via osascript, anomalous keystrokes or network activity) but the clause's scope is set by organisational requirements rather than mandating universal coverage of every AppleScript execution vector.
- T1059.003detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unusual system behaviour, command-and-control traffic patterns, and deviations in standard protocols, which surfaces many (but not all) Windows cmd.exe abuse cases once they run; the clause's scope is set by organisational requirements rather than mandating universal coverage of every cmd.exe invocation.
- T1059.003responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (incl. process injection, unusual behaviour, malware patterns), alerting, and timely response procedures to minimize adverse effects once the technique is underway, but the clause itself only surfaces and hands off the incident rather than performing containment/eradication.
- T1059.004detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unusual system behaviour, deviations in standard protocols, resource use anomalies, and known attack characteristics, which surface many (but not all) Unix shell abuses once they run; scope is set by organisational requirements rather than mandating universal coverage of every shell invocation.
- T1059.004prevents — A.8.16 requires monitoring for anomalous behaviour including process injection, unusual system behaviour, unauthorised access, and deviations in standard protocols, which can surface some Unix shell abuse (especially interactive or script-driven anomalies) before or while it runs, but the control sets its own scope and does not mandate removal of interpreters or block legitimate shell use required by the platform.
- T1059.004responds — A.8.16 requires real-time/periodic monitoring of system/network/application activity, baselines, and anomalies (including process injection, unauthorized access, malware-like behavior, and unusual shell activity patterns), plus dedicated personnel and procedures to respond to alerts in a timely manner per 5.26; this surfaces and acts on T1059.004 once underway but only for the monitored slice an organization chooses, not the full technique surface (e.g., lightweight/Busybox shells or unmonitored embedded systems).
- T1059.005detects — A.8.16 explicitly lists process injection, anomalous system behaviour, malware-associated activity, and deviations in standard protocols as detectable anomalies, which covers some but not all VB abuse vectors (especially VBA macros in Office documents or VBScript in non-monitored contexts).
- T1059.005responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unusual system behaviour, malware patterns, and deviations from baseline) and requires timely response procedures once an indicator fires; this bounds an in-flight VB execution but does not contain/eradicate every VB abuse vector (e.g. macro execution inside Office or one-off VBScript) and the clause itself stops at detection-plus-procedure rather than mandating full incident response containment.
- T1059.006detects — A.8.16 explicitly lists monitoring for process injection, anomalous system behaviour, malware-associated activity, unauthorized code execution, resource anomalies and real-time/periodic baselines that can surface Python-based execution when it deviates from the monitored scope, but the clause sets its own scope by business requirements so an implementation can be fully conformant while missing many Python abuse vectors (e.g. only network/application layers, no host telemetry).
- T1059.006prevents — A.8.16 requires monitoring for anomalous behaviour (incl. process injection, unusual system behaviour, malware-associated activity, and deviations from baseline) which can surface Python-based execution when it deviates from the established baseline, but the control sets its own scope and does not mandate removal of Python interpreters or block their use outright
- T1059.006responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (incl. process injection, malware patterns, unusual system behaviour) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26, which directly matches the `responds` verb once the Python-abuse technique is underway; partial because the clause sets scope by business requirements rather than mandating universal coverage of every possible Python execution vector.
- T1059.007detects — A.8.16 explicitly lists monitoring for anomalous behaviour, process injection, malware-associated activity, unusual system behaviour, and deviations in protocols, which surfaces many (but not all) JavaScript abuse vectors once they execute; scope is set by organisational requirements rather than mandating universal coverage of every JS runtime or in-memory execution.
- T1059.007responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unusual system behaviour, malware-associated activity, and deviations from baseline), which directly enables the incident response procedures (see 5.26) once the JavaScript abuse technique is underway.
- T1059.008detects — A.8.16 explicitly lists monitoring of network traffic, system/network activity logs, admin configuration changes, resource anomalies, known attack patterns, and deviations such as process injection or unauthorized access, which can surface CLI abuse on network devices when it produces observable signals inside the chosen scope; however the clause sets scope by business requirements rather than mandating universal instrumentation of every network device CLI, leaving a large slice of stealthy or non-anomalous uses undetected.
- T1059.008responds — A.8.16's real-time/periodic monitoring of network traffic, system activity, configuration changes, anomalous behaviour (incl. process injection, unauthorized access, malware patterns), and alert generation directly surfaces an in-progress CLI abuse on a network device so that dedicated personnel can respond per linked procedures (5.26).
- T1059.009detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unusual system behaviour, admin-level access, resource use, and known attack patterns, which can surface cloud API abuse when it deviates from the established baseline; however the clause sets scope by organisational requirements rather than mandating coverage of all cloud API calls, leaving many legitimate-looking tenant API invocations outside the monitored slice.
- T1059.009responds — A.8.16 requires real-time/periodic monitoring, anomaly detection against baseline (incl. unusual behaviour, process injection, unauthorized access, admin activity), alerting and timely response procedures to minimize adverse-event impact once the technique is underway; this matches `responds` but only partially because the clause sets scope by business needs rather than mandating universal coverage of all cloud-API abuse vectors or platforms.
- T1059.010detects — A.8.16 explicitly lists process injection, unusual system behaviour, resource anomalies, and execution of unauthorized/tampered code as detectable via baseline monitoring and real-time tools; these surface many (but not all) AHK/AutoIT uses, especially compiled .exe or anomalous runtime patterns, while legitimate/stealthy script automation falls outside the named scope.
- T1059.010prevents — A.8.16's baseline-driven anomaly detection (including process injection, unauthorized code execution, unusual behaviour, and monitoring of executed code integrity) can surface or constrain many uses of AHK/AutoIT scripts, but the control only sets scope and does not mandate blocking, so the technique is not prevented from running.
- T1059.010responds — A.8.16's real-time/periodic anomaly detection (process injection, unusual behaviour, resource use, malware patterns) surfaces T1059.010 once the script or compiled payload runs, enabling the dedicated response procedures it mandates; partial because scope is set by organisational requirements rather than universal coverage of all AHK/AutoIT execution vectors.
- T1059.011detects — A.8.16 requires monitoring for anomalous behaviour (incl. process injection, unusual system behaviour, malware-associated activity, and deviations from baseline) which can surface Lua-based execution when it deviates from the monitored scope and baseline, but the clause sets the monitoring scope by business requirements rather than mandating universal coverage of all interpreters or embedded Lua use.
- T1059.011responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (including process injection and unusual behaviour), alerting, and timely response procedures to minimize adverse effects once an event is underway, but its scope is set by organisational requirements rather than mandating universal coverage of Lua script execution across all platforms and embedding scenarios.
- T1059.012detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unusual system behaviour, resource use, admin-level config changes, and known attack patterns, which can surface hypervisor CLI abuse on ESXi when it deviates from baseline; however the clause sets scope by organisational requirements rather than mandating instrumentation of the hypervisor layer itself, leaving coverage as an implementer-chosen slice.
- T1059.013detects — A.8.16 requires monitoring of network/system/application traffic, access, logs, resource use, baselines for anomalies (incl. process injection, unauthorized access, unusual behaviour), and real-time/periodic alerting; this surfaces many T1059.013 indicators (e.g. anomalous kubectl/docker API calls, container creation, resource spikes) when inside the chosen scope, but the clause sets that scope by business needs so coverage of container-specific CLI/API abuse is an implementer-chosen slice rather than a bounded remainder.
- T1059.013responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unusual system behaviour, resource use, and unauthorized access) and requires timely response procedures once an indicator fires, which can contain or eradicate an in-flight container CLI abuse once detected; it is partial because the clause sets scope by organisational requirements rather than mandating universal container-specific instrumentation, leaving some container CLI/API activity outside the monitored baseline.
- T1068detects — A.8.16 explicitly lists monitoring for process injection, anomalous system behaviour, unauthorized access attempts, known attack characteristics, resource anomalies, and deviations from baseline, all of which surface T1068 exploitation events in real time or near-real time on the monitored estate; the named remainder is exploitation that produces no observable deviation within the chosen monitoring scope.
- T1068responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unauthorized access, unusual system behaviour, known attack characteristics) that surfaces an in-progress T1068 exploitation attempt, with dedicated trained personnel and procedures to respond per 5.26 once the technique is underway.
- T1069detects — A.8.16 explicitly lists monitoring for anomalous behaviour including unauthorized access/attempts, unusual user/system behaviour, process injection, and deviations from baseline (covering discovery-oriented commands and anomalies), but the clause sets scope by organisational requirements rather than mandating universal coverage of all T1069 vectors across every platform.
- T1069.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour including unauthorized access/attempts, unusual user/system behaviour, process injection patterns, and baseline deviations that can surface local group enumeration commands when they deviate from the established baseline of normal access and commands.
- T1069.002detects — A.8.16 explicitly lists monitoring for access to systems/servers/critical apps, event logs, anomalous user/system behaviour, unauthorized access attempts, and deviations such as process injection; these can surface domain enumeration commands (net group, ldapsearch) when they deviate from baseline, but the clause's scope is set by organisational requirements rather than mandating coverage of every discovery technique, leaving a genuine slice uncovered.
- T1069.003detects — A.8.16 requires monitoring (incl. access, config changes, anomalous behaviour, and real-time alerts) that can surface cloud permission-enumeration activity when it matches the defined baseline/scope, but the clause explicitly sets that scope by organisational requirements rather than mandating universal coverage of every API call or cloud-provider log, leaving a large slice of T1069.003 executions outside the monitored set.
- T1070detects — Logging and real-time monitoring of system and network activity make it harder for adversaries to clear traces of their presence without detection.
- T1070.003detects — A.8.16 requires monitoring of logs, command history files (e.g. ~/.bash_history, ConsoleHost_history.txt), system activity, and anomalies like unauthorized access or tampering, which can surface the clearing technique in real time or via retained records; partial because scope is set by the organization and many platforms/vectors (e.g. in-memory session clears, network device CLI) fall outside mandated coverage.
- T1070.003responds — A.8.16's real-time/periodic monitoring of logs, command activity, anomalous behaviour and file changes (including history files and shell logs) surfaces the clearing technique once it runs, enabling timely response per linked 5.26 procedures; partial because scope is set by organisational requirements rather than mandating universal coverage of every history mechanism on every platform.
- T1070.004detects — A.8.16 explicitly lists monitoring of event logs, system/network activity, resource use, process termination, unauthorized access, and anomalous behaviour (including process injection and malware-associated activity); file deletion via built-in commands or tools is observable in those logs and baselines, with a bounded remainder for stealthy or non-logged deletions outside monitored scope.
- T1070.004responds — A.8.16's real-time/periodic anomaly detection, baseline comparison, and alert procedures enable response to indicators of post-intrusion file deletion (e.g. unusual process termination, resource anomalies, or unauthorized access patterns), but the clause's scope is set by organizational requirements rather than mandating coverage of all deletion artifacts or techniques.
- T1070.005detects — A.8.16 explicitly lists monitoring for anomalous behaviour including unauthorized access, unusual system behaviour (e.g. process injection), network traffic, event logs, and deviations in protocols, which can surface network share connection removal as an anomaly or post-action trace; however the clause sets scope by business requirements so coverage of this specific cleanup technique is an implementer-chosen slice rather than a bounded remainder.
- T1070.006detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection), file/system access, and deviations from baseline (e.g. resource use, access patterns); timestomping produces detectable anomalies in file timestamps, MFT attributes, or access times that fit these but is not named and depends on whether the chosen monitoring scope and tools actually instrument file metadata or forensic indicators.
- T1070.007detects — A.8.16 explicitly lists monitoring of network traffic, event logs, system activity, configuration files, anomalous behaviour (including deviations in protocols), and baselines for access patterns, which can surface the clearing or modification of connection history artifacts in logs/registry/files after the fact; however the clause sets scope by organisational requirements rather than mandating universal coverage of every possible artifact or platform, leaving real gaps (e.g. stealthy in-memory tampering or unmonitored network devices).
- T1070.007responds — A.8.16's real-time/periodic monitoring, anomaly detection (including unauthorized access, configuration changes, and unusual behavior), alerting, and procedures to respond to positive indicators directly enable timely response to the T1070.007 cleanup technique once it is underway, though scope is set by organizational requirements rather than mandating universal coverage of all artifacts or platforms.
- T1070.008detects — A.8.16 explicitly includes monitoring of logs from security tools, event logs, anomalous behaviour (including activity associated with malware), and unauthorized access attempts, which can surface mailbox-clearing actions when they deviate from baseline or match known patterns; however the clause's scope is set by organisational requirements rather than mandating coverage of every mailbox API or transport-rule change, leaving a genuine slice unseen.
- T1070.009detects — A.8.16 explicitly lists monitoring for anomalies including process injection, unauthorized access, unusual system behaviour, and deviations from baseline (covering many persistence-cleanup artifacts such as deleted services/executables, registry/plist changes, or account deletions when they produce observable deviations), but the control's scope is set by organisational requirements rather than mandating coverage of every possible cleanup action on every platform.
- T1070.009responds — A.8.16's real-time/periodic anomaly monitoring (process termination, unauthorized access, baseline deviations, alerts triggering 5.26 response) can surface the cleanup actions once they occur, but the clause's scope is set by organizational requirements and does not guarantee coverage of all listed artifacts or platforms.
- T1070.010detects — A.8.16 explicitly lists monitoring for anomalous behaviour, malware-associated activity, process injection, unauthorized access, and deviations from baseline (including file/system events that would surface relocation/copy anomalies), but scope is set by the organization rather than mandating coverage of every relocation tactic on every platform.
- T1070.010responds — A.8.16's real-time/periodic anomaly detection, baseline monitoring for malware-associated activity, process injection indicators, unauthorized access, and dedicated alert response procedures enable containment/eradication once relocation (as evasion) is underway, but scope is set by organizational requirements rather than mandating coverage of all relocation variants or platforms.
- T1071detects — A.8.16 explicitly requires monitoring of network, system and application traffic, baselines of normal behaviour, and anomalous patterns including known attack characteristics, unusual system behaviour and deviations in standard protocols — directly surfacing T1071's covert blending into legitimate application-layer traffic (e.g. HTTP, DNS, SMB) once it occurs.
- T1071prevents — A.8.16 requires monitoring of network/application traffic, baselines, and anomalies (including known attack patterns and deviations in protocols) which can surface blended C2 traffic and thereby constrain the technique's undetected success, but the clause sets scope by organisational requirements rather than mandating universal deep-packet or behavioural blocking, leaving many protocol blends (especially internal enclave ones like SMB/SSH/RDP) as an implementer-chosen slice.
- T1071responds — A.8.16 requires real-time/periodic monitoring of network, system and application traffic plus anomaly detection (including known attack patterns and deviations from baseline), with dedicated personnel and procedures to respond to alerts; this surfaces and acts on T1071 once the blended C2 traffic is underway, but only for the monitored slice (scope is set by business requirements, not universal coverage of all protocols or internal enclave traffic).
- T1071.001detects — A.8.16 explicitly requires monitoring of outbound/inbound network traffic, security-tool logs (firewalls/IDS/IPS), anomalous behaviour patterns, known malicious domains, deviations in standard protocols, and real-time alerting against a baseline; this directly surfaces T1071.001 C2 traffic that blends with or deviates from web-protocol norms, with the bounded remainder being fully stealthy implementations inside allowed traffic that match the baseline exactly.
- T1071.001prevents — A.8.16 requires monitoring (including network traffic, baselines of normal behaviour, anomalous patterns, and known attack characteristics) that can surface disguised C2 blending with legitimate web traffic, but the clause sets scope by organisational requirements rather than mandating universal detection of every possible embedding or mimicry, leaving a genuine slice of the technique unaddressed.
- T1071.001responds — A.8.16 requires real-time/periodic monitoring of network traffic, anomalous behaviour patterns, known attack characteristics and deviations from baseline (explicitly naming process injection and unusual protocol use), plus dedicated alert response and procedures that align with incident response once C2 is underway; the named remainder is stealthy blending that evades the tuned baseline.
- T1071.002detects — A.8.16 explicitly requires monitoring of outbound/inbound network traffic, security-tool logs (firewalls/IDS/IPS), anomalous behaviour patterns, known malicious domains/IPs, deviations in standard protocols, and real-time alerting against a baseline; this surfaces T1071.002's C2 traffic when it deviates from or matches known-bad signatures, with the bounded remainder being fully blended traffic on unmonitored segments or protocols outside the chosen scope.
- T1071.002responds — A.8.16's real-time/periodic monitoring of network traffic, anomalous behaviour, known attack patterns and deviations from baseline can surface an ongoing T1071.002 C2 channel once it produces detectable anomalies, enabling response procedures (5.26); it is not guaranteed because the technique deliberately blends with normal file-transfer traffic and the clause's scope is set by organisational requirements rather than mandating universal deep-packet or protocol-anomaly coverage.
- T1071.003detects — A.8.16 explicitly requires monitoring of outbound/inbound network traffic, event logs, security-tool logs, resource use, and anomalous behaviour patterns (including known malicious domains, protocol deviations, and C2-like activity); T1071.003's mail-protocol C2 produces observable network artefacts that fall inside this scope and would be surfaced by baseline deviation or signature-based detection, with only a bounded remainder (e.g., perfectly mimicked low-volume traffic or monitoring scopes that deliberately exclude certain mail flows) left unreached.
- T1071.003prevents — A.8.16 requires monitoring of network traffic, baselines of normal behaviour, and anomalies including known attack characteristics and deviations in standard protocols, which can surface disguised C2 in common mail protocols; however, the control sets scope by organisational requirements rather than mandating universal deep packet inspection or protocol-specific anomaly detection, leaving a large slice of blended legitimate-looking mail traffic unaddressed.
- T1071.003responds — A.8.16 requires real-time/periodic monitoring of network traffic (incl. application-layer), anomaly detection against baseline, and timely response procedures to positive indicators (see 5.26), which can surface and trigger response to T1071.003 C2 blending with mail traffic; partial because scope is set by org requirements rather than mandating universal mail-protocol depth, leaving slice implementations that miss it.
- T1071.004detects — A.8.16 explicitly lists monitoring of network traffic, anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection deviations), and baseline deviations for real-time or periodic detection with alerts; this surfaces some DNS tunneling/beaconing that deviates from baseline but the clause sets scope by organisational requirements rather than mandating universal DNS-specific depth, leaving a large slice (e.g. infrequent beacons that blend with normal traffic) undetected per the source prose.
- T1071.004responds — A.8.16 requires real-time/periodic monitoring of network traffic (incl. DNS), baselines, anomalous patterns (e.g. unusual DNS behavior, known attack characteristics), and dedicated response to generated alerts, which directly enacts containment/eradication once DNS tunneling/beaconing is underway per the event-lane definition of responds; mostly because scope is set by org requirements rather than mandating universal DNS depth.
- T1071.005detects — A.8.16 requires monitoring of network/application traffic, baselines of normal behaviour, and anomalies including unusual system behaviour or traffic from known malicious sources; this can surface pub/sub abuse when it deviates from the tuned baseline, but the clause sets scope by organisational requirements rather than mandating universal deep packet or protocol-specific inspection of MQTT/XMPP/AMQP/STOMP flows, leaving a large slice of blended legitimate-looking traffic unseen.
- T1071.005prevents — A.8.16 requires monitoring of network/application traffic, baselines of normal behaviour, and detection of anomalies including unusual system behaviour and known attack characteristics; this can surface pub/sub C2 traffic that deviates from baseline, but the control sets scope by organisational requirements rather than mandating universal deep-packet or protocol-specific detection of blended legitimate-looking pub/sub abuse, leaving a large slice of implementations that would miss it.
- T1071.005responds — A.8.16 requires real-time/periodic monitoring of network traffic, anomalous behaviour (including deviations in protocols), and alerts with dedicated response personnel per 5.26; this surfaces and contains pub/sub C2 once underway, but scope is set by org requirements so coverage of this specific protocol blending is not assured.
- T1072detects — A.8.16 explicitly lists monitoring for anomalous behaviour, process injection, unauthorized access, admin-level config changes, resource anomalies, and known attack patterns, which can surface abuse of deployment tools once they deviate from baseline; however the clause sets scope by organisational requirements rather than mandating coverage of every management suite or SaaS channel, leaving a slice determined by the implementer
- T1072prevents — A.8.16's real-time/continuous monitoring of traffic, access, config files, logs, resource use, baselines, and explicit anomalous indicators (process injection, unauthorized access, malware-like activity, admin-level changes) surfaces many abuse patterns of enterprise deployment tools before or while they enable RCE/lateral movement, but the clause only sets scope per business needs and does not mandate coverage of every management suite, SaaS channel, or CI/CD integration, leaving a genuine slice unreached.
- T1072responds — A.8.16's real-time/periodic anomaly detection, baseline-based alerting on unusual behaviour (incl. process injection, unauthorized access, admin-level config changes), and procedures to respond to positive indicators directly enable containment/eradication once T1072's abuse of deployment tools is underway, but scope is set by org requirements so coverage of all such tools (esp. SaaS/cloud) is not assured.
- T1074detects — A.8.16 explicitly lists monitoring of network traffic, access, configuration files, security-tool logs, event logs, resource use, baselines of normal behaviour, and specific anomalies including process injection, malware-associated activity, unauthorized access/scanning, and deviations from expected user/system behaviour — all of which surface T1074 staging activity (file copies, archiving, new cloud instances, central directories) in real time or near-real time; the remainder is activity that evades the chosen scope or produces no observable deviation.
- T1074responds — A.8.16's real-time/periodic anomaly detection, baselines, and alerts (including on unusual behaviour, process injection, unauthorized access, and resource anomalies) enable response procedures once staging is underway, but the clause only surfaces indicators rather than performing containment/eradication itself.
- T1074.001detects — A.8.16 explicitly lists monitoring of file/system activity, resource use, process anomalies, baselines of normal behaviour, and real-time/periodic detection of deviations including unusual system behaviour; local data staging produces observable artifacts (new files, archive activity, registry changes, anomalous I/O or process execution) that fall inside the listed scope, with only a bounded remainder (e.g. perfectly stealthy in-memory staging on unmonitored hosts) left unreached.
- T1074.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour, process injection, unusual system behaviour, resource use, file access, and network traffic that can surface remote data staging when it deviates from the established baseline, but the clause sets its own scope by business requirements so many implementations will miss it entirely (e.g. network-only monitoring).
- T1074.002responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. unusual behaviour, process injection, resource use), alerting and dedicated response procedures enable containment/eradication once staging (a post-collection precursor to exfil) is underway and observable, but scope is set by org requirements so coverage of all platforms/behaviours is not assured.
- T1078detects — Continuous monitoring of access attempts against a baseline of normal user behaviour and locations directly reduces the stealth value of using valid accounts for unauthorized activity.
- T1078prevents — A.8.16's baseline-driven anomaly detection (unusual access patterns, unauthorized attempts, process injection, resource deviations) can surface many uses of valid accounts but does not stop credential compromise or the legitimate-looking access itself, and its scope is set by organizational requirements rather than mandating coverage of every account or platform.
- T1078responds — A.8.16 surfaces anomalous use of valid accounts (e.g. unusual login times/locations, unauthorized access attempts, deviations from baseline) once the technique is underway and feeds those indicators to 5.26 response procedures, but the control itself performs none of the core respond actions (contain, eradicate) and many T1078 vectors (inactive accounts, legitimate-looking pivots without malware) produce no observable anomaly at all.
- T1078.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access attempts, unusual user/system behaviour, access to critical systems, and known attack patterns, which surfaces many (but not all) default-account abuses once they produce observable deviations from baseline; it does not inherently surface static existence of unchanged default accounts or credential material before use.
- T1078.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour including unauthorized access attempts, unusual user/system behaviour, process injection, admin-level config changes, and resource anomalies that can surface domain account abuse in flight or post-compromise, but the clause sets scope by organisational requirements rather than mandating universal coverage of all credential-abuse indicators or platforms.
- T1078.003detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access attempts, unusual user/system behaviour, admin-level config changes, and resource/performance deviations that can surface many (but not all) abuses of local accounts across its broad scope of traffic, logs, events and baselines; the clause sets its own monitoring scope by organisational requirements rather than mandating universal coverage of every local-account abuse vector (e.g. credential dumping on unmonitored endpoints or silent password-reuse lateral movement).
- T1078.003responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (including unauthorized access, process injection, unusual behaviour), alerting, and timely response procedures to minimize adverse effects once an incident is underway, which directly maps to responding to local account abuse indicators; partial because the clause sets scope by business needs rather than mandating universal coverage of all local-account abuse vectors across every platform.
- T1078.004detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access attempts, unusual user/system behaviour, access to critical systems, and real-time/periodic alerts tuned to a baseline, which surfaces many T1078.004 indicators (e.g. anomalous logons, privilege assumptions, unexpected resource use); however the clause sets scope by organisational requirements rather than mandating coverage of all cloud-specific account behaviours or hybrid/federated paths, leaving a genuine implementation-chosen slice.
- T1078.004responds — A.8.16 requires real-time/periodic monitoring, anomaly detection against baseline (including unauthorized access, privilege anomalies, unusual behaviour), alert generation and dedicated trained personnel to respond to alerts, which directly enables timely response to T1078.004 indicators once the technique is underway; partial because the clause sets scope by organisational requirements rather than mandating universal coverage of all cloud-account misuse vectors (e.g. purely API-driven or hybrid-federated pivots may fall outside chosen monitoring).
- T1080detects — A.8.16 explicitly lists monitoring for anomalous behaviour (e.g. process injection, malware-associated activity, unauthorized access/scanning, unusual file/system behaviour, known attack patterns) and requires real-time/periodic tools with alerts, which surfaces many indicators of T1080 once the tainted content is accessed or executes; however the clause's scope is set by organisational requirements rather than mandating coverage of all shared-storage writes or pre-execution binary tainting, leaving a genuine slice uncovered.
- T1080responds — A.8.16's real-time/periodic anomaly detection, baseline comparison, and alerts for malware-associated activity, unauthorized access, process anomalies, and known attack patterns (including file tampering indicators) enable response to an in-progress T1080 taint once the tainted content is accessed or executed, but the clause's scope is set by organizational requirements rather than mandating coverage of all shared-content vectors or pre-execution file-integrity checks.
- T1082detects — A.8.16 requires monitoring of system/network activity, resource use, anomalous behaviour (incl. process injection, unusual system behaviour) and security-tool logs, which can surface T1082 when it deviates from baseline or triggers known patterns, but the clause sets scope by organisational requirements rather than mandating coverage of every discovery command, CLI query or cloud API call, leaving a large slice of T1082 executions unseen.
- T1083detects — A.8.16 explicitly lists monitoring for unauthorized access/attempts, anomalous user/system behaviour, and specific patterns such as process injection or deviations, which can surface T1083 when it produces observable anomalies against the established baseline; however the clause's scope is set by organisational requirements rather than mandating universal coverage of all discovery commands or locations, leaving a large slice of stealthy or permission-gated enumeration undetected.
- T1083responds — A.8.16 requires real-time/near-real-time monitoring for anomalous behaviour (including unauthorized access/scanning attempts, unusual system behaviour, and deviations from baseline) plus dedicated personnel and procedures to respond to alerts (see 5.26), which can contain/eradicate an in-progress T1083 enumeration once detected; partial because the clause sets scope by business needs rather than mandating universal coverage of all discovery methods or platforms, and detection/response depends on what is instrumented in the baseline.
- T1087detects — A.8.16 requires monitoring for anomalous behaviour including unusual user/system activity, unauthorized access attempts, and process/command patterns that can surface many T1087 discovery actions (e.g. via command-line, file searches, or baseline deviations), but scope is set by the organization so coverage of all platforms/methods (cloud APIs, ESXi, Office Suite, etc.) is not mandated.
- T1087responds — A.8.16's real-time/periodic monitoring of system activity, anomalous behaviour (incl. unusual access or process patterns), resource use, and alerts for predefined thresholds can surface account-discovery activity once underway, enabling response per linked 5.26 procedures; partial because the clause sets scope by organisational requirements rather than mandating universal coverage of every enumeration vector (e.g. file searches or cloud API calls may fall outside chosen baselines).
- T1087.001detects — A.8.16 explicitly lists monitoring for access to systems/servers, event logs, unauthorized access attempts, unusual user/system behaviour, and process anomalies, which can surface local account enumeration commands or /etc/passwd reads as deviations from baseline; however the clause sets scope by organisational requirements rather than mandating coverage of every discovery technique, leaving a slice determined by the implementer (cf. A.8.16 vs T1055 anchor).
- T1087.002detects — A.8.16 explicitly lists monitoring for access to systems/servers/critical apps, event logs, anomalous user/system behaviour, unauthorized access attempts, and deviations such as process injection or unusual patterns, which can surface domain enumeration commands (e.g. net, ldapsearch, PowerShell Get-ADUser) when they deviate from baseline; however the clause sets scope by organisational requirements rather than mandating universal coverage of all such activity, leaving a genuine slice unreached.
- T1087.003detects — A.8.16 requires monitoring for anomalous behaviour (including unusual access, admin activity, resource use, and patterns like unauthorized scanning or access to protected resources such as file systems or directories), which can surface T1087.003 when it deviates from baseline; however the clause explicitly sets scope by business requirements rather than mandating universal coverage of all email-account enumeration vectors (e.g. authenticated PowerShell against Exchange or Google Workspace directory queries may fall outside chosen telemetry).
- T1087.004detects — A.8.16 requires monitoring of access, logs, anomalous behaviour, and known attack patterns (including unusual user/system behaviour), which can surface cloud account enumeration after authenticated access; however the clause sets scope by organisational requirements rather than mandating coverage of every cloud-provider API call or IAM enumeration command, leaving a large slice of stealthy or low-volume enumeration outside the monitored baseline.
- T1090detects — A.8.16 explicitly lists monitoring of inbound/outbound network traffic, anomalous behaviour patterns, known malicious IPs/domains, and deviations such as process injection or protocol anomalies, which surfaces many (but not all) proxy-based C2 techniques once they generate observable traffic or baseline deviations.
- T1090responds — A.8.16 surfaces anomalous proxying patterns (e.g. unexpected traffic, known C2 domains, process injection, or deviations from baseline) once underway and feeds them to 5.26 response procedures, satisfying the core of `responds`; it is only partial because the clause's scope is set by organizational requirements rather than mandating coverage of every proxy variant or platform, and many stealthy or in-band proxy uses produce no observable anomaly at all.
- T1090.001detects — A.8.16 explicitly lists monitoring of inbound/outbound network traffic, anomalous behaviour patterns, known attack characteristics, deviations in protocols, and unusual system behaviour (including process injection), which can surface internal proxying when it produces observable anomalies against the baseline; however the clause's scope is set by organisational requirements rather than mandating universal coverage of all stealthy p2p/SMB-blended internal proxy activity.
- T1090.001responds — A.8.16 configures real-time/periodic monitoring of network traffic, anomalous behaviour (incl. process injection, unusual protocols, malware patterns), and generates tuned alerts for dedicated response per 5.26; this surfaces and enables response to internal proxy C2 once underway, but scope is set by org requirements so coverage of stealthy p2p/SMB blending or non-monitored internal lateral paths is a chosen slice rather than bounded remainder.
- T1090.002detects — A.8.16 explicitly lists monitoring of outbound/inbound network traffic, anomalous behaviour patterns, known malicious IP/domains, and deviations such as process injection or unusual protocols, which surfaces external-proxy C2 traffic when it deviates from the established baseline; however the clause's scope is set by organisational requirements rather than mandating universal coverage of all possible external proxies or stealthy implementations, leaving a large slice of the technique unseen.
- T1090.002prevents — A.8.16 requires monitoring of network traffic, anomalous behaviour, known attack patterns and deviations from baseline (including unusual protocols or outbound connections), which can block some external-proxy C2 setups that produce detectable signatures or anomalies; however the control only sets a scope-determined monitoring practice rather than a universal blocking mechanism, leaving many stealthy or whitelisted-proxy uses untouched.
- T1090.002responds — A.8.16 configures real-time/periodic monitoring of network traffic, anomalous behaviour (incl. known attack patterns, unusual protocols, unauthorized access), baselines, and alerts that surface an in-flight external-proxy C2 channel so dedicated personnel can respond per linked 5.26 procedures.
- T1090.003detects — A.8.16 explicitly lists monitoring of inbound/outbound network traffic, anomalous behaviour patterns, known malicious IPs/domains, unusual system behaviour (including process injection), and real-time/periodic anomaly detection against baselines, which surfaces many observable indicators of multi-hop proxying (e.g. Tor, ORB, P2P routing); however the control's scope is set by organisational requirements rather than mandating coverage of all proxy variants or the full chain, leaving a large slice (especially encrypted/obfuscated hops or non-monitored network layers) unreached.
- T1090.003prevents — A.8.16's real-time/periodic monitoring of inbound/outbound traffic, anomalous patterns, known malicious IPs/domains, unusual protocols, and deviations from baseline can block some multi-hop proxy chains (e.g. detectable Tor/ORB signatures or anomalous routing), but the control's scope is set by the organization and leaves many stealthy/decentralized/P2P/blockchain variants undetected before they succeed.
- T1090.003responds — A.8.16 configures real-time/periodic monitoring plus alerts for anomalous traffic patterns, unauthorized access, and known attack characteristics (including proxy-like C2 or botnet traffic), enabling timely response procedures per 5.26 once the multi-hop chain is observed entering the network; it does not act on or contain the technique before the final hop or address tracing prior proxies.
- T1090.004detects — A.8.16 explicitly lists monitoring of inbound/outbound network traffic, anomalous behaviour patterns, known attack characteristics, and deviations in standard protocols (plus real-time tools and alerts), which can surface domain fronting when it produces observable anomalies against the established baseline; however the clause's scope is set by organisational requirements rather than mandating universal deep packet inspection of TLS/HTTP header mismatches, leaving a large slice of stealthy or non-anomalous uses undetected.
- T1091detects — A.8.16 explicitly lists monitoring for malware-associated activity, known attack characteristics, process injection, unauthorized access attempts, anomalous system behaviour, resource anomalies, and real-time/periodic alerts against a baseline, which surfaces many observable indicators of T1091 (e.g. Autorun execution, USB/removable-media events, anomalous processes) but leaves a bounded remainder for fully air-gapped or pre-execution firmware/media manipulation that never reaches monitored systems or logs.
- T1091prevents — A.8.16's real-time/periodic monitoring of traffic, logs, resource use, baselines, malware signatures, process injection, unauthorized access, and anomalous behaviour can detect and thereby prevent execution of the Autorun/removable-media payload in many (but not all) cases, especially on connected systems; air-gapped, firmware, or manual-execution vectors lie outside its scope.
- T1091responds — A.8.16 requires real-time/periodic monitoring of system behaviour, resource use, logs, malware indicators and anomalies (including process injection and unauthorized access), plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26; this surfaces and acts on T1091 once the media-triggered execution or infection is underway, but only for the observable slice inside the scoped baseline rather than all air-gapped or manual-removable-media cases.
- T1092detects — A.8.16 explicitly lists monitoring for anomalous behaviour, malware-associated activity, process injection, unauthorized access, resource use deviations, and real-time/periodic analysis of network/system/application traffic and logs, which can surface indicators of removable-media C2 (e.g. anomalous USB activity, file staging, or exfil patterns) once the media is mounted or the relay occurs; however the clause's scope is set by organizational requirements rather than mandating coverage of air-gapped or removable-media vectors, leaving a large slice of T1092's disconnected/lateral-movement scenarios outside typical monitoring instrumentation.
- T1095detects — A.8.16 explicitly lists monitoring of outbound/inbound network traffic, anomalous behaviour patterns, known attack characteristics, and deviations in standard protocols (plus real-time tools and baselines), which surfaces many non-application-layer uses such as ICMP/UDP/SOCKS; however, the VMCI-localized variant is explicitly invisible to external monitoring and standard tools, and scope is set by organizational requirements rather than mandating universal coverage of every possible non-app protocol.
- T1095responds — A.8.16 explicitly configures monitoring to generate alerts on anomalous behaviour including known attack characteristics, unusual system behaviour (e.g. process injection), and deviations in use of standard protocols, with dedicated personnel and procedures to respond to positive indicators per 5.26; this matches the `responds` verb once the non-application-layer C2 is underway, but is only partial because VMCI-localized traffic and many non-application protocols remain invisible to the listed external/network-focused monitoring scope.
- T1098detects — A.8.16 explicitly lists monitoring for anomalous behaviour including unauthorized access/attempts, account-related activity patterns, admin/config changes, process anomalies, and deviations from baseline (e.g. unusual user behaviour, access times/locations), which surfaces most forms of account manipulation once it occurs on the monitored estate; the named remainder is pre-compromise manipulation on external identity providers or SaaS outside the organization's own monitored systems and logs.
- T1098responds — A.8.16's real-time/periodic anomaly detection, alerting, and procedures to respond to positive indicators (including unusual behaviour like privilege changes or account anomalies) enable containment/eradication once account manipulation is underway, but the clause's scope is set by organisational requirements rather than mandating coverage of all T1098 vectors (e.g. offline credential mods, SaaS/identity-provider paths).
- T1098.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access attempts, unusual system behaviour (including process injection), admin-level config changes, and resource/performance deviations; these surface many T1098.001 indicators (e.g. new SSH keys, access-key creation, federation-token calls, or anomalous credential-add API activity) once the baseline is tuned, but the clause sets scope by organisational requirements rather than mandating universal coverage of every cloud API or identity-provider event, leaving a genuine slice unreached.
- T1098.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access (actual or attempted), unusual user/system behaviour, admin-level config changes, and real-time/periodic alerting on deviations from baseline, which surfaces T1098.002 mailbox-permission grants when they fall inside the chosen monitoring scope; the clause sets that scope by organisational requirements rather than mandating coverage of every mailbox-permission or cloud-admin action, so only a slice is guaranteed to be detected.
- T1098.003detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access/privilege changes, admin-level config modifications, unusual system behaviour (including process injection patterns), and real-time alerting on deviations from baseline, which surfaces many T1098.003 instances in IaaS/SaaS/Office environments; however, the control's scope is set by organizational requirements rather than mandating coverage of all cloud IAM/policy APIs or external tenant role additions, leaving a slice determined by the implementer.
- T1098.004detects — A.8.16 explicitly lists monitoring of access to systems/servers/critical apps, event logs, admin config files, anomalous behaviour (including unauthorized access attempts and deviations from baseline), and real-time/periodic anomaly detection against a tuned baseline; this surfaces many T1098.004 realizations (esp. on Linux/macOS via file changes or unusual access), but the clause sets scope by org requirements so implementations can fully conform while missing cloud API calls, network-device CLI use, or non-monitored hosts — a slice chosen by the implementer rather than a bounded remainder.
- T1098.004responds — A.8.16's real-time/periodic anomaly detection (including file/config changes, unauthorized access, process injection indicators, and baseline deviations) surfaces the technique once it runs, enabling timely response per linked 5.26, but scope is set by org requirements so coverage of all SSH authorized_keys mods (esp. on network devices, cloud APIs, or non-monitored hosts) is only a chosen slice.
- T1098.005detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access attempts, unusual system behaviour (including process injection), resource use anomalies, and real-time/periodic alerts tuned to a baseline; device registration can surface as anomalous MFA enrollment, unusual admin activity, or resource spikes, but the control's scope is set by organizational requirements rather than mandating coverage of identity-provider or MFA enrollment events, leaving a large slice (especially stealthy or low-volume registrations) unreached.
- T1098.006detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access/attempts, unusual system behaviour (including process injection), admin-level config changes, and baseline deviations that can surface the permission/role-binding activity when it deviates from normal, but the clause's scope is set by organisational requirements rather than mandating coverage of container orchestration or Kubernetes RBAC/ABAC specifically, leaving most realisations outside the chosen slice.
- T1098.007detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access/privilege changes, unusual user/system behaviour, admin-level config changes, and resource/performance deviations; these surface many (but not all) instances of T1098.007 after the fact when the group-add command or its effects deviate from baseline.
- T1098.007responds — A.8.16's real-time/periodic anomaly detection, baseline comparison, and alert generation on events like unauthorized access, privilege changes, or unusual account activity can surface an in-progress group-addition (T1098.007) once it triggers observable logs or deviations, enabling response procedures (5.26), but the clause's scope is set by organizational requirements rather than mandating coverage of all such modifications.
- T1102detects — A.8.16 explicitly lists monitoring of outbound/inbound network traffic, anomalous behaviour patterns, known malicious domains/IPs, deviations in protocols, and real-time/continuous tools that can surface C2 via web services when they deviate from the established baseline, but the control's scope is set by organisational requirements rather than mandating universal coverage of all legitimate web services used for C2.
- T1102responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (incl. malware-associated traffic, known attack characteristics, process injection, deviations in protocols) plus dedicated trained personnel and procedures to respond to alerts (see 5.26), which acts on T1102 once underway to contain/eradicate; partial because scope is set by org requirements so coverage of web-service C2 in expected noise is not mandated.
- T1102.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, malware-associated traffic, deviations in protocols, and outbound network traffic against a baseline, which can surface dead-drop resolver activity when it deviates from expected patterns, but the clause sets scope by organisational requirements rather than mandating universal coverage of all web-service C2 (especially when it blends with expected noise on popular sites).
- T1102.002detects — A.8.16 explicitly lists monitoring of outbound/inbound network traffic, anomalous behaviour patterns, known malicious domains/IPs, unusual system behaviour (including process injection), and real-time/continuous tools that surface deviations from baseline; this catches many T1102.002 indicators once the C2 channel is active, but the technique's use of common legitimate services (Google/Twitter) that blend into expected noise and its SSL/TLS protection leave a substantial slice undetected when scope is set only by business requirements.
- T1102.002responds — A.8.16 requires real-time/periodic monitoring of network traffic, anomalous behaviour (including known attack patterns and deviations), and dedicated response to alerts, which can surface and trigger response to bidirectional C2 once underway; partial because scope is set by organisational requirements rather than mandating universal coverage of all web-service channels or encrypted payloads.
- T1102.003detects — A.8.16 explicitly lists monitoring of outbound/inbound network traffic, anomalous behaviour patterns, known malicious domains/IPs, and deviations such as process injection or unusual system behaviour; this surfaces one-way C2 over common web services when it deviates from the established baseline, but the clause sets scope by organisational requirements rather than mandating universal coverage of all such traffic, leaving a large slice (e.g. low-and-slow or fully blended use of Google/Twitter) dependent on what the implementer includes.
- T1102.003prevents — A.8.16 mandates monitoring of outbound/inbound traffic, anomalous behaviour, known malicious domains, unusual system behaviour and baseline deviations; this can surface or block some one-way Web-service C2 that deviates from the baseline, but the technique's use of common legitimate services (Google/Twitter) that already appear in normal traffic is explicitly noted as hiding in expected noise, so only a minority slice is prevented.
- T1104detects — A.8.16 explicitly lists monitoring for anomalous network traffic, known attack characteristics, unusual system behaviour (including process injection), outbound/inbound flows, resource anomalies, and real-time alerting against a baseline; this surfaces many observable indicators of multi-stage C2 staging and fallback but leaves a slice (e.g., fully air-gapped or non-networked staging steps, or stages that perfectly mimic baseline behaviour) unreached because scope is set by organisational requirements rather than mandating exhaustive coverage of every possible stage.
- T1104responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (incl. process injection, unusual traffic, malware patterns, unauthorized access) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26, which directly matches the `responds` verb once a multi-stage C2 channel is underway; partial because the clause sets scope by business requirements rather than mandating universal coverage of every possible staging artifact or fallback channel.
- T1105detects — Monitoring inbound and outbound traffic for signatures associated with malware or known malicious domains can detect and alert on unauthorized tool transfers.
- T1105responds — A.8.16 requires real-time/periodic monitoring of network traffic, system activity, anomalous behaviour (incl. malware-associated downloads), resource use, and alerts on deviations from baseline, plus dedicated response to positive indicators per 5.26; this surfaces and enables response to T1105 once underway but does not contain/eradicate the transferred tool or its effects, and scope is set by org requirements rather than mandating full coverage of all transfer vectors.
- T1106detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized access attempts, and monitoring of system/network/application activity plus baselines for anomalies, which surfaces many (but not all) native API abuse patterns; the control's scope is set by organisational requirements rather than mandating universal coverage of every syscall or in-process invocation, leaving a genuine slice unseen.
- T1110detects — Baseline monitoring of access frequency and failed login attempts helps identify brute-force or password-spraying attempts against accounts.
- T1110prevents — A.8.16's baseline-driven anomaly detection (failed logins, unusual access patterns, known attack characteristics) can surface and thereby stop many online brute-force attempts before success, but it is silent on offline attacks, does not mandate blocking mechanisms, and leaves slices determined by the chosen monitoring scope.
- T1110responds — A.8.16 surfaces brute-force indicators (failed logins, anomalous access patterns, unusual login times/locations, traffic to/from malicious IPs) in real time or near-real time and feeds them to the 5.26 response process for containment and eradication once the technique is underway.
- T1110.001detects — A.8.16 explicitly configures monitoring and alerting against a baseline for anomalous behaviour that squarely includes unsuccessful access attempts to protected resources, unusual login patterns, activity from known malicious IPs, and known attack characteristics; this surfaces password guessing in flight on the organization's estate (especially where it generates observable logs or traffic on covered services), with the bounded remainder being fully external/pre-authentication attempts that never reach monitored internal resources.
- T1110.001prevents — A.8.16 mandates real-time/periodic monitoring of network traffic, access attempts, auth logs, anomalous behaviour baselines, and explicit indicators such as unsuccessful access to protected resources, unusual login patterns, and known attack characteristics; this directly stops password-guessing success on covered vectors (e.g. via alerts triggering 5.26 response before compromise), with the bounded remainder being exempted identities, legacy protocols, or out-of-scope monitoring choices allowed by the clause.
- T1110.001responds — A.8.16 requires real-time/periodic monitoring of network traffic, access attempts, logs, anomalous behaviour (including unauthorized access attempts and known attack patterns), baseline deviations, and alert generation with dedicated response personnel; this directly surfaces and enables timely response to password-guessing activity once underway, with the named remainder being stealthy attempts that evade the configured scope or baseline.
- T1110.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour including unauthorized access attempts, successful/unsuccessful protected-resource access, unusual user behaviour, and known attack characteristics, which surfaces many password-cracking indicators once they interact with the monitored environment; it does not cover offline cracking performed entirely on adversary-controlled systems outside the target network.
- T1110.002prevents — A.8.16's baseline-driven continuous monitoring explicitly targets anomalous login patterns, failed/successful access attempts to protected resources, unusual user behaviour, known attack characteristics and malware-like activity, which directly stops most offline-cracked credential use at the point of authentication (the technique's final step).
- T1110.003detects — A.8.16 explicitly monitors inbound/outbound traffic on the exact management ports and protocols (SSH, RDP, HTTP, LDAP, Kerberos, SMB, etc.) that password spraying uses, plus access attempts, event logs, anomalous login patterns, unusual user behaviour, and known attack characteristics, surfacing the technique in flight; the remainder is throttled or low-and-slow spraying that deliberately stays under the tuned baseline thresholds.
- T1110.003prevents — A.8.16 mandates real-time/periodic monitoring of network traffic, access attempts, auth logs, anomalous behaviour baselines, known attack patterns (including login-related), and alerting on thresholds, which directly stops most password-spraying attempts from succeeding by enabling timely response before credential acquisition.
- T1110.003responds — A.8.16 explicitly requires real-time/periodic monitoring for anomalous behaviour (including unusual access patterns, failed login attempts, and activity matching known attack characteristics), automated alerts on thresholds, dedicated trained personnel to respond to alerts, and timely procedures to minimize adverse effects once indicators appear (cross-referenced to 5.26 incident response).
- T1110.004detects — A.8.16 requires monitoring (network, access, logs, anomalous behaviour, known attack patterns, unusual access attempts) that can surface credential-stuffing traffic or failures when inside the chosen scope and baseline, but the clause explicitly lets the organization set that scope so credential stuffing against unmonitored services, protocols or SSO endpoints can remain unseen.
- T1110.004prevents — A.8.16 mandates real-time/periodic monitoring of network traffic, access attempts, auth logs, anomalous behaviour (including unusual access patterns, failed logins, and known attack characteristics), and automated alerts on deviations from baseline, which directly stops most credential-stuffing attempts from succeeding before access is granted.
- T1110.004responds — A.8.16 requires real-time/periodic monitoring of network traffic, access attempts, logs, anomalous behaviour (including unusual access patterns and authentication failures), and automated alerts with dedicated response personnel; this surfaces and enables containment of credential stuffing once underway (the technique runs and produces observable failures/traffic), with the named remainder being attacks that complete before detection/response or fall outside the scoped baseline.
- T1111detects — A.8.16 explicitly lists monitoring for process injection, keylogging, anomalous user/system behaviour, malware-associated activity, and unauthorized access attempts, which surface several T1111 vectors (e.g. keyloggers, token capture, anomalous MFA flows) in real time or near-real time; it does not cover all out-of-band interception vectors (e.g. SMS provider compromise) or non-observable replay/prediction steps, and scope is set by the implementer rather than mandated universally.
- T1112detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, unusual system behaviour, admin-level config changes, and known attack characteristics, which can surface many T1112 Registry modifications that deviate from baseline (e.g. via event logs, resource use, or signatures); however the clause sets scope by organisational requirements rather than mandating universal Registry instrumentation, leaving a slice of stealthy or non-anomalous modifications unseen.
- T1113detects — A.8.16 requires monitoring for anomalous behaviour (incl. process injection, unusual system behaviour, resource use, and known attack patterns) and can surface screen-capture activity when it deviates from the established baseline or matches a monitored signature, but the clause sets scope by organisational requirements rather than mandating universal coverage of every possible screenshot API or native utility, leaving a slice determined by the implementer
- T1114detects — A.8.16 explicitly lists monitoring of network traffic, access to systems/servers/critical apps, security tool logs (incl. DLP), event logs, anomalous behaviour patterns (incl. malware-associated activity), and real-time/periodic alerting tuned to a baseline, which surfaces many instances of email collection from mail servers/clients; however the clause's scope is set by business requirements rather than mandating coverage of all email clients or exfiltration vectors, leaving a genuine slice unreached.
- T1114responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (including malware patterns, unauthorized access, and deviations), alert generation, and dedicated response procedures that align with 5.26 incident response, enabling containment once email collection is underway; partial because the clause sets scope by business needs (not mandating coverage of all email vectors like client-side collection or Office Suite) and focuses on detection/alerting rather than full eradication of the technique's artifacts.
- T1114.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, unusual system behaviour, file access patterns, and resource anomalies, which can surface local email collection in real time or near-real time; however the clause's scope is set by organisational requirements rather than mandating universal coverage of every local file read, so what is caught is an implementer-chosen slice rather than a bounded remainder.
- T1114.002detects — A.8.16 explicitly lists monitoring of network traffic, access to systems/servers/critical apps, event logs, anomalous user/system behaviour, and known attack patterns; this can surface credentialed Exchange/Office 365 access or unusual email collection patterns once the baseline is tuned, but the clause sets scope by business requirements rather than mandating coverage of every SaaS API call or credentialed mailbox query, leaving a large slice of remote collection unseen.
- T1114.002responds — A.8.16 requires real-time/periodic monitoring, anomaly detection against baseline (including unusual access and resource use), alerts, and dedicated trained personnel with procedures to respond to positive indicators (explicitly referencing 5.26 incident response), which acts on the technique once underway to contain/eradicate it; partial because the clause sets scope by business requirements rather than mandating universal coverage of email-service interactions or credentialed collection.
- T1114.003detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unusual user/system activity, access to protected resources (including file systems and mail-related logs), and real-time/periodic alerting on deviations from baseline; this surfaces many T1114.003 indicators (e.g. new forwarding rules, hidden MAPI changes, unexpected outbound mail flows) when they fall inside the chosen scope, but the clause itself only sets requirements for scope and does not mandate coverage of email-rule creation or transport-rule events, leaving a large implementer-chosen slice uncovered.
- T1114.003responds — A.8.16's real-time/periodic anomaly detection, alerting, and procedures to respond to positive indicators (see 5.26) can surface and trigger response to anomalous forwarding-rule creation or hidden-rule activity once it occurs, but the clause's scope is set by organizational requirements and does not guarantee coverage of email-client or transport-rule artifacts.
- T1115detects — A.8.16 explicitly lists process injection, anomalous system behaviour, resource use, and deviations from baseline as monitoring targets, which can surface clipboard-monitoring or clipboard-replacement techniques when they produce observable anomalies; the remainder is silent, stealthy, or non-anomalous clipboard reads that produce no detectable deviation from the configured baseline.
- T1119detects — A.8.16 explicitly lists monitoring of network/system/application traffic, access, event logs, resource use, anomalous behaviour baselines, and specific indicators such as process injection or unusual system behaviour that can surface automated collection activity once it is underway; however the clause sets scope by organisational requirements rather than mandating universal coverage of every collection vector (e.g. cloud ETL pipelines or built-in RAT functionality), making the coverage a chosen slice rather than a bounded remainder.
- T1119responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (including unusual behaviour, process injection, unauthorized access), alerting, and timely response procedures to minimize adverse effects once an event is underway, which matches the `responds` verb; extent is partial because the clause's scope is set by organizational requirements rather than mandating universal coverage of all automated collection vectors (e.g. cloud APIs, ETL, or built-in RAT functionality may fall outside monitored baselines).
- T1120detects — A.8.16 requires monitoring for anomalous behaviour (incl. unusual system behaviour and resource use) and can surface peripheral discovery when it deviates from the established baseline or matches known patterns, but the clause sets scope by business requirements rather than mandating instrumentation of all discovery techniques, leaving a large slice of stealthy or non-anomalous enumeration uncovered.
- T1123detects — A.8.16 explicitly lists monitoring for process injection, anomalous system behaviour, malware-associated activity, resource use, event logs, security-tool logs and deviations from baseline, all of which surface audio-capture techniques (API calls, new processes, unusual mic/webcam access, file writes) in real time or near-real time; the named remainder is capture performed entirely through legitimate, in-scope applications (e.g. voice-call services) that produce no detectable deviation.
- T1124detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unusual system behaviour (including process injection), resource use deviations, and known attack characteristics, which can surface many T1124 discovery methods when they deviate from baseline; however the clause sets scope by organisational requirements rather than mandating universal coverage of every local/remote time-query vector (CLI, syscalls, GetTickCount, etc.), leaving a large slice of stealthy or in-process executions outside any given implementation.
- T1125detects — A.8.16 explicitly lists monitoring for anomalous behaviour, process injection, malware-associated activity, unauthorized access, and deviations from baseline (including resource use and executed code integrity), which surfaces many T1125 realizations in real time or near-real time; the remainder is silent or out-of-scope implementations that omit peripheral-device or API-call telemetry.
- T1127detects — A.8.16 explicitly lists process injection, anomalous system behaviour, code execution integrity checks, resource anomalies, and known attack patterns (including those matching trusted-developer-utility abuse) within its monitoring scope and baseline; this surfaces T1127 when it runs on monitored Windows systems, with the bounded remainder being execution outside the defined monitoring scope or before baseline tuning.
- T1127responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. process injection, unauthorized execution, unusual behaviour), alerting and dedicated response procedures directly enable containment/eradication once T1127 proxy execution is underway as an observable event; partial because scope is set by org requirements rather than mandating universal coverage of all developer utilities or LOLBAS.
- T1127.001detects — A.8.16 requires monitoring for anomalous behaviour (including process injection and deviations in standard protocols) and can surface MSBuild abuse when it deviates from the established baseline of normal system behaviour, but the clause sets the monitoring scope by organisational requirements rather than mandating universal coverage of all possible MSBuild inline task executions.
- T1127.001responds — A.8.16's real-time/periodic monitoring of system behaviour, process activity, resource use, and explicit anomalies such as process injection or unauthorized code execution surfaces T1127.001 once it runs, enabling the dedicated alert-response process the clause requires.
- T1127.002detects — A.8.16 explicitly lists process injection, anomalous process behavior, unauthorized code execution, and baseline deviations as monitoring targets, which would surface many (but not all) ClickOnce abuse indicators such as unexpected child processes of DFSVC.EXE or anomalous startup-folder activity; the remainder is implementation-dependent scope that may omit the specific technique.
- T1127.002prevents — A.8.16's baseline monitoring for anomalous behaviour, process injection indicators, unauthorized access, and real-time alerts can surface or constrain some ClickOnce abuse vectors (e.g. unusual child processes of DFSVC.EXE or startup-folder activity), but the control only sets a scoped monitoring requirement rather than blocking the technique's execution paths such as user-driven installation or rundll32 proxying.
- T1127.003detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unsigned/tampered code execution, resource anomalies, and baseline-deviant activity (including developer-tool abuse that deviates from normal build patterns) among the observables its monitoring scope and real-time/periodic tooling can surface; JamPlus script proxying is a detectable deviation but only when the chosen monitoring scope includes host/process telemetry rather than solely network/application layers, which the clause itself determines rather than mandates.
- T1129detects — A.8.16 explicitly lists process injection and anomalous system behaviour (including unusual code execution or resource patterns) among the monitored indicators, which surfaces many T1129 instances in real time or near-real time, but the clause sets scope by organisational requirements rather than mandating universal coverage of all module-loading calls or paths.
- T1129prevents — A.8.16's baseline monitoring for anomalous behaviour (incl. process injection, unauthorized code execution, resource anomalies, and known attack patterns) can surface or constrain some T1129 executions in real time, but the control only sets scope per requirements and does not mandate mechanisms that stop the module load itself.
- T1129responds — A.8.16 configures monitoring (incl. process injection, anomalous behaviour, resource use, code tampering) to surface T1129 once underway and generate tuned alerts for dedicated response personnel, but scope is set by org requirements so coverage of in-process module loads is not mandated.
- T1132detects — A.8.16 explicitly lists monitoring for anomalous network/application traffic, known attack characteristics, deviations in standard protocols, and baseline deviations that can surface encoded C2 (especially when it produces observable anomalies like unusual patterns or signatures), but the control's scope is set by organizational requirements rather than mandating detection of all encoding, leaving a large slice of stealthy or protocol-conformant encoding undetected.
- T1132.001detects — A.8.16 explicitly lists monitoring for anomalous network/application traffic, known attack characteristics, deviations in protocols, and baseline anomalies, which can surface encoded C2; however the clause sets scope by organisational requirements rather than mandating detection of every encoding scheme, leaving a large slice (e.g. novel or obfuscated encodings that blend with baseline) unreached.
- T1132.002detects — A.8.16 explicitly lists monitoring for anomalous network/application traffic, known attack characteristics, unusual system behaviour (including process injection and protocol deviations), and baseline deviations that can surface non-standard encoding in C2; however the clause sets scope by organisational requirements rather than mandating universal deep-packet or protocol-anomaly detection, so only a chosen slice is covered.
- T1133detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access/attempts, unusual system behaviour (including process injection), network traffic, and known attack patterns, which surfaces many T1133 manifestations (e.g. unexpected external connections, anomalous admin access, Tor hidden services, exposed unauthenticated services) once the baseline is established; it is only partial because the clause lets the organization set its own monitoring scope, so an implementation can be fully conformant while omitting the specific external-remote-service vectors an adversary actually uses.
- T1133responds — A.8.16 explicitly requires real-time/periodic monitoring, anomaly detection against baseline (including unauthorized access, process injection, known attack patterns), alert generation, dedicated trained personnel to respond to alerts, and timely procedures to minimize adverse effects once indicators appear, which matches the `responds` verb for an already-underway T1133 event; partial because the clause sets scope by business needs rather than mandating universal coverage of every remote-service vector (e.g., unauthenticated exposed APIs or Tor hidden services may fall outside chosen monitoring).
- T1134detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unusual user/system behaviour, resource use deviations, and security-tool/event logs as monitoring targets; token manipulation produces observable anomalies in process tokens, parent-child relationships, privilege escalations to SYSTEM, and related API calls that fall inside the defined baseline-comparison scope.
- T1134prevents — A.8.16's baseline monitoring for anomalous behaviour (incl. process injection, unusual system behaviour, unauthorized access attempts) can surface token manipulation in real time, but the clause only sets scope and detection — it does not stop the API calls, runas, or token theft from succeeding.
- T1134responds — A.8.16 configures monitoring (incl. process injection, anomalous behaviour, unauthorized access, and real-time alerts) to surface T1134 once underway, with dedicated trained personnel and procedures to respond per 5.26, though some token manipulations may evade detection before response.
- T1134.001detects — A.8.16 explicitly lists process injection and anomalous system behaviour (including deviations in use of standard protocols) among the anomalies its monitoring baseline and tools are configured to surface in real time; token impersonation/theft is a closely related Windows in-process privilege-escalation technique that can produce observable anomalies in access patterns, thread behaviour or token usage, but is not named and is only partially covered by the clause's scope-setting language and listed examples.
- T1134.001prevents — A.8.16's baseline monitoring for anomalous behaviour (incl. process injection, unusual system behaviour, access attempts, and code tampering checks) can surface token impersonation in real time on covered Windows systems, but the clause only sets scope per business needs and does not mandate the specific process-level instrumentation required to stop the technique from running.
- T1134.001responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection and deviations from baseline), which surfaces T1134.001 once it runs so dedicated personnel can respond per linked 5.26 procedures; partial because scope is set by organisational requirements rather than mandating host-level token monitoring, leaving some in-process impersonation outside the covered slice.
- T1134.002detects — A.8.16 explicitly lists process injection and anomalous system behaviour (including deviations from baseline) among the monitored items that generate alerts, which surfaces T1134.002 when it deviates from the established normal-behaviour baseline; however the clause's scope is set by organisational requirements rather than mandating universal coverage of every token-creation variant, leaving a slice determined by the implementer.
- T1134.002prevents — A.8.16's baseline-driven monitoring of process creation, resource use, anomalous behaviour and explicit examples such as process injection can surface or block some Windows token-use patterns before they fully succeed, but the clause only sets scope and does not mandate the specific mechanisms that stop CreateProcessWithTokenW or runas.
- T1134.002responds — A.8.16 configures monitoring (incl. process injection, anomalous behaviour, access attempts, resource use) to surface and alert on T1134.002 once underway, with dedicated response personnel and procedures (see 5.26) for timely containment/eradication; partial because scope is set by org requirements rather than mandating detection of every token-creation variant.
- T1134.003detects — A.8.16 explicitly lists process injection and anomalous system behaviour (including deviations in use of standard protocols) among the monitored anomalies, which surfaces T1134.003 when it produces observable deviations from the established baseline; however the clause sets scope by organisational requirements rather than mandating universal instrumentation, so an implementation monitoring only network/application layers remains conformant yet blind to token creation.
- T1134.003prevents — A.8.16's baseline monitoring for anomalous behaviour (incl. process injection, unauthorized access, unusual system behaviour) can surface token creation/impersonation in real time on covered Windows systems, but the clause only sets scope by org requirements so the technique runs unimpeded where that scope excludes it.
- T1134.003responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection and unauthorized access patterns) and requires dedicated trained personnel plus procedures to respond to positive indicators per 5.26, which bounds an in-flight T1134.003 once detected; partial because the clause sets scope by business requirements rather than mandating universal coverage of token-creation APIs or threads.
- T1134.004detects — A.8.16 explicitly lists process injection and unusual system behaviour as detectable anomalies via baseline monitoring of system activity, logs, and resource use, which can surface PPID spoofing when it deviates from expected parent-child relationships, but the clause sets scope by organisational requirements rather than mandating universal process-tree instrumentation, leaving some realisations (e.g. in unmonitored processes) unseen.
- T1134.004responds — A.8.16's real-time/periodic monitoring of process activity, baselines, and explicit anomalous behaviours (including process injection and unusual parent-child relationships) surfaces an in-flight PPID-spoofing technique so dedicated personnel can respond, but the clause itself performs only detection and alert generation while response lives in the cited 5.26 procedures.
- T1134.005detects — A.8.16 explicitly lists process injection and anomalous behaviour (including unusual system behaviour and unauthorized access) as items to baseline and monitor for in real time, which surfaces SID-History Injection when it manifests as observable anomalies; however the clause's scope is set by organisational requirements rather than mandating host-level visibility into every AD attribute write, leaving a slice determined by the implementer
- T1134.005responds — A.8.16's real-time/periodic anomaly detection, baseline comparison, and alert generation on indicators such as process injection or unauthorized access can surface SID-History Injection once underway, enabling timely response per linked 5.26 procedures, but the clause's scope is set by organizational requirements rather than mandating coverage of this specific AD manipulation.
- T1135detects — A.8.16 explicitly lists monitoring for anomalous behaviour including unauthorized access/attempts, unusual system behaviour (e.g. process injection), network traffic, and deviations from baseline (e.g. unusual access patterns or resource use); T1135's network share enumeration via SMB/commands is observable as anomalous traffic or access in scope, but the clause sets scope by org requirements so only a chosen slice is guaranteed to be instrumented rather than a bounded remainder.
- T1136detects — A.8.16 explicitly monitors for anomalous behaviour including unauthorized access/attempts, account-related events in logs, unusual user/system behaviour, admin config changes, and process/resource anomalies, which surfaces most instances of T1136 account creation across its broad platform scope once the baseline is established and alerts are tuned.
- T1136responds — A.8.16 requires real-time/periodic monitoring for anomalies (incl. unauthorized access, account-related events via logs, baselines, and alerts) plus dedicated response procedures that contain/eradicate once the create-account technique is underway, but scope is set by org requirements so coverage of all platforms/variants is not assured.
- T1136.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour including unauthorized access/attempts, admin-level config changes, unusual user/system behaviour, and process/command patterns that can surface local account creation (e.g. via net user, useradd, or kubectl) once the baseline is tuned, but scope is set by the organization so coverage of all platforms, vectors, and post-creation use is not assured.
- T1136.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour including unauthorized access/attempts, unusual user/system behaviour, admin-level config changes, and resource/performance deviations; domain account creation is a detectable anomaly once a baseline of normal account activity is established, but the control's scope is set by organisational requirements rather than mandating coverage of every account-creation vector, leaving a slice uncovered.
- T1136.003detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access (actual or attempted), unusual user/system behaviour, and baseline deviations that can surface cloud account creation when it deviates from established patterns, but the clause sets scope by organisational requirements rather than mandating universal coverage of cloud IAM events, leaving many stealthy or low-privilege creations outside the monitored slice.
- T1137detects — A.8.16 explicitly lists process injection, anomalous user/system behaviour, code execution integrity checks, and baseline-deviation monitoring (including Office startup anomalies if scoped in), which surfaces T1137 techniques in real time or periodically; however the clause's scope is set by organisational requirements rather than mandating coverage of all Office persistence vectors, leaving a large slice unseen.
- T1137.001detects — A.8.16 requires monitoring of anomalous behaviour (incl. process injection, unusual system behaviour, macro-related activity via logs/events from security tools, baselines of normal access/execution, and real-time alerts), which surfaces T1137.001 when it deviates from baseline or triggers signatures, but scope is set by the organization so coverage of this specific Office-template persistence vector is an implementer-chosen slice rather than a bounded remainder.
- T1137.001prevents — A.8.16's baseline of normal behaviour, real-time/periodic monitoring of system activity, file integrity (tamper checks on executed code), resource anomalies, and alerts on deviations (including process injection or unusual Office startup behaviour) can surface and thereby constrain the macro-persistence technique in some implementations, but the clause only sets scope-determined monitoring rather than mandating any specific mechanism that stops template abuse or macro execution at load time.
- T1137.002detects — A.8.16 requires monitoring of system activity, event logs, resource use, baselines for anomalies (incl. process injection and unauthorized access), and real-time/periodic alerting on deviations; this can surface the anomalous Office startup and Registry-driven DLL load after the fact, but the clause sets scope by org requirements rather than mandating coverage of this specific persistence vector, leaving a large slice of implementations that would miss it.
- T1137.003detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, unusual system behaviour, and deviations in protocols, which can surface the loading/execution of malicious Outlook forms as an anomaly against baseline; however the clause sets scope by organisational requirements rather than mandating coverage of client-application form loading, leaving a genuine slice uncovered.
- T1137.003responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (including process injection and unusual system behaviour), dedicated personnel to respond to alerts, and procedures to respond to positive indicators in a timely manner per 5.26; this bounds an in-progress T1137.003 execution once its anomalous loading or execution is detected, but the clause sets scope by organisational requirements rather than mandating universal detection of this specific persistence mechanism.
- T1137.004detects — A.8.16 explicitly lists process injection, anomalous user/system behaviour, and monitoring of application/system activity (including email clients like Outlook) as items to baseline and alert on, which surfaces this persistence technique when it runs; the remainder is that the clause sets scope by organisational requirements rather than mandating universal coverage of every possible Outlook folder load or external URL execution.
- T1137.004responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (incl. process injection, unauthorized access, malware-like activity) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26, which directly matches the `responds` verb once the Outlook Home Page persistence technique is underway; partial because the clause sets scope by business requirements rather than mandating universal coverage of this specific Office-suite technique.
- T1137.005detects — A.8.16 explicitly lists monitoring for anomalous behaviour, process injection, unusual system behaviour, and event logs from security tools, which can surface the loading/execution of malicious Outlook rules when they deviate from the established baseline, but the clause's scope is set by organisational requirements so coverage of this specific mailbox-persistence technique is not mandated.
- T1137.005prevents — A.8.16's baseline + anomaly detection (incl. unusual behaviour, process injection, malware patterns, unauthorized access) can surface the rule-loading or crafted-email trigger in real time, stopping the persistence technique from completing on monitored systems; scope is set by organisational requirements rather than mandating universal coverage of all Outlook/mailbox activity, leaving a genuine slice unreached.
- T1137.005responds — A.8.16 requires real-time/periodic monitoring of network, system, application traffic, logs, anomalous behaviour (incl. malware-associated activity and process injection), baseline deviations, and alert generation with dedicated response personnel; this surfaces and enables response to the crafted email trigger or rule execution once underway, but the clause's scope is set by org requirements so coverage of this specific mailbox/persistence vector is not assured.
- T1137.006detects — A.8.16 explicitly lists process injection, anomalous code execution, unauthorized access attempts, and baseline-deviant application behaviour (including at Office startup) among the monitored events it surfaces; this catches some but not all T1137.006 add-in persistence techniques depending on the chosen monitoring scope.
- T1137.006prevents — A.8.16 requires monitoring (incl. code execution authorization, tampering checks, process anomalies, and baseline deviations) that can surface add-in loading at startup, thereby preventing the persistence technique from completing its goal in monitored environments; however the clause sets scope by org requirements rather than mandating universal coverage of all Office add-in vectors.
- T1137.006responds — A.8.16's real-time/periodic monitoring of system behaviour, process execution, resource use, and anomalies (including process injection and unauthorized access) can surface the add-in's execution on Office start as an abnormal event, enabling response per linked 5.26 procedures; partial because scope is set by organisational requirements rather than mandating detection of all add-in types or Office-specific persistence.
- T1140detects — A.8.16 requires monitoring for anomalous behaviour and known attack characteristics (incl. process injection, malware activity, unusual system behaviour), which surfaces some T1140 instances (e.g. certutil, copy/type commands, or post-deobfuscation anomalies) when they match the baseline or signatures, but the clause sets scope by organisational requirements rather than mandating detection of every deobfuscation method or file, leaving a large slice of stealthy or user-driven cases unreached.
- T1140responds — A.8.16's real-time/periodic anomaly detection, baseline comparison, and alerts for malware-associated activity, process anomalies, or unauthorized behavior can surface T1140 once the deobfuscation runs and produces observable artifacts (e.g. certutil execution, unusual file ops), enabling timely response per linked 5.26; partial because many deobfuscations are silent, user-driven, or pre-execution and fall outside the monitoring scope an implementer may set.
- T1176detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, unusual system behaviour, and deviations in standard protocols, which can surface some T1176 manifestations (e.g. suspicious extension-driven network traffic, resource spikes, or post-install anomalies) once the baseline is tuned; however the clause sets scope by organisational requirements rather than mandating coverage of extension installation, marketplace trust, or benign-extension abuse, leaving a large slice of the technique (especially pre-execution or blended-in extensions) outside what is required.
- T1176.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, unusual system behaviour, and deviations in protocols, which surfaces many post-install effects of T1176.001 (e.g. background browsing, C2, resource spikes); it does not cover the silent file-modification or pre-execution installation vectors themselves, and scope is set by organisational requirements rather than mandating coverage of all extension loading.
- T1176.001prevents — A.8.16's real-time/periodic monitoring of network traffic, system behaviour, resource use, known attack patterns, process injection, unauthorized access, and anomalous deviations (plus baseline-based alerting) can surface many T1176.001 indicators once the extension loads or acts, thereby preventing successful persistence/C2/stealth use in monitored environments, but the control is silent on blocking installation vectors themselves and its scope is set by organisational requirements rather than mandating universal coverage.
- T1176.001responds — A.8.16 requires real-time/periodic monitoring of system behaviour, logs, processes, resource use and anomalies (including process injection and unauthorized access), plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26; this surfaces and acts on an in-progress T1176.001 extension once loaded and exhibiting anomalous behaviour, but the control's scope is set by organisational requirements rather than mandating universal coverage of all extension-install vectors or platforms.
- T1176.002detects — A.8.16 explicitly lists process injection, anomalous code execution, unauthorized access attempts, and deviations from baseline behaviour (including resource use and executed code integrity) among the anomalies its monitoring scope and real-time/periodic tooling must surface; IDE extension loading and its post-install execution fit inside those observables on the monitored host, but the clause's scope is set by organisational requirements rather than mandating universal coverage of every IDE or extension load.
- T1185detects — A.8.16 explicitly lists process injection, anomalous system behaviour, and deviations in standard protocols as detectable anomalies, and requires real-time/continuous monitoring of system, application, and network activity plus dedicated alert response; this surfaces many T1185 realizations (esp. injection into browser processes), but the clause sets scope by org requirements so an implementation can be fully compliant while missing the technique (e.g. no host telemetry).
- T1185prevents — A.8.16's real-time monitoring of processes, resource use, anomalous behaviour (explicitly naming process injection), unauthorized access, and known attack patterns can surface or block some session-hijacking techniques before they fully succeed, but the clause sets scope by organisational requirements rather than mandating universal coverage of all browser-injection vectors, leaving a large slice unaddressed.
- T1185responds — A.8.16 surfaces anomalous behaviour (process injection into browser, unusual network patterns, resource deviations) once the hijacking is underway and feeds it to 5.26 response procedures for containment/eradication; partial because the clause sets scope by organisational requirements rather than mandating universal coverage of all browser-process or proxy-pivot artefacts, and some realisations (e.g. silent certificate inheritance without observable deviation) stay outside monitored baselines.
- T1187detects — A.8.16 explicitly lists monitoring of network traffic, access attempts, anomalous behaviour (including process injection and deviations in protocols), resource use, and real-time alerts tuned to a baseline, which can surface forced SMB/WebDAV/EFSRPC authentication attempts as unusual outbound connections or access patterns; however the clause sets scope by organisational requirements rather than mandating universal coverage of all possible forced-auth vectors or endpoints.
- T1187prevents — A.8.16's real-time/periodic monitoring of network traffic, anomalous behaviour (incl. process injection, unauthorized access, known attack patterns), baselines, and alerts can surface forced SMB/WebDAV authentication attempts in flight, but does not stop the technique from triggering the outbound credential material or prevent the adversary from receiving the hash.
- T1187responds — A.8.16's real-time/periodic monitoring, anomaly detection (including unusual behaviour like process injection or unauthorized access), alerting, and procedures to respond to positive indicators directly enable containment/eradication once forced authentication (and its anomalous outbound SMB/WebDAV traffic) is underway, but scope is set by business requirements so coverage of this specific technique is not guaranteed.
- T1189detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, process injection, unauthorized access, malware-associated traffic, and real-time alerts on deviations from baseline, which surfaces many (but not all) observable indicators of a drive-by compromise in flight or post-delivery.
- T1189prevents — A.8.16's real-time/periodic monitoring of network traffic, system behaviour, known attack patterns (including drive-by indicators such as malicious domains, process injection, anomalous scripts), resource anomalies, and baseline deviations can block many T1189 executions before code execution succeeds, but the clause only sets scope per organisational requirements rather than mandating universal detection or blocking mechanisms, leaving a large slice of watering-hole or zero-day drive-bys outside any given implementation.
- T1189responds — A.8.16 requires real-time/periodic monitoring of network, system, application traffic, logs, anomalous behaviour (incl. process injection, malware patterns, unauthorized access), baseline deviations, and automated alerts with dedicated response personnel; this directly contains and eradicates an in-progress drive-by once the exploit delivers or executes on the endpoint, matching the `responds` verb, with a named remainder of pre-alert stealthy delivery steps.
- T1190detects — A.8.16 explicitly configures monitoring to surface anomalous behaviour including known attack characteristics, unauthorized access/attempts, unusual system behaviour (e.g. process injection), and deviations that would accompany successful or attempted exploitation of a public-facing app, but the clause sets scope by business requirements rather than mandating universal coverage of every Internet-facing socket or every possible exploit vector.
- T1190responds — A.8.16 requires real-time/periodic monitoring of network traffic, access attempts, anomalous behaviour (incl. known attack patterns, unauthorized access/scanning, process anomalies), baseline deviation detection, and dedicated trained personnel plus procedures to respond to positive indicators (explicitly referencing 5.26 incident response), which directly acts on an in-flight T1190 exploit attempt once underway to contain/eradicate it; mostly because scope is set by org requirements rather than mandating universal coverage of every possible public-facing app or edge device.
- T1195detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, malware-associated activity, process injection, unauthorized access, code tampering, and deviations from baseline (including in development or update contexts), which surfaces many supply-chain delivery or execution artifacts post-deployment; it does not address pre-receipt manipulation of development tools, source repositories, or physical supply-chain stages outside monitored systems.
- T1195.001detects — A.8.16 requires monitoring of network/system/application traffic, logs, resource use, baselines for anomalies, known attack patterns, unauthorized access/scanning, and malware-associated activity (including process injection and tampered code execution); this surfaces some supply-chain compromise indicators once manifested (e.g. anomalous CI/CD behavior or malicious dependency traffic) but leaves the pre-receipt manipulation of external dependencies/packages outside monitored scope in most implementations.
- T1195.002detects — A.8.16 explicitly lists monitoring for code tampering (f), unauthorized access/scanning, anomalous behaviour, known attack patterns, and baseline deviations that can surface supply-chain trojans post-delivery (e.g. via process injection, unexpected resource use, or malware-like activity), but the technique occurs pre-receipt in the upstream supply chain where no organizational monitoring reaches the manipulation itself or unsigned third-party builds before they are ingested.
- T1195.003detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection), resource deviations, and unauthorized access attempts, which can surface indicators of a hardware supply-chain backdoor once the tampered component is deployed and exhibits observable anomalies; however, the control's scope is limited to post-deployment runtime monitoring of traffic, logs, and behaviour, leaving pre-deployment supply-chain insertion itself outside its view.
- T1197detects — A.8.16 explicitly lists monitoring of network traffic, system activity, resource use, process anomalies, malware-associated behaviour and deviations from baseline (including process injection and unusual system behaviour), which can surface BITS job abuse in real time or near-real time; however the clause's scope is set by organisational requirements rather than mandating universal coverage of all BITS job creation/management paths, leaving a slice determined by the implementer
- T1197responds — A.8.16's real-time/periodic anomaly detection, baseline monitoring for unusual behaviour (including process injection and malware-like activity), alerting, and procedures to respond to positive indicators directly enable containment/eradication once a BITS abuse event is underway, but the clause's scope is set by organisational requirements rather than mandating universal coverage of BITS job creation/execution artefacts.
- T1199detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access attempts, unusual system behaviour (including process injection), access to systems/servers/critical apps, and deviations from baseline that can surface T1199 activity once underway (e.g. via compromised third-party accounts or anomalous traffic), but the clause sets scope by business requirements rather than mandating coverage of all third-party trust relationships or supply-chain access paths, leaving a large slice unseen.
- T1200detects — A.8.16 explicitly lists monitoring of inbound/outbound network traffic, access to systems/networking equipment, resource use, anomalous behaviour (including keystroke logging and process injection), and known attack characteristics, which would surface many hardware additions once connected and active; however the clause's scope is set by organisational requirements and does not mandate physical/port-level detection of the insertion act itself or pre-execution hardware not yet generating observable traffic/behaviour.
- T1201detects — A.8.16 requires monitoring of system/network/application activity, access attempts, configuration files, event logs, resource use, and anomalies (including unauthorized access/scanning and deviations from baseline), which can surface password-policy discovery commands or API calls when they match monitored patterns or baselines, but the clause's scope is set by organizational requirements rather than mandating coverage of every discovery vector (e.g. specific CLI utilities or cloud APIs), leaving a genuine slice unreached.
- T1202detects — A.8.16 requires monitoring for anomalous behaviour and explicitly lists process injection, unusual system behaviour, and deviations in standard protocols as detectable; T1202's stealthy proxying of execution through living-off-the-land binaries can surface in those observables when the monitoring scope includes them, but the clause's scope is set by organisational requirements rather than mandating coverage of all indirect execution vectors, leaving a large slice uncovered.
- T1203detects — A.8.16 explicitly configures monitoring to surface anomalous behaviour including process injection, malware-associated activity, known attack characteristics, unauthorized access attempts, and deviations from baseline that match the post-exploitation code execution and anomalous effects of T1203 exploitation.
- T1203responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (incl. process injection, malware activity, unauthorized access), alerting, and timely response procedures to minimize adverse effects once an exploit has executed and anomalous behaviour is underway.
- T1204detects — A.8.16 explicitly lists monitoring for anomalous behaviour, malware-associated activity, process injection, unauthorized access, unusual user/system behaviour, and real-time alerts on deviations from baseline, which surfaces many (but not all) forms of user execution such as running malicious documents or enabling RATs; it does not cover social-engineering delivery itself or every manual-execution vector outside monitored scope.
- T1204responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (incl. malware-associated activity, process injection, unauthorized access, unusual behaviour), alerting, and timely response procedures to minimize adverse-event impact once the user-execution technique is underway; this matches `responds` but is scoped only to what the chosen monitoring covers rather than guaranteeing containment/eradication of every instance.
- T1204.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, malware-associated activity, unusual system behaviour, and real-time alerts on deviations from baseline, which surfaces many (but not all) post-click execution indicators of T1204.001; the clause's scope is set by organisational requirements rather than mandating universal coverage of every link-click vector.
- T1204.001responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (incl. process injection, malware patterns, unauthorized access), alerting, and timely response procedures to minimize adverse effects once the technique has begun (e.g. after link click leads to execution or follow-on behavior).
- T1204.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, malware-associated activity, unauthorized access/execution attempts, unusual system behaviour, and real-time/periodic anomaly detection against baselines, which surfaces many (but not all) instances of a user executing a malicious file; the remainder is the slice where execution produces no observable deviation from the chosen monitoring scope.
- T1204.002prevents — A.8.16's real-time/periodic monitoring of traffic, logs, file execution authorization, resource anomalies, known attack patterns, and process injection can surface or block some malicious-file execution vectors (e.g., via IDS/IPS signatures or integrity checks), but the core reliance on user action/social engineering to open the file is outside its scope and remains unaddressed.
- T1204.002responds — A.8.16 configures real-time/periodic monitoring plus alerts for anomalous behaviour (including process injection, malware patterns, unauthorized access, and deviations from baseline), enabling timely response procedures per 5.26 once the malicious-file execution is underway; it does not itself contain or eradicate, and coverage is scoped by organisational requirements rather than universal.
- T1204.003detects — A.8.16 explicitly lists monitoring for process injection, malware-associated activity, anomalous system behaviour, unauthorized access, and deviations from baseline (including resource use and executed code integrity), which surfaces many runtime indicators once a malicious image deploys; it does not address the pre-execution image itself or the social-engineering/name-mimicry vector that leads to deployment.
- T1204.003responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. malware patterns, process injection, unauthorized access, resource anomalies), alerting, and timely response procedures to minimize adverse effects directly address containment/eradication once a malicious image executes in an IaaS/container environment, but only for the subset of observable post-execution indicators rather than the full technique (e.g., silent deployment or naming tricks).
- T1204.004detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unusual system behaviour, unauthorized access attempts, malware-associated activity, and deviations from baseline (with real-time/continuous tools and alerts), which surfaces many realisations of T1204.004 post-execution; it does not cover the social-engineering delivery or pre-execution paste itself, and scope is implementation-defined rather than universal.
- T1204.005detects — A.8.16's monitoring of system/network/application behaviour, resource use, code tampering, malware-associated activity and anomalies can surface malicious library execution or its effects (e.g. process injection, unusual behaviour), but the clause sets scope by organisational requirements rather than mandating detection of library installation or supply-chain compromise itself, leaving a large slice (pre-execution upload/typosquatting on external repos) outside any guaranteed coverage.
- T1205detects — A.8.16 explicitly lists monitoring of inbound/outbound traffic, unusual flags, known attack characteristics, anomalous network behaviour, and real-time signature/pattern recognition, which surfaces many forms of traffic signaling (port knocking, magic packets, unusual sequences); it does not cover all variants (e.g. raw-socket or embedded-device signaling outside monitored scope).
- T1205prevents — A.8.16's baseline-driven monitoring of network traffic, unusual flags/strings, known attack patterns, and anomalous behaviour (including port-scanning-like activity) can detect and thereby stop the signalling sequence before the hidden port opens or the malicious response triggers, but the clause sets scope by organisational requirements rather than mandating universal coverage of every signalling variant or embedded-device case.
- T1205responds — A.8.16's real-time/periodic monitoring of network traffic, anomalous patterns, known attack characteristics, and alerts feeds directly into 5.26 response procedures once the signaling packets or triggered behavior are observed on the estate; partial because the control's scope is set by organizational requirements (not all signaling is guaranteed to match the baseline or be in monitored layers) and the core response (containment/eradication) lives in the referenced 5.26 clause rather than in A.8.16 itself.
- T1205.001detects — A.8.16 explicitly lists monitoring of inbound/outbound network traffic, anomalous behaviour, known attack characteristics, and deviations in protocols, which can surface port-knocking sequences as unusual connection patterns or anomalies against baseline; however the clause's scope is set by organisational requirements rather than mandating universal packet-level instrumentation, leaving many stealthy implementations (raw sockets, custom non-network observables) outside what is required.
- T1205.001responds — A.8.16 configures monitoring (incl. network traffic, anomalous patterns, known attack characteristics, real-time alerts) that surfaces port-knocking sequences once they occur, enabling the dedicated response personnel and procedures (cross-referenced to 5.26) to contain/eradicate; partial because scope is set by org requirements and the clause does not mandate universal packet-level instrumentation that would catch every raw-socket or libpcap implementation.
- T1205.002detects — A.8.16 explicitly lists monitoring of inbound/outbound network traffic, anomalous behaviour (including process injection and deviations in protocols), resource use, and real-time/periodic anomaly detection against baselines, which can surface socket filter installation or triggered actions in some cases, but the technique's passive/low-activity/raw-socket nature is explicitly noted as difficult to detect and falls outside much of the listed scope.
- T1205.002responds — A.8.16's real-time/periodic monitoring of network traffic, anomalous behaviour, known attack patterns, and process injection (with alerts and dedicated response personnel) can surface socket filter installation or activation once the crafted packet arrives and triggers activity, but the technique's passive/low-activity nature, raw socket usage, and limited visibility explicitly noted in the source limit detection to a minority slice rather than the bulk.
- T1207detects — A.8.16 requires monitoring of logs, configuration files, system/network activity, resource use, and explicit anomalous behaviours including process injection and unauthorized access; rogue DC registration (creating AD schema objects via admin/KRBTGT privileges) can surface in those observables or deviate from baseline, but the technique is explicitly designed to bypass logging/SIEM sensors and the clause's scope is set by organisational requirements rather than mandating coverage of every AD replication vector.
- T1207responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unauthorized access, unusual AD-related activity via baselines and signatures) and requires timely response procedures once triggered, but the technique's explicit design to bypass logging/SIEM sensors and alter metadata creates a substantial unaddressed slice
- T1210detects — A.8.16 explicitly configures monitoring to surface anomalous behaviour including known attack characteristics (DoS, buffer overflows), process injection, unauthorized access/attempts, unusual system behaviour, and traffic patterns from malicious sources, which directly catches the observable indicators and execution of remote service exploitation (T1210) on the monitored estate; the bounded remainder is pre-compromise discovery or exploitation that produces no detectable anomaly within the organization's own systems, networks or logs.
- T1210prevents — A.8.16's real-time/periodic monitoring of network traffic, anomalous behaviour, known attack patterns (incl. buffer overflows, process injection, unauthorized access/scanning), and baselines can surface or block some T1210 exploitation attempts in flight, but does not stop the initial vulnerability exploitation itself or prevent all lateral movement vectors.
- T1210responds — A.8.16 surfaces anomalous behaviour (e.g. process injection, unauthorized access, known attack patterns, unusual system behaviour) that can occur during or after T1210 exploitation and hands it to the 5.26 response procedure, but the core of `responds` (containment/eradication of an already-underway event) is performed by the separate incident-response control, not by monitoring itself.
- T1211detects — A.8.16 requires monitoring for anomalous behaviour (incl. process injection, unusual system behaviour, known attack characteristics, and deviations from baseline) and can surface exploitation used to suppress logs or hide activity when it produces detectable telemetry, but the technique's core purpose is to operate inside trusted/unmonitored components or suppress telemetry itself, which evades the very monitoring the control configures.
- T1212detects — A.8.16 explicitly lists monitoring for process injection, anomalous system behaviour, known attack characteristics, malware-associated activity, unauthorized access attempts, and deviations from baseline (including resource use and executed code integrity), all of which surface T1212 exploitation in flight on the covered platforms; the named remainder is exploitation occurring entirely outside monitored estate or before a baseline exists.
- T1213detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access/attempts, unusual system behaviour (including process injection), access to critical systems/resources, and security-tool logs, which would surface many repository-access patterns or exfiltration; however the technique can be performed entirely via legitimate authorized access to a repository (no anomaly, no malware signature, no unauthorized scan), leaving a large slice of stealthy or insider uses undetected.
- T1213.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access/attempts, unusual system behaviour (including process injection), and security tool logs, which can surface Confluence data mining when it deviates from baseline (e.g. unusual access patterns or exfil-like activity); however the control's scope is set by organisational requirements and does not mandate coverage of every SaaS repository or internal wiki access.
- T1213.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access/attempts to protected resources, unusual system behaviour (including process injection), and access to critical systems/servers, which can surface SharePoint data mining when it deviates from baseline (e.g. unusual queries or access patterns); however the clause's scope is set by organisational requirements rather than mandating coverage of every repository or data-exfiltration technique, leaving a large implementer-chosen slice uncovered.
- T1213.003detects — A.8.16 explicitly lists monitoring for unauthorized access/attempts to systems or information, anomalous user/system behaviour, access to critical applications, and (via logs from security tools) events that can surface repository access or exfiltration of source/credentials once the technique is underway; this is genuine detection coverage but only a slice because the control's scope is set by organisational requirements rather than mandating instrumentation of every SaaS code repo interaction, and the technique can succeed silently without triggering the listed anomalies.
- T1213.004detects — A.8.16 explicitly lists monitoring for unauthorized access/attempts, anomalous user/system behaviour, access to critical applications, and resource/performance deviations; these can surface CRM mining post-compromise as an anomaly against baseline, but the clause's scope is set by organisational requirements rather than mandating coverage of every SaaS CRM instance or data-exfiltration pattern, leaving a large implementer-chosen slice uncovered.
- T1213.005detects — A.8.16 explicitly lists monitoring of network/application traffic, access to critical apps, event logs, anomalous user/system behaviour, and real-time alerts tuned to a baseline, which can surface misuse of messaging apps (e.g. unusual exfiltration or access patterns); however the clause's scope is set by organisational requirements rather than mandating coverage of every SaaS messaging channel or message content, leaving a large implementer-chosen slice uncovered.
- T1213.006detects — A.8.16 explicitly lists monitoring of database-relevant signals (access to critical applications/databases, event logs, unauthorized access attempts, anomalous user/system behaviour, resource use) and requires real-time/periodic anomaly detection against a baseline, which surfaces many instances of database mining; it is only partial because the clause sets scope by organisational requirements rather than mandating universal database telemetry, leaving some SaaS/cloud database access outside the monitored set as an implementer-chosen slice.
- T1216detects — A.8.16 explicitly lists process injection, anomalous system behaviour, code execution integrity checks, and baseline-deviation monitoring (including resource use and unsigned/tampered code), which surface T1216's proxy script execution when it deviates from the established baseline; however the clause's scope is set by organisational requirements rather than mandating universal coverage of all LOLBAS proxies or script-proxy artefacts, leaving a slice determined by the implementer.
- T1216responds — A.8.16's real-time/periodic monitoring of system behaviour, process execution, resource use, and anomalies (including process injection and unauthorized activity) surfaces T1216 once the proxy script runs, enabling timely response per linked 5.26 procedures; partial because the clause sets scope by organisational requirements rather than mandating universal depth on all LOLBAS proxies or script-proxy behaviours.
- T1216.001detects — A.8.16 requires monitoring for anomalous behaviour and explicitly lists process injection and deviations in protocols as example indicators, which can surface PubPrn abuse when it deviates from baseline; however the clause sets scope by organisational requirements rather than mandating universal coverage of this living-off-the-land technique, leaving real gaps (e.g. implementations that omit host/process telemetry).
- T1216.002detects — A.8.16 explicitly lists process injection, anomalous script/command execution, unusual system behaviour, and baseline-deviant resource or process activity as items its monitoring tools and alerts are configured to surface; SyncAppvPublishingServer.vbs abuse is a signed-script proxy technique that produces observable command-line, wscript, and PowerShell child-process artefacts falling inside those monitored categories, but the clause's scope is set by organisational requirements rather than mandating universal coverage of every LOLBin invocation, leaving a genuine slice unreached.
- T1216.002prevents — A.8.16's baseline monitoring for anomalous behaviour, process injection, unusual system behaviour, signed-script execution, and real-time alerts can surface (and thereby constrain) abuse of SyncAppvPublishingServer.vbs as a living-off-the-land proxy, but the clause only sets scope by organisational requirements rather than mandating universal detection of every possible invocation, leaving a genuine slice unreached.
- T1216.002responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unusual system behaviour, unauthorized access, and deviations from baseline), which surfaces T1216.002 once the signed script is abused to proxy execution; dedicated personnel and procedures then respond to those alerts per 5.26, but the clause itself only detects and notifies rather than performing containment/eradication.
- T1217detects — A.8.16 requires monitoring for anomalous behaviour (incl. process injection, unusual file access, malware patterns) and can surface T1217 when it deviates from baseline or matches signatures, but scope is set by the organization so many implementations will not instrument the specific local browser-file reads.
- T1218detects — A.8.16 requires monitoring for anomalous behaviour and explicitly lists process injection and deviations in standard protocols as detectable anomalies, which surfaces many (but not all) T1218 proxy-abuse executions; the clause's scope is set by organisational requirements rather than mandating universal coverage of every signed-binary proxy.
- T1218responds — A.8.16's real-time/continuous monitoring, anomaly detection (incl. process injection, unauthorized execution, unusual behaviour), alerting and dedicated response procedures directly enable containment/eradication once T1218 proxy execution is underway as an observable event.
- T1218.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unusual system behaviour, malware-associated activity, unauthorized access attempts, and deviations in standard protocols; these observables can surface T1218.001 execution via hh.exe or embedded payloads, but the clause's scope is set by organisational requirements rather than mandating coverage of all CHM abuse vectors, leaving a genuine slice uncovered.
- T1218.002detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized access attempts, and baseline-deviation monitoring (including resource use, executed code integrity, and real-time alerts), which surface many T1218.002 indicators once the technique runs; it does not guarantee coverage of every delivery vector or renamed-CPL registration outside the chosen monitoring scope.
- T1218.002prevents — A.8.16's baseline-driven continuous monitoring of system behaviour, process execution integrity, resource use, and anomalies (including process injection and unauthorized access) can surface or constrain many instances of control.exe abuse as anomalous activity, but the clause sets scope by organisational requirements rather than mandating universal coverage of all proxy-execution vectors, leaving a genuine slice unreached.
- T1218.002responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unauthorized execution, and deviations from baseline), which surfaces T1218.002 once underway for incident response per linked 5.26; it does not itself contain or eradicate the running technique.
- T1218.003detects — A.8.16 explicitly lists process injection, anomalous process termination, unusual system behaviour, signed-binary abuse patterns, resource anomalies, and real-time baseline monitoring of system activity, logs, and security tools, all of which surface CMSTP.exe proxy execution of malicious INF/DLL/SCT payloads on Windows.
- T1218.003responds — A.8.16 configures real-time/periodic monitoring, baselines, and alerts for anomalous behaviour (including process injection and unauthorized execution), enabling detection that feeds into timely incident response procedures per 5.26 once the CMSTP abuse is underway.
- T1218.004detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unsigned/tampered code execution, resource anomalies, and security-tool logs (including IDS/IPS) within its real-time baseline monitoring and alerting scope, which surfaces InstallUtil proxy execution when it deviates from the established baseline on a monitored Windows endpoint.
- T1218.004responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection and unauthorized execution patterns) and requires timely response procedures once an indicator is raised; this matches the `responds` verb for an already-underway technique, but only partially because the clause sets scope by organisational requirements rather than mandating universal coverage of all InstallUtil proxy-execution variants.
- T1218.005detects — A.8.16 explicitly lists monitoring for process injection, anomalous system behaviour, unauthorized code execution, resource anomalies, security-tool logs, and real-time alerting against baselines, which directly surfaces mshta.exe abuse as a trusted binary proxying malicious HTA/VBS/JS payloads.
- T1218.005prevents — A.8.16's baseline monitoring for anomalous behaviour, process injection, unauthorized execution, and real-time alerts can surface or constrain some mshta.exe abuse vectors (especially network-borne or resource-deviant ones), but the control only sets monitoring scope and does not mandate blocking or removal of the technique itself.
- T1218.005responds — A.8.16 surfaces anomalous behaviour (e.g. process injection, unusual system behaviour, malware-associated activity) once the mshta.exe proxy execution is underway and hands it to 5.26 response procedures; the core of `responds` (containment/eradication) is engaged only where the chosen monitoring scope includes the relevant host telemetry, which the clause itself determines rather than mandates.
- T1218.007detects — A.8.16 explicitly lists monitoring for process injection, anomalous system behaviour, unsigned/tampered code execution, resource anomalies, and security-tool/ event logs, all of which surface msiexec.exe proxying malicious payloads or DLLs as deviations from baseline.
- T1218.007responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. process injection, unauthorized execution, unusual behaviour), alerting and procedures to respond to positive indicators directly enable response once the msiexec abuse technique is underway, but scope is set by organisational requirements rather than mandating coverage of every possible msiexec invocation.
- T1218.008detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unsigned/tampered code execution, and baseline-deviant resource or process activity as items to monitor and alert on; odbcconf.exe proxying a DLL is observable as anomalous process behaviour or code execution but is a narrow, chosen slice of what the control's configurable scope actually instruments.
- T1218.008responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. process injection, unauthorized execution, unusual behaviour), alerting and dedicated response procedures directly enable response once the odbcconf.exe abuse is underway, but the clause sets scope by org requirements rather than mandating universal coverage of every signed binary or LOLBin invocation.
- T1218.009detects — A.8.16 explicitly lists process injection, anomalous system behaviour, code execution/tampering checks, resource use, security-tool logs, and real-time baseline monitoring for malware-like activity, all of which surface Regsvcs/Regasm proxy execution; the named remainder is non-monitored processes or implementations that omit host telemetry.
- T1218.009prevents — A.8.16's baseline monitoring for anomalous behaviour (including process injection, unauthorized code execution, and deviations in standard protocols) can surface the technique when it runs, but does not stop the signed utility from executing the registered code and therefore does not prevent the technique from running.
- T1218.009responds — A.8.16 configures monitoring (incl. process injection, anomalous behaviour, and alerts) that surfaces the technique once it runs, enabling timely response per linked 5.26 procedures; partial because scope is set by organisational requirements rather than mandating universal coverage of this specific proxy-execution vector.
- T1218.010detects — A.8.16 explicitly requires monitoring for anomalous behaviour including process injection, unusual system behaviour, execution of unauthorized code, and deviations from baseline (with real-time/continuous tooling, alerts, and dedicated response), which surfaces most Regsvr32 abuse (especially Squiblydoo network loads, anomalous DLL execution, and non-baseline regsvr32 activity); the bounded remainder is stealthy cases that perfectly mimic normal Windows allowlisted regsvr32 behaviour.
- T1218.010responds — A.8.16 surfaces anomalous behaviour (process injection, unusual system behaviour, malware-associated activity, unauthorized execution) in real time or near-real time and feeds it to the 5.26 response procedure; this engages the core of `responds` (containment/eradication once underway) for the in-process execution slice of T1218.010 but leaves the pre-execution proxying, COM scriptlet loading from URL, and persistence-via-hijacking aspects outside monitored observables or response scope.
- T1218.011detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized code execution, resource anomalies, security-tool logs, and real-time baseline deviation monitoring, all of which surface rundll32.exe proxying of malicious DLLs/scripts as observable anomalies or events.
- T1218.011prevents — A.8.16's real-time baseline monitoring of process activity, resource use, code integrity, and anomalous behaviours (including process injection and deviations in standard protocols) can stop many rundll32.exe abuse vectors from succeeding, but the clause sets scope by organisational requirements rather than mandating universal coverage of every possible proxy, masquerading, or signed-DLL variant, leaving a genuine slice unaddressed.
- T1218.011responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. process injection, unusual behaviour, malware patterns), alerting and procedures to respond to positive indicators directly engage an in-flight T1218.011 instance on monitored Windows systems, enabling containment/eradication once underway, but scope is set by org requirements so coverage of all possible rundll32 abuse is a chosen slice rather than bounded remainder.
- T1218.012detects — A.8.16 explicitly lists process injection, anomalous process termination, unusual system behaviour, and monitoring of system activity, access, and resource use as things its baseline-driven, real-time/periodic monitoring and alerting should surface; verclsid.exe abuse is a signed-binary proxy technique that can manifest in those observables, but the clause's scope is set by organisational requirements rather than mandating universal coverage of every COM/CLSID abuse path, leaving a genuine slice unreached.
- T1218.012prevents — A.8.16's baseline-driven anomaly detection (process injection, unauthorized execution, unusual system behaviour, signed-binary abuse) can surface verclsid.exe proxying in real time, but the control only sets monitoring scope and does not itself block the technique from running.
- T1218.012responds — A.8.16 configures monitoring (including process injection, anomalous binaries, and unauthorized execution) to generate real-time alerts on detected events, with dedicated personnel and procedures to respond to positive indicators per 5.26, but the clause itself stops at detection/alerting rather than performing containment/eradication.
- T1218.013detects — A.8.16 explicitly lists process injection and anomalous system behaviour (including deviations in standard protocols) among the monitored items and baseline anomalies, and requires real-time/periodic tools that surface such activity via alerts; however the clause sets scope by organisational requirements rather than mandating universal host-level instrumentation, so only the slice inside the chosen monitoring scope is detected.
- T1218.013prevents — A.8.16 requires monitoring for anomalous behaviour including process injection and deviations in standard protocols, which can surface mavinject.exe abuse when it deviates from the established baseline of normal system behaviour; however the control sets its own monitoring scope rather than mandating universal coverage of all processes or injection vectors, leaving a slice dependent on what the organisation chooses to instrument.
- T1218.013responds — A.8.16 surfaces process injection (explicitly listed as anomalous behaviour) and other signs of mavinject.exe abuse via real-time/periodic monitoring of system behaviour, resource use, logs and security-tool output, then feeds alerts to dedicated trained personnel and procedures that respond per 5.26; partial because the clause sets scope by organisational requirements rather than mandating universal coverage of every possible mavinject variant or unmonitored processes.
- T1218.014detects — A.8.16 requires monitoring of system/network/application behaviour, event logs, resource use, process termination, and anomalies such as process injection or unauthorized access; this can surface MMC.exe abuse when it deviates from baseline (e.g. unusual .msc execution or CLSID tampering), but the clause sets scope by organisational requirements rather than mandating universal coverage of all proxy-execution vectors, leaving a slice determined by the implementer
- T1218.014prevents — A.8.16's real-time/periodic monitoring of system behaviour, process activity, resource use, and anomalies (including process injection and unauthorized access) can surface or block some MMC abuse vectors that deviate from baseline, but the clause sets scope by organisational requirements rather than mandating universal coverage of all signed-binary proxy-execution paths, leaving a large slice of stealthy .msc/CLSID abuse undetected and unprevented.
- T1218.014responds — A.8.16's real-time/periodic monitoring of system behaviour, process anomalies, unauthorized access and known attack patterns (including process injection) surfaces an in-flight MMC abuse once it begins, enabling timely response per linked 5.26 procedures; partial because scope is set by organisational requirements rather than mandating universal coverage of all MMC/CLSID/proxy-execution vectors.
- T1218.015detects — A.8.16 requires monitoring for anomalous behaviour and explicitly lists process injection and unusual system behaviour as detectable indicators; Electron abuse (malicious JS, disguised child-process execution) can surface as such anomalies within the monitored baseline, but the clause sets scope by organisational requirements rather than mandating universal coverage of Electron-specific or in-memory JS execution vectors, leaving a large slice unseen.
- T1219detects — A.8.16 explicitly lists monitoring for anomalous behaviour, process injection, unusual system behaviour, access to systems/servers, network traffic, and deviations from baseline (including real-time alerts), which surfaces many legitimate RAT uses post-compromise; however, the clause sets scope by organisational requirements rather than mandating universal coverage of all RAT sessions or abuse of EDR features themselves, leaving a slice determined by the implementer.
- T1219prevents — A.8.16's baseline-driven anomaly detection (unusual traffic, process injection, unauthorized access, resource spikes, known C2 patterns) can surface and thereby block many legitimate-RAT uses before or during C2 establishment, but the clause only sets monitoring scope and does not mandate blocking, and many post-compromise RAT behaviors (e.g. signed desktop-support tools inheriting legitimate permissions) remain inside the allowed baseline.
- T1219responds — A.8.16 requires real-time/periodic monitoring of network traffic, access, logs, anomalous behaviour (including process injection and deviations), and alerts with dedicated response personnel per 5.26, which can contain/eradicate an already-underway RAT C2 session once detected as anomalous; however, the clause sets scope by requirements rather than mandating universal coverage of all possible RAT behaviors or installations, leaving a slice uncovered.
- T1219.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour, network traffic, process activity, resource use, and signatures/patterns that can surface IDE tunneling (e.g. unusual outbound sessions, process injection-like behaviour, or deviations from baseline developer workflows), but the clause's scope is set by organisational requirements rather than mandating coverage of all IDE/remote-dev channels, leaving a large slice of stealthy or whitelisted developer traffic unseen.
- T1219.001responds — A.8.16 requires real-time/periodic monitoring of network traffic, system activity, anomalous behaviour (including process injection and deviations in protocols), resource use, and alerts on thresholds, which can surface IDE tunneling once underway as an anomalous C2/persistence channel; however the clause sets scope by organisational requirements rather than mandating universal depth, leaving many legitimate-developer-workflow tunnels inside the baseline or outside monitored layers.
- T1219.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unusual system behaviour, unauthorized access attempts, resource use deviations, and known attack patterns, which can surface many instances of legitimate RMM tools used as C2 (especially when they deviate from baseline); however the clause's scope is set by organisational requirements rather than mandating universal coverage of all RMM traffic or processes, leaving a slice determined by the implementer.
- T1219.002responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (including process injection, unusual system behaviour, unauthorized access, and deviations from baseline) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26; this surfaces and acts on T1219.002 once underway (e.g. via anomalous remote desktop traffic or behaviour) but the clause sets scope by business needs rather than mandating universal coverage of all RMM tools or protocols, leaving a slice determined by the implementer
- T1219.003detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, unusual system behaviour, resource use deviations, and known attack characteristics, which can surface hardware-based remote access (e.g. via traffic, access logs, or baseline anomalies); however the clause sets scope by organisational requirements rather than mandating coverage of all physical/peripheral hardware channels, leaving a genuine slice of implementations that see nothing of post-compromise KVM use.
- T1220detects — A.8.16 requires monitoring of network, system, application traffic, logs, resource use, baselines of normal behaviour, and explicit anomalous indicators including process injection and deviations in standard protocols; this surfaces some (but not all) T1220 executions that produce observable anomalies while others (e.g. silent local msxsl.exe runs with no network or resource deviation) remain outside the clause's scoped, requirement-driven instrumentation.
- T1221detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unusual system behaviour, malware-associated traffic, known attack characteristics, and deviations in protocols, which surfaces template injection when it triggers observable anomalies or fetches; however the clause sets scope by organisational requirements so an implementation focused only on network/application layers (fully compliant) sees nothing of the document-level or RTF byte-level injection itself.
- T1222detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access attempts, changes to critical configuration files, resource anomalies, and known attack patterns; T1222 modifications of file/directory permissions (especially on config, binary, or ACL targets) are observable in event logs, access logs, and baseline deviations on the covered platforms.
- T1222.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access attempts, unusual system behaviour, and deviations from baseline (covering many T1222.001 indicators such as icacls/takeown usage or unexpected permission changes), but scope is set by organisational requirements rather than mandating coverage of all Windows file-permission activity.
- T1222.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access attempts, unusual system behaviour, and deviations from baseline (covering chown/chmod anomalies on Linux/macOS), but scope is set by the organization so coverage of this specific permission-modification technique is not mandated.
- T1480detects — A.8.16 requires monitoring for anomalous behaviour and explicitly lists process injection, unusual system behaviour, malware-associated activity, and deviations from baseline as detectable; guardrails often manifest via such checks (e.g. environment-specific values, user-agent filtering, or conditional execution), but this is scoped by organisational requirements rather than mandating coverage of all guardrail implementations or platforms.
- T1480.001detects — A.8.16's monitoring of anomalous behaviour, process injection, resource use, unauthorized access, malware-associated activity, and baseline deviations can surface environmental keying when its observable effects (e.g. unusual decryption, process anomalies, or network patterns) match configured signatures or thresholds, but the technique is explicitly designed to evade detection tools like AV/IDS and many of its checks (e.g. AD domain, files, system time) produce no detectable deviation from the baseline.
- T1480.002detects — A.8.16 explicitly lists process injection, anomalous system behaviour, malware-associated activity and deviations from baseline as monitoring targets, which can surface mutex-based single-instance checks when they produce observable anomalies (e.g. unusual process starts or resource use); coverage is only a slice because mutex acquisition itself is typically silent and many implementations stay inside the named remainder of unmonitored host telemetry.
- T1482detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access attempts, unusual system behaviour, and deviations in protocols, which can surface domain trust enumeration via tools like nltest or LDAP queries when they deviate from the established baseline of normal access patterns; however the clause's scope is set by organisational requirements rather than mandating coverage of all discovery activity, leaving a large slice of stealthy or low-and-slow T1482 executions outside monitored telemetry.
- T1484detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access attempts, unusual system behaviour (including process injection), admin-level configuration changes, and deviations from baseline (e.g. via real-time/periodic tools and alerts), which surfaces many T1484 indicators in AD/tenant environments; however the clause's scope is set by organisational requirements rather than mandating coverage of all domain-policy or cross-tenant modifications, leaving a genuine implementation-dependent slice unreached.
- T1484responds — A.8.16's real-time/periodic anomaly detection, baseline comparison, and alerts for events like unauthorized access, configuration changes, or unusual behaviour can surface an in-progress T1484 modification (or its immediate effects) once underway, enabling the dedicated response personnel and procedures (cross-referenced to 5.26) to contain/eradicate; partial because the clause sets scope by org requirements rather than mandating universal coverage of all domain/tenant policy objects or stealthy/temporary mods.
- T1484.001detects — A.8.16 explicitly lists monitoring of critical/admin configuration files, event logs, unauthorized access attempts, anomalous system behaviour (including process injection), and deviations from baseline (e.g. unusual access patterns or resource use); GPO modification touches SYSVOL configuration files and produces detectable AD events, but the clause's scope is set by organizational requirements rather than mandating coverage of every GPO edit, leaving a slice determined by the implementer
- T1484.001prevents — A.8.16's real-time/periodic monitoring of network traffic, access to critical files (including SYSVOL paths), configuration changes, admin activity, baselines for anomalies, and explicit detection of unauthorized access/scanning directly surfaces many GPO modifications in flight or shortly after, preventing the downstream privilege-escalation or chained techniques from succeeding in many cases; it is only partial because the clause sets scope by organizational requirements rather than mandating universal coverage of every possible GPO edit vector or pre-modification block.
- T1484.001responds — A.8.16's real-time/periodic monitoring, anomaly detection (including unauthorized access, config-file changes, process anomalies, and known attack patterns), alerting, and procedures to respond to positive indicators directly address an in-progress GPO modification once it triggers observable events, containing or eradicating the actor's actions per the incident-response boundary of `responds`; partial because the clause's scope is set by organizational requirements rather than mandating universal coverage of all GPO paths or stealthy modifications.
- T1484.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access/attempts, unusual system behaviour (including process injection), admin-level config changes, and known attack patterns, which surfaces some trust modifications (esp. in AD/IdP environments) but leaves a large slice of cloud/tenant trust changes outside typical baseline scope and tooling.
- T1484.002responds — A.8.16's real-time/periodic anomaly detection, baseline monitoring for unusual behaviour (incl. process injection, unauthorized access, config changes), alerting and procedures to respond to positive indicators directly enable containment/eradication once trust manipulation is underway, but scope is set by org requirements so coverage of identity-provider or cloud trust mods is not assured.
- T1485detects — A.8.16 explicitly lists monitoring for anomalous behaviour, malware-associated activity, known attack characteristics, unusual system behaviour (including process injection), resource anomalies, unauthorized access, and deviations from baseline, all of which surface T1485 in flight or at execution; the named remainder is stealthy or non-anomalous destruction that evades the configured scope.
- T1485responds — A.8.16's real-time/continuous monitoring, anomaly detection (incl. unusual behaviour, resource overloads, unauthorized access), alerting, and procedures to respond to positive indicators directly enable containment/eradication once data destruction is underway, per the event-lane definition of responds.
- T1485.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access, unusual system behaviour (including process injection), resource use, and event logs from security tools and cloud-relevant activity; this surfaces lifecycle policy changes and mass-deletion patterns once they occur, but the clause's scope is set by organisational requirements rather than mandating coverage of every cloud storage API call or bucket policy mutation, leaving a genuine implementation-chosen slice unreached.
- T1486detects — A.8.16 explicitly configures monitoring against a baseline to surface anomalous behaviour including activity typically associated with malware, known attack characteristics, unusual system behaviour (e.g. process injection), unauthorized access, and deviations that ransomware encryption produces (resource spikes, mass file changes, unplanned terminations); this surfaces the technique in flight or its immediate effects, with the named remainder being fully stealthy or out-of-scope implementations.
- T1486recovers — A.8.16 only detects and alerts on anomalous behaviour (including ransomware indicators) and feeds 5.26 response procedures; it performs no recovery of encrypted data or system state.
- T1486responds — A.8.16 requires real-time/continuous monitoring for anomalous behaviour (incl. malware patterns, unauthorized access, unusual system behaviour, resource anomalies) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26, which directly matches the EVENT-LANE definition of responds (containment/eradication once the ransomware technique is underway); mostly because the clause sets scope by org requirements rather than mandating universal coverage of every T1486 vector (e.g. cloud SSE-C or hypervisor encryption may fall outside chosen monitoring).
- T1489detects — A.8.16 explicitly lists monitoring for anomalous behaviour including unplanned termination of processes, unusual system behaviour (e.g. process injection), resource use deviations, and known attack characteristics, which directly surfaces service-stop activity once it occurs.
- T1489responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. unplanned terminations, unauthorized access, unusual behaviour), alerting and procedures to respond to positive indicators directly enable timely response once service-stop is underway, but the clause's scope is set by org requirements rather than mandating coverage of all service-stop vectors (e.g. cloud API calls, non-monitored processes).
- T1491detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unauthorized access/attempts, unusual system behaviour (including process injection), and real-time alerts on deviations from baseline, which surfaces many T1491 instances once they alter visible content or trigger related anomalies; however the clause's scope is set by organisational requirements rather than mandating coverage of every defacement vector (e.g. external website changes or non-monitored IaaS resources), so only a chosen slice is guaranteed.
- T1491responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (including unauthorized access and unusual behaviour), alert generation, and dedicated personnel/procedures to respond to positive indicators in a timely manner per 5.26, which directly matches the `responds` verb once defacement (a realised integrity-impacting event) is underway; partial because the clause's scope is set by organisational requirements rather than mandating universal coverage of all defacement vectors (e.g. external website changes may fall outside monitored internal baselines).
- T1491.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection and deviations), resource/performance anomalies, unauthorized access, and real-time/continuous monitoring with alerts; internal defacement produces visible, logged changes to websites, login messages, desktops or files that deviate from baseline and are observable in the enumerated scopes (config files, event logs, system behaviour, resource use).
- T1491.001responds — A.8.16 requires real-time/periodic monitoring for anomalies (including unauthorized access, unusual behavior, and tampering indicators), dedicated alert response personnel, and timely procedures that align with 5.26 incident response to contain or eradicate an ongoing internal defacement once underway; partial because the clause sets scope by business needs rather than mandating universal coverage of all defacement vectors (e.g., post-compromise wallpaper changes on unmonitored endpoints).
- T1491.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unauthorized access/scanning, and unusual system behaviour (including deviations that could surface post-defacement), but its scope is set by organisational requirements rather than mandating coverage of all external defacement on IaaS/websites, leaving a large slice unreached.
- T1491.002responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (including unauthorized access, changes to config/files/code, and unusual behavior), alerts, and timely response procedures to minimize adverse effects once an incident is underway; this surfaces and contains external defacement of websites but does not address the realized impact (e.g., altered content, lost trust) which is bounded to the recovery lane.
- T1495detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, malware-associated activity, unusual system behaviour, resource anomalies and known attack characteristics, which can surface many T1495 indicators in real time or near-real time; however the technique's low-level firmware overwrite on non-volatile memory (especially pre-boot or on network devices) frequently evades the host-centric, OS-visible monitoring scope the control sets.
- T1496detects — A.8.16 explicitly requires monitoring of resource use (CPU, disks, memory, bandwidth) and performance against a normal baseline, plus anomalies such as overloads, bottlenecks, and unusual system behaviour; this surfaces the bulk of resource-hijacking techniques (cryptomining, bandwidth proxying, spam floods) while the named remainder is hijacking that stays inside normal thresholds or outside the organisation-defined monitoring scope.
- T1496prevents — A.8.16's baseline of normal resource use (CPU, disks, memory, bandwidth) and real-time/periodic anomaly detection directly stops many hijacking forms (cryptomining, proxying, spam floods) from continuing once they deviate from the baseline, but the clause sets scope by business requirements rather than mandating universal coverage of all hijacking vectors or platforms, leaving a genuine slice unreached.
- T1496responds — A.8.16 surfaces anomalous resource consumption (CPU, memory, bandwidth, bottlenecks, overloads) and unusual behaviour such as process injection or deviations from baseline, enabling the incident response procedure (5.26) to contain/eradicate an in-progress hijacking; partial because the clause sets scope by business requirements rather than mandating universal coverage of every hijacking vector (e.g. SMS spam or proxy selling may fall outside monitored systems).
- T1496.001detects — A.8.16 explicitly requires monitoring of resource use (CPU, disks, memory, bandwidth), performance baselines, anomalies such as overloads/bottlenecks/latency/jitter, and unusual system behaviour, directly surfacing compute hijacking's resource-consumption signature in real time or near-real time.
- T1496.001prevents — A.8.16 mandates monitoring of resource use, performance baselines, and anomalies (including high CPU/memory consumption, process termination, and deviations from normal behaviour) that directly surface compute hijacking in flight, but the clause only sets requirements for scope and tooling rather than mandating any blocking or prohibition mechanism that stops the technique from running.
- T1496.001responds — A.8.16 configures real-time/periodic monitoring of resource use (CPU, disks, memory, bandwidth), performance baselines, anomalies (bottlenecks, overloads, unusual behaviour), and generates tuned alerts for dedicated trained personnel to respond per 5.26 procedures, directly addressing in-flight compute hijacking once underway.
- T1496.002detects — A.8.16 explicitly requires monitoring of network traffic, resource use (including bandwidth), performance baselines, anomalies such as overloads/latency/jitter/bottlenecks, and malware-associated behaviour, directly surfacing bandwidth hijacking when it deviates from the established baseline.
- T1496.002prevents — A.8.16 requires monitoring (incl. network traffic, resource use, baselines, and anomalies such as botnet C2, unusual bandwidth consumption, or scanning) that can block some Bandwidth Hijacking vectors before impact, but the clause only sets scope per business needs and does not mandate enforcement mechanisms that stop the technique outright.
- T1496.002responds — A.8.16 requires real-time/periodic monitoring for anomalies (including bandwidth overuse, botnet C2 traffic, unusual resource consumption, and known attack patterns), dedicated alert response personnel, and timely procedures that align with 5.26 incident response to contain and eradicate an in-flight bandwidth-hijacking event.
- T1496.003detects — A.8.16 explicitly lists monitoring for anomalous resource use (CPU, bandwidth, etc.), baseline deviations, unusual system behaviour, bottlenecks/overload, and real-time alerts on patterns, which surfaces SMS-pumping-induced traffic floods or cost spikes; partial because the clause's scope is set by organisational requirements and the listed items focus on system/network/application layers rather than external telecom-provider billing or SMS-specific pumping signatures.
- T1496.003responds — A.8.16 requires real-time/periodic monitoring for anomalies (including resource overloads, unusual traffic/behaviour, and alerts with dedicated response personnel per 5.26), which can surface and trigger response to SMS-pumping-induced overloads or cost spikes once underway, but the clause's scope is set by org requirements rather than mandating coverage of SaaS messaging/OTP abuse specifically.
- T1496.004detects — A.8.16 explicitly lists monitoring of resource use/performance, anomalous behaviour against baseline (including overloads, unusual system behaviour, and known attack patterns), plus real-time/continuous tools that generate tuned alerts; this surfaces SaaS hijacking via anomalous consumption or LLMJacking signatures in some cases, but the clause's scope is set by organisational requirements so coverage of cloud/SaaS-specific hijacking remains an implementer-chosen slice rather than a bounded remainder.
- T1496.004prevents — A.8.16's real-time/periodic monitoring of traffic, resource use, baselines, anomalies (e.g. overloads, unusual behaviour, known attack patterns) and alerting can surface and thereby stop some hijacking in flight before full impact, but the clause sets scope by org requirements rather than mandating universal coverage of all SaaS/LLM abuse vectors, leaving a large slice unaddressed.
- T1496.004responds — A.8.16's real-time/periodic monitoring, anomaly detection against baseline (including resource use, unusual behaviour, and alerts), and procedures to respond to positive indicators in a timely manner (cross-referenced to 5.26 incident response) allow response to an in-progress hijacking once anomalous resource consumption or service behaviour is observed, but the clause's scope is set by organisational requirements rather than mandating coverage of all SaaS/LLM abuse patterns.
- T1497detects — A.8.16 requires monitoring for anomalous behaviour and known attack characteristics including process injection and deviations, which surfaces some sandbox-evasion artifacts and checks (e.g. monitoring-tool presence, unusual resource use, or malware-like loops), but the technique's core VME/sandbox discovery methods and pre-payload decisions largely occur before or outside the monitored runtime baseline, leaving most of the class undetected.
- T1497.001detects — A.8.16's monitoring of system behaviour, resource use, processes, network traffic and anomalies (including process injection or deviations) can surface some T1497.001 checks as anomalous activity in real environments, but the technique is explicitly designed to run silently in analysis/sandbox setups where such monitoring is absent or out of scope, and the clause itself sets scope by organisational requirements rather than mandating universal coverage of discovery behaviours.
- T1497.002detects — A.8.16 requires monitoring for anomalous behaviour and explicitly lists process injection, unusual user/system behaviour, resource use, and deviations from baseline (including mouse/keyboard patterns or expected interaction), which can surface many T1497.002 checks; however the clause sets scope by organisational requirements rather than mandating universal coverage of all possible user-activity artifacts or sandbox-evasion logic, leaving a slice determined by the implementer
- T1497.003detects — A.8.16 requires monitoring for anomalous behaviour (including process injection, unusual system behaviour, resource use, and deviations from baseline), which can surface time-based sandbox checks as anomalous API calls, timing deviations or resource patterns, but the clause's scope is set by organisational requirements rather than mandating coverage of this specific anti-analysis technique.
- T1498detects — A.8.16 explicitly requires monitoring for anomalous behaviour including known attack characteristics (e.g. denial of service), unusual system behaviour, bottlenecks/overload (latency, jitter, queuing), and traffic patterns, with real-time/continuous tools, baselines, and alerts; this surfaces Network DoS in flight for most cases, with the bounded remainder being attacks below detection thresholds or outside the scoped monitoring.
- T1498prevents — A.8.16 mandates real-time/periodic monitoring of network traffic, known attack characteristics (explicitly including denial of service), anomalous behaviour, and baselines that can trigger alerts to stop or deter a Network DoS before full exhaustion occurs, but the control only sets scope by requirements rather than mandating universal detection or blocking mechanisms, leaving many volumetric DDoS cases (e.g., external saturation before internal monitoring) outside its reach.
- T1498responds — A.8.16 explicitly requires real-time/periodic monitoring for known attack characteristics (including denial of service), anomalous traffic/behaviour, and generating tuned alerts so dedicated personnel can respond via defined procedures (cross-referenced to 5.26 incident response) once the Network DoS is underway, bounding impact; mostly because scope is set by organisational requirements rather than mandating universal coverage of every possible vector.
- T1498.001detects — A.8.16 explicitly requires monitoring of inbound/outbound network traffic, resource performance (CPU/bandwidth/overload), known attack characteristics (DoS), anomalous behaviour against baseline, and real-time alerting on signatures/patterns that match high-volume flooding, directly surfacing the technique in flight.
- T1498.001prevents — A.8.16 mandates real-time/periodic monitoring of inbound/outbound network traffic, baselines, known attack patterns (incl. DoS and overloads), and anomaly detection with alerts, which can prevent some direct network floods from succeeding by enabling early blocking; however, the control only sets requirements for monitoring scope and tools rather than mandating universal preventive mechanisms, leaving many high-volume botnet floods (where distinction from legitimate traffic is hard) unstopped.
- T1498.001responds — A.8.16 explicitly requires real-time/continuous monitoring for known attack characteristics (DoS, buffer overflows), anomalous traffic/behaviour, resource overloads, and timely procedures to respond to positive indicators (see 5.26), which directly matches responding to a network flood once underway; the named remainder is that pure volumetric saturation from massive botnets can still overwhelm detection/response capacity before action completes.
- T1498.002detects — A.8.16 explicitly requires monitoring of inbound/outbound network traffic, known attack characteristics (e.g. denial of service), anomalous behaviour, and real-time alerts against a baseline, which directly surfaces Reflection Amplification floods when they occur.
- T1498.002prevents — A.8.16 mandates real-time/periodic monitoring of inbound/outbound network traffic, known attack characteristics (explicitly including denial of service), anomalous behaviour, and baselines that surface reflection/amplification patterns, which can block the technique from succeeding when alerts trigger preventive action; it is only a slice because the clause sets scope by organisational requirements rather than mandating universal blocking mechanisms.
- T1498.002responds — A.8.16 surfaces anomalous traffic patterns, known attack characteristics (DoS, buffer overflows), and unusual network behaviour in real time, feeding alerts to the 5.26 response procedure for containment; partial because the control's scope is set by organisational requirements and many reflection amplifiers lie outside the monitored estate, so the event on the target may not be visible until impact is already realised.
- T1499detects — A.8.16 explicitly requires monitoring for anomalous behaviour including resource exhaustion (CPU, memory, bandwidth, bottlenecks, overloads), known attack characteristics (DoS, buffer overflows), unusual system behaviour (process injection, deviations), and baseline deviations that directly surface Endpoint DoS techniques across the listed platforms.
- T1499prevents — A.8.16's baseline-driven continuous monitoring for anomalies (resource exhaustion, bottlenecks, overloads, unusual behaviour, known attack patterns) can stop some endpoint DoS techniques from completing or succeeding when they cross detection thresholds, but the clause sets scope by organisational requirements rather than mandating universal coverage of all layers, vectors or botnet-scale attacks, leaving a large slice unaddressed.
- T1499responds — A.8.16 surfaces anomalous resource consumption, process crashes, overloads, and known attack patterns (including DoS and process injection) in real time and feeds them to 5.26 response procedures, but its core mechanism is detection/monitoring rather than containment or eradication once the technique is underway, and several T1499 vectors (e.g. pure resource exhaustion without detectable signature) sit outside its configured baseline.
- T1499.001detects — A.8.16 explicitly requires monitoring for known attack characteristics (DoS, buffer overflows), anomalous resource use (CPU/memory/bandwidth overloads, bottlenecks), unusual system behaviour (including deviations in protocols), and inbound/outbound traffic, directly surfacing OS-exhaustion floods such as SYN/ACK floods against the established baseline.
- T1499.001prevents — A.8.16 mandates real-time/periodic monitoring of network traffic, resource use, known attack characteristics (explicitly including denial of service), anomalous behaviour, and baselines that can trigger alerts on SYN/ACK floods or OS-exhaustion patterns, thereby stopping many (but not all) instances before full impact.
- T1499.001responds — A.8.16 surfaces the anomalous resource exhaustion, overloads, and known attack patterns (DoS, protocol deviations) in real time via monitoring and alerting, feeding directly into 5.26 response procedures for containment/eradication once the flood is underway; partial because the clause sets scope by business needs rather than mandating universal coverage of all OS-exhaustion vectors or platforms, and core response actions (contain/eradicate) sit in the referenced 5.26 rather than in monitoring itself.
- T1499.002detects — A.8.16 explicitly requires monitoring for anomalous behaviour including known attack characteristics (DoS, buffer overflows), bottlenecks/overload (network queuing, latency, jitter), resource use deviations, and unusual system behaviour, directly surfacing service exhaustion floods against the established baseline.
- T1499.002prevents — A.8.16 mandates real-time/periodic monitoring of network traffic, resource use, known attack patterns (DoS, buffer overflows), anomalous behaviour and baseline deviations that surface many Service Exhaustion Flood indicators (e.g. HTTP floods, SSL renegotiation volume, overloads), but the clause only detects and alerts rather than stopping the flood from exhausting the service, and its scope is set by organisational requirements rather than mandating universal coverage of every possible exhaustion vector.
- T1499.002responds — A.8.16 surfaces anomalous resource consumption, overloads, bottlenecks, and known attack patterns (including DoS floods) in real time and feeds them to 5.26 response procedures, but its core mechanism is detection/monitoring rather than containment or eradication once the flood is underway.
- T1499.003detects — A.8.16 explicitly requires monitoring for resource use/performance, baselines of normal behaviour, and anomalies including bottlenecks/overload, unusual system behaviour, and known attack characteristics such as DoS; this surfaces T1499.003 in flight across the listed platforms with only a bounded remainder (unmonitored resources outside the defined scope).
- T1499.003prevents — A.8.16 requires establishing a baseline of normal resource use/performance and monitoring for anomalies including bottlenecks, overloads, resource exhaustion patterns, and known attack characteristics such as DoS; this can prevent the technique from succeeding when detected early enough to act, but the clause sets scope by business requirements rather than mandating universal coverage of all application features or traffic, leaving a slice uncovered.
- T1499.003responds — A.8.16 surfaces anomalous resource consumption, overloads, and application behaviour matching the flood (via baselines, real-time monitoring, and alerts on CPU/memory/bandwidth bottlenecks), handing the event to 5.26 response procedures for containment/eradication once underway; partial because the clause sets scope by organisational requirements rather than mandating universal coverage of all application-exhaustion vectors or guaranteeing eradication of every instance.
- T1499.004detects — A.8.16 explicitly lists monitoring for known attack characteristics (DoS, buffer overflows), unplanned terminations, unusual system behaviour (including process injection), resource bottlenecks/overload, and deviations from baseline, which surfaces many application/system exploitation attempts in real time; however the clause's scope is set by organisational requirements rather than mandating coverage of every possible exploit vector or zero-day, leaving a genuine slice unseen.
- T1499.004prevents — A.8.16's baseline monitoring for anomalies (including unplanned terminations, known attack characteristics like buffer overflows, unusual system behaviour, and resource bottlenecks) can surface or constrain some exploitation attempts that produce detectable crashes or deviations before they fully deny availability, but it does not stop the vulnerability from being exploited or the initial crash from occurring.
- T1499.004responds — A.8.16 surfaces anomalous behaviour (crashes, unplanned terminations, resource overloads, known attack patterns) once the exploitation is underway and feeds it to 5.26 response procedures, but its core mechanism is detection and alerting rather than containment/eradication actions that `responds` names on the event lane.
- T1505detects — A.8.16 explicitly lists monitoring for process injection, unauthorized code execution/tampering, anomalous system behaviour, and baselines of normal activity, which surfaces many T1505 artifacts in real time or near-real time; the remainder is the slice of installations that produce no observable deviation from the chosen monitoring scope (e.g. on unmonitored network devices or via extensions that mimic legitimate behaviour).
- T1505.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, unusual system behaviour, malware-associated activity, and deviations in protocols, which surfaces many (but not all) indicators of malicious stored-procedure persistence once it is invoked or executes; the clause's scope is set by organisational requirements rather than mandating universal coverage of database-specific or CLR-assembly artefacts.
- T1505.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour, process injection, unauthorized access, code tampering, event logs, and network/application traffic that can surface a malicious transport agent once registered and invoked, but the control's scope is set by the organization so it does not guarantee coverage of this Exchange-specific persistence technique.
- T1505.003detects — A.8.16 explicitly lists monitoring for process injection, unauthorized access, anomalous system behaviour, known attack characteristics, security-tool logs, event logs, resource use, and code-tampering checks; web-shell deployment and use produce observable artifacts (e.g. anomalous web-server processes, file writes, traffic patterns, or execution anomalies) that fall inside the defined baseline-and-alert scope, with only a bounded remainder (e.g. fully stealthy or out-of-scope network-device shells) left unreached.
- T1505.003prevents — A.8.16's real-time/periodic monitoring of traffic, access, logs, code execution integrity, resource use, and explicit anomalies (process injection, unauthorized access, malware traits) can surface web shell placement or activity before persistence is fully leveraged, but the clause sets scope by org requirements rather than mandating universal detection of all web shell upload vectors or dormant shells.
- T1505.003responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (incl. process injection, unauthorized access, malware patterns) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26, which directly matches the `responds` verb once a web shell is present and active; partial because the clause sets scope by business requirements rather than mandating universal detection of every web shell variant.
- T1505.004detects — A.8.16 explicitly lists monitoring of network/application traffic, access to critical systems/servers, security tool logs (incl. IDS/IPS/firewalls), anomalous behaviour patterns (incl. process injection and deviations), and real-time/continuous tools that surface indicators; this catches many post-installation effects of a malicious IIS component but not the initial installation act itself on an unmonitored IIS server, which is a slice chosen by scope rather than a bounded remainder.
- T1505.005detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized access attempts, and monitoring of critical system files/configs/logs as detection targets; the termsrv.dll modification or replacement (a form of tampering with a critical system DLL to enable persistence) can surface as one of those observables when the monitoring scope includes it, but the clause sets scope by organisational requirements rather than mandating coverage of this specific persistence vector.
- T1505.006detects — A.8.16 explicitly lists monitoring for anomalous behaviour, process injection, unauthorized access, system configuration changes, resource anomalies, and known attack patterns, which can surface malicious VIB installation or boot-time backdoor activity in real time or via logs; however the clause sets scope by organisational requirements rather than mandating ESXi-specific VIB signature or descriptor inspection, leaving a large slice of this hypervisor-only technique outside typical coverage.
- T1518detects — A.8.16 explicitly lists monitoring for anomalous behaviour, process injection, unauthorized access/scanning, resource use deviations, and known attack patterns, which can surface Software Discovery activity when it deviates from baseline; however the clause sets scope by organisational requirements rather than mandating universal coverage of enumeration commands or queries, leaving a large slice of stealthy or in-scope-but-unmonitored discovery undetected.
- T1518.001detects — A.8.16 explicitly requires monitoring of security-tool logs (item d), event logs (e), system/network activity (e/g), resource/performance baselines, and anomalous behaviours including process injection and malware-associated activity; this surfaces the specific discovery commands, registry queries, and agent-enumeration behaviours named in T1518.001 once they execute on the monitored estate.
- T1518.001responds — A.8.16's real-time/continuous monitoring, anomaly detection (incl. unauthorized access/scanning, process injection indicators, security tool logs), alerting, and procedures to respond to positive indicators (see 5.26) enable containment/eradication once discovery behavior is observed in flight; partial because the clause sets scope by org requirements (not mandating coverage of all discovery commands, cloud APIs, or non-monitored platforms) and detection itself is not response.
- T1518.002detects — A.8.16 requires monitoring of system/network activity, resource use, process anomalies, and deviations from baseline (including process injection or unusual behavior), which can surface backup-software discovery commands (tasklist, reg query, dir) as anomalous when they match established patterns or thresholds, but the clause sets scope by business needs rather than mandating coverage of every discovery artifact or backup-specific signature.
- T1525detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, malware-associated activity, code tampering, and deviations from baseline (covering image tampering or anomalous registry/container behaviour when in scope), but the clause sets monitoring scope by organisational requirements rather than mandating coverage of cloud/container image registries, so only a chosen slice is detected.
- T1526detects — A.8.16 requires monitoring of network, system, application traffic, access, event logs, resource use, and anomalies (including unusual behaviour and unauthorized access attempts) against a baseline, which can surface cloud service enumeration activity in real time or periodically where it produces observable deviations inside the chosen monitoring scope; the clause sets that scope by organisational requirements rather than mandating coverage of every cloud API call or enumeration method, leaving a large slice of stealthy or non-anomalous discovery (especially in IaaS/SaaS/identity-provider platforms) unreached.
- T1528detects — A.8.16 requires monitoring (incl. anomalous behaviour, access to critical systems/apps, resource use, process injection indicators, and real-time alerts) that can surface many T1528 realizations once underway (e.g. token requests via IMDS, anomalous API calls, container/K8s anomalies, OAuth phishing indicators), but scope is set by org requirements so coverage of all token-theft vectors (esp. social-engineering OAuth flows or offline refresh-token use) is implementation-dependent and not mandated.
- T1528prevents — A.8.16's real-time/periodic monitoring of network traffic, access attempts, anomalous behaviour (incl. process injection, unauthorized access, malware patterns), resource use, and alerts on deviations from baseline can surface many token-theft vectors (esp. post-compromise API abuse or OAuth flows) before full exploitation, but the control only detects rather than stops the theft itself and leaves social-engineering, pre-compromise container/CI-CD, and IMDS paths largely untouched.
- T1528responds — A.8.16 configures real-time/periodic monitoring plus alerts for anomalous behaviour (including process injection, unauthorized access, and deviations from baseline), enabling timely response procedures per 5.26 once token theft indicators appear; partial because the clause sets scope by business needs rather than mandating detection of every token-theft vector (e.g. social-engineering OAuth flows or IMDS requests may fall outside chosen instrumentation).
- T1529detects — A.8.16 explicitly lists monitoring for anomalous behaviour including unplanned termination of processes, unusual system behaviour (explicitly naming process injection), known attack characteristics, resource use deviations, and successful/unsuccessful access attempts; shutdown/reboot is a visible, logged system event that deviates from the established baseline of normal behaviour and is surfaced by the listed monitoring items (event logs, resource use, system activity) in real time or near-real time.
- T1529responds — A.8.16 surfaces shutdown/reboot via anomalous behaviour (e.g. unplanned termination, unusual system behaviour, resource spikes) in real time and feeds it to the 5.26 response procedure for containment/eradication once underway; mostly because the clause sets scope by business requirements rather than mandating universal coverage of every shutdown vector.
- T1530detects — A.8.16 requires monitoring of network traffic, access attempts, logs, anomalous behaviour (incl. unauthorized access/scanning and deviations from baseline), and real-time alerts, which surfaces many T1530 realizations (esp. via anomalous API calls, unusual access patterns or leaked-credential use); it does not cover stealthy direct reads of properly-authenticated cloud objects that match the baseline.
- T1530responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (including unauthorized access attempts and unusual behavior), alerting, and procedures to respond to positive indicators in a timely manner per 5.26, which directly matches the `responds` verb once the T1530 event (cloud storage access) is underway; partial because scope is set by organizational requirements rather than mandating universal coverage of all cloud storage access vectors.
- T1531detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access (actual or attempted), unusual user/system behaviour, and deviations such as process injection or known attack patterns; these surface many T1531 precursors or indicators (e.g. account lockouts, permission changes, unusual admin commands) once the technique is in flight, but the clause's scope is set by organisational requirements rather than mandating coverage of every platform or every account-manipulation vector, leaving a genuine implementation-chosen slice.
- T1531responds — A.8.16's real-time/periodic anomaly detection, alerting, and procedures to respond to positive indicators (including unusual account behaviour or access patterns) surface and enable timely response to T1531 once underway, but the clause's scope is set by organisational requirements rather than mandating coverage of account-modification techniques, leaving a large slice uncovered.
- T1534detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection), unauthorized access attempts, and deviations in protocols or user behaviour that can surface internal spearphishing artifacts such as anomalous internal messages, unexpected attachments/links, or credential-capture patterns once the technique is in flight; however the clause sets scope by organisational requirements rather than mandating universal coverage of chat apps, SaaS, or all internal traffic, leaving a genuine slice of the multi-staged technique (especially early credential compromise or impersonation) outside guaranteed detection.
- T1534responds — A.8.16 requires real-time/periodic monitoring of network, system, application traffic, access, logs, anomalous behaviour (incl. process injection, unauthorized access, malware patterns) plus alert generation and dedicated response personnel; this surfaces and enables containment of an internal spearphishing campaign once underway (e.g. via anomalous internal messages, attachments, or credential-capture sites), though the initial trusted-account compromise may precede detection.
- T1535detects — A.8.16 requires monitoring of network/system/application traffic, access, logs, resource use, baselines and anomalies (including unusual behaviour or unauthorized access), which can surface activity in unused regions if that activity produces observable signals inside the chosen monitoring scope; however the clause explicitly sets scope by business requirements, so an implementation that limits monitoring to actively-used regions is conformant yet sees nothing of the technique.
- T1537detects — A.8.16 explicitly calls for monitoring network traffic, system/resource use, baselines of normal behaviour, anomalous patterns (including unusual access and cloud-relevant indicators like unusual system behaviour), and real-time/automated alerts on deviations; this surfaces many T1537 transfers that deviate from baseline (e.g. large internal backups or anomalous API calls), but the technique's use of same-provider internal APIs, cloud-native sharing links, and blending into legitimate traffic leaves a large slice of stealthy instances undetected per the source prose.
- T1537responds — A.8.16 explicitly requires real-time/periodic monitoring for anomalous behaviour (including unusual system behaviour, resource use, and deviations from baseline), automated alerts on thresholds, dedicated trained personnel to respond to alerts, and timely procedures to address positive indicators per 5.26; this directly enables response once T1537 is underway, but the control's scope is set by organisational requirements so coverage of cloud-internal API transfers or backups is not mandated.
- T1538detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access (actual or attempted), unusual user/system behaviour, access to critical systems/applications, and real-time/continuous tools that surface deviations from baseline, which catches dashboard use with stolen credentials when it deviates from established patterns (e.g. unusual time/location/frequency or admin-level access); however the clause sets scope by organisational requirements rather than mandating universal coverage of all cloud dashboard sessions, leaving a slice determined by the implementer.
- T1539detects — A.8.16 explicitly lists monitoring for anomalous behaviour (including process injection, malware activity, unauthorized access, network traffic, and deviations from baseline), which surfaces many T1539 vectors such as local malware, JS injection, or anomalous proxy traffic; it does not cover all vectors (e.g. purely passive network sniffing of cookies or memory scraping without observable anomaly).
- T1539prevents — A.8.16's real-time baseline monitoring for anomalies (process injection, malware activity, unauthorized access, network traffic, JS injection indicators) can stop many T1539 vectors before cookie theft succeeds, but the clause sets scope by org requirements rather than mandating universal coverage of all vectors (e.g. local disk/memory theft, phishing proxies, or unmonitored endpoints), leaving a genuine slice uncovered.
- T1539responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. process injection, unauthorized access, malware patterns), alerting, and procedures to respond to positive indicators directly enable containment/eradication once cookie theft (via malware, injection, or MitM) is underway, with the named remainder being pre-alert impact already realized.
- T1542detects — A.8.16 explicitly lists monitoring for process injection, unauthorized access, anomalous system behaviour, firmware-adjacent indicators (e.g. boot-time malware patterns, known attack characteristics), and resource anomalies, which can surface some Pre-OS Boot artifacts post-boot or via network/execution baselines, but the technique's sub-OS nature and explicit note that it evades host software defenses leave a large, nameable remainder outside the clause's scope-determined coverage.
- T1542.001detects — A.8.16 explicitly lists monitoring for process injection, unauthorized access, anomalous system behaviour, code tampering, and baseline deviations, which can surface some firmware modification artifacts (e.g. boot-time anomalies or resource spikes), but the technique's low-level pre-OS nature and the clause's scope-determined implementation leave most firmware changes outside typical monitoring reach.
- T1542.002detects — A.8.16 explicitly lists monitoring for process injection, unauthorized code execution, anomalous system behaviour, and integrity of running code against a baseline, which surfaces some component-firmware anomalies once they affect observable host or network behaviour; it does not instrument the firmware components themselves or catch pre-execution or fully-evasive implants.
- T1542.003detects — A.8.16 explicitly lists monitoring for process injection, unauthorized access, anomalous system behaviour, critical config files, boot-time resource/performance deviations, and known attack patterns, which can surface some bootkit indicators (especially post-boot anomalies or ESP changes on UEFI); however the technique's pre-OS execution on raw boot sectors (MBR/VBR) sits below the OS-level monitoring scope the clause defines, leaving a large unmonitored slice.
- T1542.003responds — A.8.16's real-time/periodic anomaly detection, baseline comparison, and alert/response procedures surface and enable timely reaction to bootkit indicators (e.g. unauthorized boot-sector changes, anomalous early-boot processes, or resource deviations) once the technique has run, but the pre-OS nature and remediation difficulty noted in the source limit it to a genuine but minority slice of the full incident-response surface.
- T1542.004detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, unusual system behaviour, known attack characteristics, and baseline deviations in network/system/application activity, which can surface ROMMONkit indicators (e.g. unexpected firmware load, boot anomalies, resource deviations) in real time or via logs/alerts, but the clause sets scope by organisational requirements rather than mandating coverage of low-level boot firmware on network devices, leaving a genuine slice unreached.
- T1542.005detects — A.8.16 explicitly lists monitoring of network traffic, configuration files, system/network activity logs, resource use, and anomalous behaviour including unauthorized access/scanning and known attack patterns; this can surface TFTP boot abuse or config changes to a malicious server on covered network devices, but the clause sets scope by organisational requirements rather than mandating universal coverage of boot sequences or all network devices, leaving a large slice unseen.
- T1543detects — A.8.16 explicitly lists monitoring of system/network config files, event logs, resource use, process termination, malware-associated activity, process injection, unauthorized access, and deviations from baseline — all of which surface creation or modification of system processes (services/daemons/agents) for persistence.
- T1543responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unauthorized access, unusual system behaviour, and deviations from baseline) and requires dedicated trained personnel plus procedures to respond to positive indicators in a timely manner per 5.26, which directly matches the `responds` verb once the persistence technique is underway; partial because the clause sets scope by business requirements rather than mandating universal coverage of every service/daemon creation or modification on all platforms.
- T1543.001detects — A.8.16 requires monitoring of system/network activity, configuration files, resource use, anomalous behaviour (including process injection and deviations), and baselines that can surface launch-agent anomalies or plist changes in scope, but the clause sets scope by organisational requirements rather than mandating coverage of this macOS-specific persistence mechanism.
- T1543.001responds — A.8.16 configures monitoring (incl. process injection, anomalous system behaviour, resource use, and real-time alerts) to surface the technique once it has executed and is running at login; this enables timely response per linked 5.26 but does not itself contain or eradicate, and scope is set by org requirements rather than mandating coverage of all launch-agent artifacts.
- T1543.002detects — A.8.16 explicitly lists monitoring of critical/admin configuration files (c), event logs for system/network activity (e), security tool logs (d), resource/performance anomalies (g), and specific anomalous behaviours including process injection and deviations (in its baseline/anomaly examples), which directly surfaces systemd service creation, modification, or generator activity on Linux when it deviates from the established baseline.
- T1543.002prevents — A.8.16's monitoring of critical config files, system activity logs, baselines for anomalies (incl. unauthorized access, unusual behaviour, process injection), and real-time alerts can surface systemd service creation/modification before or during persistence, but does not stop the technique from executing as the control only detects rather than enforces or blocks the file changes or service registration.
- T1543.002responds — A.8.16 configures real-time/periodic monitoring of system activity, configuration files, logs, resource use, and explicit anomalies including process injection and unauthorized access; this surfaces an already-running systemd service persistence technique in flight for alert and response, but the clause sets scope by business needs rather than mandating universal coverage of all service-file or generator activity.
- T1543.003detects — A.8.16 explicitly lists monitoring of system/network config files, event logs, security-tool logs, resource use, process anomalies, unauthorized access attempts, and specifically names process injection and malware-associated behaviour; these directly surface the creation/modification of Windows services (registry changes, sc.exe, service start events, anomalous drivers) in the monitored estate, with the bounded remainder being hidden/masqueraded services that evade standard baselines.
- T1543.003prevents — A.8.16's real-time/periodic monitoring of system activity, baselines, anomalous behaviour (incl. process injection, unauthorized access, config changes), security-tool logs and resource use can surface many service-creation or modification attempts before persistence is fully realised, but the clause only sets scope and does not mandate blocking mechanisms, so the technique is not prevented in the bulk of cases.
- T1543.003responds — A.8.16 configures real-time/periodic monitoring of system activity, service-related events, anomalous behaviour (incl. process injection, unauthorized access, config changes), and generates tuned alerts for dedicated response personnel per 5.26, but only surfaces the technique after it has run and does not itself contain or eradicate it
- T1543.004detects — A.8.16 explicitly lists monitoring of system/network configuration files, event logs, resource use, process anomalies, and specifically names process injection and unauthorized access attempts; these directly surface Launch Daemon creation/modification and anomalous startup execution on macOS, with the named remainder being pre-compromise adversary activity on external infrastructure that the control cannot observe.
- T1543.004responds — A.8.16 configures monitoring (incl. process injection, anomalous system behaviour, admin config changes, resource use) to generate real-time alerts on positive indicators once the technique is underway, with dedicated trained personnel and procedures to respond per 5.26, but scope is set by organisational requirements rather than mandating coverage of all macOS Launch Daemon artifacts.
- T1543.005detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, unusual system behaviour, resource use, and known attack patterns, which can surface many T1543.005 artifacts (e.g. unexpected daemon/service mods, new DaemonSets, anomalous container starts); however the clause sets scope by organisational requirements rather than mandating universal coverage of container-specific artefacts, leaving a genuine slice unseen.
- T1543.005prevents — A.8.16's real-time/continuous monitoring of system activity, resource use, process anomalies, unauthorized access, and known attack patterns (including process injection and deviations) can surface or block the technique's execution in many cases before persistence is fully realized, but the clause sets scope by organizational requirements rather than mandating universal coverage of container daemons, DaemonSets, or kubelet modifications, leaving a large slice of the technique (especially on unmonitored container hosts) unreached.
- T1543.005responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (incl. process injection, unauthorized access, unusual system behaviour, and deviations from baseline), which surfaces T1543.005 once underway so dedicated personnel can respond per linked 5.26 procedures; it is not the response action itself and scope is set by org requirements rather than mandating coverage of all container-service modifications.
- T1546detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unusual system behaviour, unauthorized access attempts, and deviations from baseline (with real-time alerts and dedicated response), which surfaces many T1546 abuse indicators after the trigger is created/invoked; however the clause sets scope by organisational requirements rather than mandating universal coverage of all event-trigger mechanisms (e.g. certain cloud functions, logon triggers or low-level OS subscriptions may fall outside chosen telemetry).
- T1546prevents — A.8.16's baseline monitoring for anomalies (incl. process injection, unauthorized access, unusual behaviour, and event logs) can surface or constrain some T1546 triggers post-setup, but does not stop adversaries from creating/modifying event triggers for persistence or privilege escalation.
- T1546responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (including process injection, unauthorized access, unusual system behaviour) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26, which directly matches the `responds` verb once the T1546-triggered execution is underway; partial because the clause sets scope by business requirements rather than mandating universal coverage of every possible event trigger across all platforms.
- T1546.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized registry changes (via access to critical config files and event logs), unusual system behaviour, and deviations from baseline (e.g. unexpected program execution on file open); this surfaces the technique in many cases but scope is set by organisational requirements so coverage of all possible file-association triggers is not mandated.
- T1546.002detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized access attempts, and deviations from baseline (including unusual user/system activity after inactivity) as items the monitoring system should surface, which catches many T1546.002 realizations in real time or near-real time; it is only partial because the clause sets scope by business requirements rather than mandating universal coverage of all registry or screensaver triggers.
- T1546.002responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unauthorized executables, unusual system behaviour, and deviations from baseline), enabling timely response procedures once the screensaver-triggered persistence runs; it does not itself contain or eradicate, and coverage is scoped by organisational requirements rather than universal.
- T1546.003detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unusual user/system behaviour, and event logs as monitoring targets, which can surface WMI event subscriptions when they deviate from baseline; however the clause sets scope by organisational requirements rather than mandating universal coverage of WMI subscriptions or MOF compilation, leaving a large slice of stealthy or low-signal instances undetected.
- T1546.003prevents — A.8.16 requires monitoring for anomalous behaviour (incl. process injection, unusual system behaviour, admin config changes, resource use, and known attack patterns) which can surface a WMI event subscription once active, but the control sets scope by organisational requirements rather than mandating universal detection of this specific persistence technique, leaving a large slice of implementations that would miss the initial subscription creation.
- T1546.003responds — A.8.16 requires real-time/periodic monitoring of system behaviour, event logs, processes, resource use and known attack patterns (including process injection and anomalous activity), plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26; this directly matches the incident-response act of containing/eradication once the WMI-subscription technique is underway, with the named remainder being detections outside the chosen monitoring scope.
- T1546.004detects — A.8.16 explicitly lists monitoring of critical config files, system/network activity logs, anomalous behaviour (including process injection and deviations), unauthorized access attempts, and real-time/periodic anomaly detection against a baseline; this surfaces many but not all T1546.004 instances (e.g. stealthy non-anomalous modifications to user ~/. files or non-executing changes may fall outside the scoped baseline or monitored layers).
- T1546.005detects — A.8.16 explicitly lists process injection and anomalous system behaviour (including deviations in standard protocols) as items to baseline and alert on, which can surface trap-based persistence when it triggers interrupts or spawns processes; however the clause's scope is set by organisational requirements rather than mandating coverage of every shell signal handler, leaving a genuine slice of trap registrations unseen.
- T1546.006detects — A.8.16 explicitly lists process injection and anomalous system behaviour (plus code-tampering checks) among the anomalies its monitoring scope can surface, and LC_LOAD_DYLIB addition produces observable deviations at execution time; however the clause's scope is set by organisational requirements rather than mandating universal coverage of every binary or every macOS process, leaving a slice determined by the implementer.
- T1546.007detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access attempts, unusual system behaviour, and baselines of normal access/execution; this surfaces the Netsh Helper DLL persistence when it deviates from baseline or triggers observable anomalies, but the clause sets scope by organisational requirements so coverage of this specific registry-triggered technique is an implementer-chosen slice rather than a bounded remainder.
- T1546.007responds — A.8.16 requires real-time/periodic monitoring of network/system/application traffic, event logs, resource use, anomalous behaviour (including process injection and deviations), and automated alerts with dedicated response personnel; this surfaces and enables timely response to Netsh Helper DLL execution once underway, but the clause's scope is set by organisational requirements rather than mandating coverage of this specific persistence vector.
- T1546.008detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized access attempts, and deviations from baseline (including at login) as items the monitoring system should surface; these directly overlap the binary-replacement and key-triggered execution of T1546.008, but the clause sets scope by organisational requirements rather than mandating universal coverage of all persistence vectors or pre-login hooks, leaving a genuine slice unreached.
- T1546.008prevents — A.8.16's baseline + anomaly detection (incl. process injection, unauthorized access attempts, unsigned/tampered binaries, and unusual pre-login behaviour) can surface or block some T1546.008 variants in real time, but the clause sets scope by organisational requirements rather than mandating universal coverage of all binary-replacement or registry-hook methods, leaving a large slice of implementations that miss it.
- T1546.008responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. process injection, unauthorized access, unusual behaviour), alerting and dedicated response personnel directly enable containment/eradication once the accessibility-feature trigger has executed and the backdoor is active, but the clause's scope is set by organisational requirements rather than mandating universal coverage of all login-screen or pre-auth vectors.
- T1546.009detects — A.8.16 explicitly lists process injection and anomalous system behaviour (including deviations in standard protocols or API activity) among the monitored indicators, and AppCert DLLs are a form of process injection that would surface as anomalous DLL loading or process behaviour when the baseline and scope include host telemetry; however the clause sets the monitoring scope by organisational requirements rather than mandating universal host-level coverage, so only a chosen slice is guaranteed to be detected.
- T1546.009prevents — A.8.16's baseline monitoring for anomalous behaviour (incl. process injection, unauthorized code execution, and tampering checks) can surface AppCert DLL abuse in real time, but the control only sets scope and requirements rather than mandating universal instrumentation that stops the Registry edit or DLL load from occurring.
- T1546.009responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection and deviations in standard protocols), enabling dedicated personnel to respond to positive indicators per 5.26 once the technique is underway.
- T1546.010detects — A.8.16 explicitly lists process injection and anomalous system behaviour (plus code tampering and resource anomalies) among the events its monitoring scope and baseline can surface, but the clause sets scope by organisational requirements rather than mandating universal coverage of every AppInit DLL load, leaving a genuine slice determined by the implementer
- T1546.010prevents — A.8.16 requires monitoring for anomalous behaviour including process injection and deviations in standard protocols, which would surface many (but not all) malicious AppInit_DLLs once they trigger; this detection of the technique in flight is treated as `prevents` on the event lane per the calibration anchors (e.g. A.8.16 vs T1055, CM-7 vs T1059).
- T1546.010responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection and unauthorized DLL activity), with dedicated trained personnel and procedures to respond to positive indicators per 5.26, containing and eradicating the technique once underway.
- T1546.011detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized access attempts, and deviations from baseline as detectable via continuous monitoring of system activity, logs, and resources; however, the clause sets scope by organisational requirements rather than mandating universal coverage of shim installation or invocation, leaving a slice determined by the implementer (per A.8.16 event-lane anchor).
- T1546.011responds — A.8.16's real-time/periodic monitoring of system behaviour, process anomalies, resource use, and explicit mention of process injection can surface an active shim-based attack once underway, enabling timely response per linked 5.26 procedures; partial because scope is set by organisational requirements rather than mandating coverage of all shim hooks or persistence triggers.
- T1546.012detects — A.8.16 requires monitoring of system/network/application behaviour, event logs, resource use, process terminations, malware-associated activity and anomalous behaviour (including explicit mention of process injection), which surfaces many IFEO abuse indicators in real time or near-real time; however the clause's scope is set by organisational requirements rather than mandating universal coverage of all Registry, silent-exit or login-screen IFEO vectors, leaving a genuine slice unseen.
- T1546.012responds — A.8.16's real-time/periodic monitoring, anomaly detection (including process injection and unusual behaviour), alerting, and procedures to respond to positive indicators directly address an in-flight or just-triggered IFEO technique once underway, but the clause's scope is set by organisational requirements rather than mandating universal coverage of all IFEO vectors.
- T1546.013detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access attempts, unusual system behaviour, and deviations from a normal baseline of user/system activity; PowerShell profile execution on session start can surface as anomalous (especially if modified or run with elevated privileges), but the control's scope is set by organisational requirements rather than mandating coverage of this specific persistence vector, leaving a large slice of implementations that would miss it.
- T1546.013responds — A.8.16 requires real-time/periodic monitoring of system behaviour, logs, resource use, and explicit anomalies including process injection and deviations, plus dedicated trained personnel and procedures to respond to alerts (cross-referenced to 5.26 incident response); this catches and acts on the malicious profile execution once underway for many observable cases, but the clause's scope is set by organisational requirements rather than mandating coverage of every profile load, and the technique can be silent until triggered.
- T1546.014detects — A.8.16 explicitly lists monitoring for anomalous behaviour, process injection, unauthorized access, system activity logs, admin config changes, and real-time/periodic anomaly detection against a baseline, which surfaces emond rule abuse and root-level execution when it deviates from normal; however the clause sets scope by organisational requirements rather than mandating host-level visibility into plist rules in /etc/emond.d/rules or LaunchDaemon config, so only a chosen slice is covered.
- T1546.014prevents — A.8.16's baseline monitoring for anomalous behaviour, process injection, unauthorized access, and execution of unauthorized/tampered code can surface emond rule abuse as it runs, but the control only sets scope per business needs and does not mandate blocking the technique from executing.
- T1546.015detects — A.8.16 explicitly lists process injection, anomalous system behaviour, registry-adjacent activity (via config files and event logs), and baseline deviation monitoring, which can surface many COM hijacking artifacts once the technique runs; however the clause's scope is set by organisational requirements rather than mandating universal coverage of all COM/registry changes, leaving a genuine slice unseen.
- T1546.015responds — A.8.16 configures monitoring (incl. registry/config changes, process execution, anomalous behaviour, and real-time alerts) to surface COM hijacking once it has occurred and is in flight, enabling timely response per linked 5.26 procedures; partial because scope is set by organisational requirements rather than mandating coverage of all COM/registry/activity that could realise this technique.
- T1546.016detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized access attempts, resource anomalies, and monitoring of system/network/application activity plus security-tool logs; these surface many (but not all) indicators of malicious installer-script execution, especially post-install or during anomalous resource use, while installer-specific maintainer-script abuse outside monitored baselines or without triggering listed signatures remains unreached.
- T1546.016responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. process injection, unauthorized access, malware-like activity), alerting, and procedures to respond to positive indicators in a timely manner (cross-referencing 5.26) allow response once an installer-based persistence technique is underway and detected, but scope is set by org requirements so coverage of installer scripts is not mandated
- T1546.017detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, unusual system behaviour, and deviations in standard protocols, which can surface udev-rule-triggered malicious execution once it runs; however the clause sets scope by organisational requirements rather than mandating instrumentation of udev rule changes or /dev event handling, leaving a large slice of this Linux-specific persistence technique outside typical coverage.
- T1546.017prevents — A.8.16 requires monitoring of system/network activity, configuration files, resource use, anomalous behaviour (including process injection and deviations), and unauthorized access attempts, which can surface udev rule tampering or anomalous rule-triggered execution but does not stop the root-privileged modification of rules or the persistence trigger itself.
- T1546.017responds — A.8.16's real-time/periodic monitoring of system activity, resource use, process anomalies, unauthorized access, and known attack patterns (including process injection) surfaces udev-rule-triggered malicious execution once it runs, enabling timely response per linked 5.26 procedures; partial because udev events are narrow, often low-privilege/sandboxed, and not guaranteed to trigger the listed baselines or signatures unless the specific rule produces observable deviation within the scoped monitoring.
- T1546.018detects — A.8.16 explicitly lists process injection, anomalous code execution, unauthorized file changes, and deviations from baseline behaviour (including in startup/activity patterns) as detectable anomalies, which would surface Python startup-hook abuse when it runs; however the clause's scope is set by organisational requirements rather than mandating universal coverage of every Python invocation or .pth file, leaving a slice determined by the implementer.
- T1547detects — A.8.16 explicitly lists monitoring for process injection, unauthorized access, anomalous system behaviour, config file changes, resource use, malware-associated activity, and deviations from a normal baseline; these directly surface the configuration changes, kernel extensions, and autostart mechanisms (e.g. registry run keys, special directories, login items) used by T1547 after they occur.
- T1547.001detects — A.8.16 explicitly lists monitoring of access to systems/servers, critical config files, event logs, resource use, baseline anomalies, unauthorized access attempts, unusual behaviour (including process injection), and real-time/periodic alerting on signatures or patterns, which surfaces Registry Run Keys/Startup Folder persistence when it triggers observable anomalies at login or boot.
- T1547.001responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unauthorized access, unusual system behaviour, and deviations from baseline), which surfaces an in-progress T1547.001 persistence technique once the anomalous startup/run-key activity is observed, enabling timely response per linked 5.26 procedures; partial because the clause sets scope by organisational requirements rather than mandating universal coverage of all possible registry/startup-folder modifications.
- T1547.002detects — A.8.16 explicitly lists process injection and anomalous system behaviour in its monitoring scope and baseline, which can surface LSA authentication package abuse at runtime; however the clause sets scope by organisational requirements rather than mandating universal coverage of registry autostart mechanisms or LSA process loading, leaving a genuine slice uncovered.
- T1547.003detects — A.8.16 explicitly lists process injection and anomalous system behaviour (plus baselines for unusual resource use, unauthorized access, and malware-like activity) among the things its monitoring scope can surface, and T1547.003 is a boot-time DLL execution that would typically manifest as anomalous process or registry activity; however the clause only requires monitoring where scoped by the organization, so coverage of this specific persistence vector is a chosen slice rather than guaranteed.
- T1547.003prevents — A.8.16's baseline monitoring of system/network activity, config files, resource use, process termination, unauthorized access, and anomalous behaviour (including process injection) can surface the registry change and boot-time DLL load, but does not stop the admin-privileged registration or the technique from executing at startup.
- T1547.003responds — A.8.16's real-time/periodic monitoring, anomaly detection (including process injection and unauthorized access), alerting, and procedures to respond to positive indicators in a timely manner (cross-referenced to 5.26 incident response) allow containment once the boot-time DLL execution is underway and observed as anomalous, but this is only a slice because the technique's persistence is established at startup with minimal observable deviation from the baseline until after execution.
- T1547.004detects — A.8.16 requires monitoring for anomalous behaviour (including process injection and deviations from baseline) and can surface Winlogon helper DLL abuse when it produces observable anomalies in logs, resource use, or execution patterns, but the clause sets scope by organisational requirements rather than mandating universal coverage of registry or Winlogon events.
- T1547.004prevents — A.8.16's baseline monitoring of system behaviour, critical config files, event logs, resource use, process termination, unauthorized access, and explicit anomalies such as process injection can surface malicious Winlogon registry changes or the resulting DLL/executable execution at logon, thereby preventing the persistence technique from completing its full effect in monitored environments; however the clause only sets scope per organisational requirements rather than mandating universal detection of every registry abuse path.
- T1547.004responds — A.8.16's real-time/periodic monitoring, anomaly detection (including process injection and unauthorized access), alerting, and procedures to respond to positive indicators directly enable containment/eradication once the Winlogon Helper DLL persistence technique is underway on monitored Windows systems, but scope is set by org requirements so coverage of this specific technique is an implementer-chosen slice rather than bulk or bounded remainder.
- T1547.005detects — A.8.16 explicitly lists process injection and anomalous system behaviour (including deviations in standard protocols) among the anomalies to baseline and alert on, which surfaces SSP DLL loading into LSA; however the clause's scope is set by organisational requirements rather than mandating host-level visibility into every Registry modification or boot-time SSP load, leaving a genuine slice uncovered.
- T1547.005responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (including process injection and unauthorized access), alerting, and timely response procedures to minimize adverse effects once an incident is underway, which matches the `responds` verb; partial because the control's scope and depth are set by organizational requirements rather than mandating universal coverage of SSP DLL loading or LSA process anomalies.
- T1547.006detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unsigned/tampered code execution, and deviations from baseline (including resource use and kernel-visible activity) among the monitored indicators, which surfaces many LKM/kext-based rootkit manifestations; it does not guarantee detection of every stealth variant that perfectly mimics baseline or evades the chosen monitoring scope.
- T1547.006prevents — A.8.16's baseline monitoring for anomalies (including process injection, unauthorized access, code tampering checks, and known attack patterns) can surface LKM/kext loading in real time and trigger alerts, but the control only sets scope and detection requirements rather than blocking the kernel modification itself, leaving most of the technique's execution path untouched.
- T1547.006responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unauthorized access, unusual system behaviour, and deviations from baseline), which directly enables timely response procedures (see 5.26) once the LKM/kext technique is underway on Linux/macOS; partial because the clause sets scope by organisational requirements rather than mandating universal kernel-level instrumentation, leaving some in-kernel rootkit hiding outside guaranteed detection/response.
- T1547.007detects — A.8.16 explicitly lists monitoring for process injection, anomalous system behaviour, unauthorized access, and deviations from baseline (including plist changes that would alter login behaviour), but its scope is set by organisational requirements rather than mandating coverage of this specific macOS plist mechanism, leaving a slice determined by the implementer.
- T1547.008detects — A.8.16 explicitly lists process injection and anomalous system behaviour (including deviations in protocols or resource use) among the monitored indicators, which would surface many LSASS driver modifications or additions once they execute, but the clause sets scope by organisational requirements rather than mandating universal coverage of every possible driver load or LSA subsystem change.
- T1547.009detects — A.8.16 explicitly lists process injection, anomalous startup behaviour, unauthorized access, and baseline deviations as detectable anomalies, which can surface shortcut modifications in the startup folder or anomalous LNK behaviour; however the clause sets scope by organisational requirements rather than mandating universal coverage of all persistence mechanisms, leaving a slice of implementations that do not instrument the relevant file/registry events.
- T1547.010detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized access attempts, and monitoring of system/network activity, logs, and baselines as detection targets; port monitor DLL loading at boot via registry or spoolsv.exe is a detectable anomaly within those categories, but the clause sets scope by organisational requirements rather than mandating universal coverage of this specific persistence vector.
- T1547.010responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unauthorized access, unusual system behaviour, and deviations from baseline), which surfaces the port-monitor DLL load once it occurs so dedicated personnel can respond per linked 5.26 procedures; it does not itself contain or eradicate the running technique.
- T1547.012detects — A.8.16 explicitly lists monitoring for process injection, anomalous system behaviour, unauthorized access attempts, event logs, security-tool logs, resource use, and baseline deviations; these observables surface T1547.012's print-processor DLL load and spoolsv.exe restart under SYSTEM.
- T1547.012responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unauthorized access, unusual system behaviour, and deviations from baseline), which directly enables timely response procedures (cross-referenced to 5.26) once the T1547.012 technique has executed at boot; the named remainder is that detection depends on the chosen monitoring scope and may miss stealthy or non-anomalous installations.
- T1547.013detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access attempts, unusual system behaviour at login, and deviations from a normal baseline of access times/locations/frequency; this surfaces many (but not all) XDG Autostart abuse artifacts in real time or near-real time, yet the clause's scope is set by organisational requirements rather than mandating coverage of every autostart directory or .desktop file change, leaving a slice determined by the implementer.
- T1547.014detects — A.8.16 explicitly lists monitoring for process injection, anomalous user/system behaviour, unauthorized access attempts, registry-adjacent events (via config files, event logs, resource/performance baselines), and real-time alerting on deviations from normal login-time execution, which surfaces many (but not all) Active Setup abuse artifacts depending on the chosen monitoring scope.
- T1547.014responds — A.8.16's real-time/periodic monitoring of system behaviour, process execution, resource use, and anomalies (including process injection and unauthorized changes) surfaces the execution of a malicious Active Setup StubPath after login, enabling alert-driven response; it does not act on the prior registry-write step itself.
- T1547.015detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unusual system behaviour, unauthorized access attempts, and deviations from a user/group baseline of login times/locations/frequency; this surfaces many (but not all) T1547.015 instances on macOS, especially visible shared-list login items or those causing observable anomalies, while hidden launchd-based ones or those matching normal user patterns can remain undetected depending on the scoped implementation.
- T1547.015responds — A.8.16's real-time/periodic anomaly detection, baseline monitoring for unusual behaviour (including process injection and unauthorized access), alerting, and procedures to respond to positive indicators directly address an in-flight T1547.015 login-item persistence event once it has executed at login, but only for the observable slice (e.g. anomalous launch, resource use, or config change) rather than the full technique.
- T1548detects — A.8.16 explicitly lists process injection, unauthorized access attempts, anomalous system behaviour, and deviations from baseline (including admin/config activity) as detectable anomalies, which covers several T1548 techniques in real time; however, the clause sets scope by organisational requirements rather than mandating universal coverage of all elevation-abuse vectors (e.g. many macOS/Linux sudo or UAC bypasses can be silent), so only a slice is instrumented.
- T1548responds — A.8.16's real-time/periodic monitoring, anomaly detection (including process injection and unauthorized access), alerting, and procedures to respond to positive indicators directly enable response once T1548 privilege-escalation behavior is underway, but the clause sets scope by business needs rather than mandating universal coverage of all elevation-abuse vectors.
- T1548.001detects — A.8.16 explicitly lists process injection and anomalous system behaviour (including deviations in use of standard protocols) as items to baseline and alert on, which surfaces many T1548.001 abuses once they execute, but the clause sets scope by organisational requirements rather than mandating universal coverage of all setuid/setgid executions or file-permission changes.
- T1548.002detects — A.8.16 explicitly lists process injection, unusual system behaviour, anomalous resource use, and known attack characteristics (including malware patterns) among the monitored items and baseline deviations it requires tools to surface in real time or at intervals; these directly match several T1548.002 methods, but the clause's scope is set by organisational requirements rather than mandating universal coverage of every UAC-bypass variant or remote/lateral cases, leaving a genuine implementation-chosen slice.
- T1548.002responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unauthorized access, unusual system behaviour, and deviations from baseline), which surfaces a UAC-bypass technique once underway so dedicated personnel can respond per linked procedures (5.26); the named remainder is fully-silent bypasses that produce no observable anomaly within the configured scope.
- T1548.003detects — A.8.16 explicitly lists monitoring for process injection, unauthorized access/privilege changes, anomalous system behaviour, admin-level config file changes (sudoers), and resource anomalies, which would surface many T1548.003 indicators in real time or near-real time; it is only partial because the clause sets scope by organisational requirements rather than mandating universal coverage of all sudo caching or sudoers edits.
- T1548.004detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized access attempts, and deviations from baseline (including resource/performance anomalies) as items the monitoring system should surface; T1548.004's use of a deprecated API, world-writable file loads, and masquerading can produce observable anomalies in logs, process execution, or resource use that fall inside the clause's scope, but the control's scope is set by organisational requirements rather than mandating universal coverage of this macOS-specific technique, leaving a genuine slice uncovered.
- T1548.004prevents — A.8.16's baseline monitoring for anomalous behaviour, process integrity checks, unauthorized access attempts, and real-time alerts can surface or constrain some macOS privilege-escalation flows that deviate from normal (e.g. unexpected prompts or modified binaries), but the control sets scope by organisational requirements rather than mandating universal prevention of the deprecated API's abuse.
- T1548.005detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access/attempts, unusual system behaviour (including process injection), admin/config activity, and real-time/automated alerts tuned to a baseline, which surfaces many T1548.005 indicators in IaaS/identity-provider logs; it does not guarantee coverage of every stealthy or misconfiguration-driven impersonation/pass-role case, especially where logs do not clarify role impersonation.
- T1548.005responds — A.8.16 requires real-time/periodic monitoring, anomaly detection against baselines (including unusual behaviour like process injection or unauthorized access), alerts, and procedures to respond to positive indicators in a timely manner per 5.26, which bounds impact once the temporary elevation technique is underway; partial because scope is set by organisational requirements rather than mandating coverage of all cloud permission-abuse indicators.
- T1548.006detects — A.8.16 explicitly lists process injection, unusual system behaviour, access to critical files/configs, and anomalous resource/use patterns (all core to TCC manipulation) as items to baseline and alert on in real-time or periodic monitoring, but the clause sets scope by organisational requirements rather than mandating universal coverage of every TCC.db access or SIP-disabled manipulation vector.
- T1548.006prevents — A.8.16's real-time/periodic monitoring of system behaviour, process integrity, resource use, and anomalies (including process injection and unauthorized access) can surface TCC manipulation in flight on covered macOS systems, thereby preventing successful completion of the technique in monitored environments, but the clause sets scope by organisational requirements rather than mandating universal coverage of all TCC database accesses or SIP-disabled vectors.
- T1548.006responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. process injection, unauthorized access, unusual behaviour), alerting and dedicated response procedures directly surface and enable timely response to TCC manipulation once underway, but the clause sets scope by org requirements so coverage of this macOS-specific technique is a chosen slice rather than guaranteed.
- T1550detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unusual system behaviour, unauthorized access attempts, and deviations from baseline (access patterns, resource use, known attack characteristics), which directly surfaces the observable artifacts and execution of T1550 (e.g. anomalous use of stolen tickets/hashes/tokens for lateral movement).
- T1550responds — A.8.16 configures monitoring (incl. process injection, anomalous behaviour, access attempts, resource use) to generate alerts on indicators of T1550 once underway, with dedicated response personnel and procedures that bound impact per 5.26, but scope is set by org requirements so coverage of alternate auth material theft/use is not comprehensive.
- T1550.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access attempts, unusual system behaviour (including process injection), access to protected resources, and deviations from baseline (including API traffic and resource use), which surfaces many T1550.001 indicators in real time or near-real time; however the clause sets scope by organisational requirements rather than mandating universal coverage of all token abuse vectors (e.g. long-lived refresh tokens or perfectly legitimate-looking API calls), so only a chosen slice is guaranteed to be detected.
- T1550.001responds — A.8.16 requires real-time/periodic monitoring of network, system, application traffic, access events, security-tool logs, anomalous behaviour (including unusual API patterns or resource use), and dedicated trained personnel plus procedures to respond to alerts (see 5.26), which can contain/eradicate an in-progress T1550.001 token abuse once detected; partial because the clause sets scope by business needs rather than mandating universal coverage of all token/API channels, leaving a slice dependent on what the implementer includes.
- T1550.002detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unusual access patterns, and monitoring of access to systems/servers as detection targets; PtH manifests in those observables on Windows but is a narrow, specific credential-use technique whose full scope (hash capture, overpass-the-hash, Kerberos ticket creation) sits outside the clause's named examples and baseline-tuning focus.
- T1550.003detects — A.8.16 explicitly lists monitoring for process injection, anomalous system behaviour, unauthorized access attempts, and deviations from baseline (including unusual resource use and access patterns), which can surface many PtT indicators in real time or near-real time; however the clause's scope is set by organisational requirements rather than mandating universal coverage of all Kerberos ticket anomalies or memory-resident credential use, leaving a genuine slice uncovered.
- T1550.003responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unauthorized access, unusual system behaviour, and deviations from baseline), which surfaces PtT in flight for dedicated personnel to contain/eradicate once underway per linked 5.26 procedures; it is not the response itself and leaves many stealthy PtT variants (e.g. golden/silver ticket use without obvious anomalies) outside the monitored scope or baseline.
- T1550.004detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, malware-associated activity, unauthorized access attempts, unusual user/system behaviour, and security-tool logs (IDS/IPS/firewalls/DLP); these surface many T1550.004 realizations (e.g. malware stealing/importing cookies, anomalous sessions, or post-use access patterns) once the baseline is tuned, but the clause sets scope by business requirements rather than mandating universal coverage of all cookie-theft vectors or all platforms, leaving a genuine slice uncovered.
- T1550.004responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (incl. malware activity, unauthorized access, unusual system behaviour) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26, which directly matches the event-lane definition of `responds` once the cookie-theft or reuse is underway; partial because the clause sets scope by business requirements rather than mandating universal coverage of all session-cookie misuse vectors (e.g. purely external SaaS use with no observable internal anomaly).
- T1552detects — A.8.16's monitoring of logs, access, anomalous behaviour, process injection, unauthorized access attempts, and baselines can surface T1552 activity (e.g. unusual file/registry reads or credential-dumping patterns), but the clause sets scope by organisational requirements rather than mandating coverage of all credential-search locations or artifacts, leaving a large slice determined by the implementer
- T1552.001detects — A.8.16 explicitly requires monitoring of file access, configuration/credential files, logs (incl. container/deployment logs), anomalous behaviour patterns, and known attack characteristics, which surfaces the search for or presence of insecure credential files on the listed platforms.
- T1552.002detects — A.8.16 requires monitoring of system activity, event logs, resource use, baselines of normal behaviour and specific anomalies (including process injection and unauthorized access), which can surface Registry queries for credentials when they deviate from the tuned baseline or match known malicious patterns; however the clause sets scope by business requirements rather than mandating instrumentation of all Registry reads, so only a slice chosen by the implementer is covered.
- T1552.003detects — A.8.16 explicitly lists monitoring for anomalous behaviour, process injection, unusual system behaviour, access to critical files, and event logs, which can surface shell-history access or reads of ~/.bash_history / ConsoleHost_history.txt when those deviate from the established baseline; it does not guarantee coverage of every history-file read on every platform or user context.
- T1552.004detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access attempts, unusual system behaviour (including process injection), file access to critical resources, and security-tool logs that can surface searches for .key/.pem/.ssh files or export commands, but the clause sets scope by organisational requirements rather than mandating coverage of every credential-search pattern on every platform, leaving a genuine slice unreached.
- T1552.005detects — A.8.16 requires monitoring of network traffic, anomalous behaviour, known attack patterns and unusual system behaviour (including process injection and deviations), which can surface direct queries or SSRF attempts to the metadata API as anomalies against baseline, but scope is set by organisational requirements so coverage of this specific IaaS technique is not mandated.
- T1552.005responds — A.8.16 configures monitoring (incl. network traffic, anomalous behaviour, known attack patterns, real-time alerts) to surface and enable timely response to the technique once underway (e.g. SSRF to 169.254.169.254 or unusual queries from an instance), but does not itself perform containment/eradication — that lives in 5.26 procedures referenced by the clause.
- T1552.006detects — A.8.16 requires monitoring of network, system, application traffic, access to critical resources, event logs, resource use, and anomalies including unauthorized access/scanning and unusual behaviour; this can surface GPP credential-enumeration activity (e.g. anomalous SYSVOL XML enumeration or access), but the clause sets scope by organisational requirements rather than mandating instrumentation that necessarily sees every instance of this technique.
- T1552.007detects — A.8.16 explicitly lists monitoring for anomalous behaviour, process injection, unauthorized access, resource use deviations, and known attack patterns (including via logs, network traffic, and system events), which can surface many T1552.007 realizations in real time or near-real time; however the clause's scope is set by organizational requirements rather than mandating universal container API coverage, leaving a genuine slice (e.g. stealthy API calls inside unmonitored clusters) unreached.
- T1552.008detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection), unauthorized access attempts, and real-time/periodic analysis of network, system, application traffic, logs, and resource use; this surfaces T1552.008 activity on monitored endpoints or SaaS services when it deviates from baseline, but the clause's scope is set by organizational requirements rather than mandating universal coverage of chat-message credential extraction across all platforms and integration tools.
- T1553detects — A.8.16 explicitly lists monitoring for process injection, unauthorized code execution/tampering, anomalous system behaviour, and malware-associated activity, which surfaces many T1553 sub-techniques in flight; it does not cover all trust-subversion vectors (e.g. stolen certs, registry changes, or non-runtime indicators) and scope is implementation-defined rather than universal.
- T1553prevents — A.8.16's baseline monitoring and anomaly detection (including process injection, unauthorized code execution, tampering indicators, and malware-like behaviour) surfaces many T1553 subversions in flight or post-execution, but does not stop the adversary from first undermining or bypassing the trust control itself.
- T1553.001detects — A.8.16 explicitly lists monitoring for process injection, unauthorized access/execution, anomalous system behaviour, code-tampering checks, and baseline deviations that can surface a Gatekeeper-bypass execution of untrusted code; scope is implementer-defined so only a slice of possible bypass vectors (e.g. those that produce observable anomalies) is covered.
- T1553.002detects — A.8.16 explicitly lists monitoring for process injection, unauthorized code execution, tampered binaries, known attack patterns, and deviations from baseline (including code that is not authorized or has been altered), which surfaces adversary use of stolen or forged signing materials when the signed malware runs or exhibits anomalous behavior; however, purely pre-execution acquisition/creation of signing material on external infrastructure or fully stealthy validly-signed benign-looking binaries fall outside the listed scopes and baselines.
- T1553.003detects — A.8.16 explicitly lists monitoring for process injection, unauthorized access, anomalous system behaviour, code-tampering checks, and baseline deviations that can surface SIP/trust-provider hijacking when it produces observable artifacts (e.g. registry changes, unexpected DLL loads, or anomalous validation calls), but the control's scope is set by organisational requirements rather than mandating coverage of every stealthy in-memory or registry-only hijack, leaving a genuine slice unreached.
- T1553.003responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. process injection, unauthorized access, tampered code execution), baseline-driven alerting, and procedures to respond to positive indicators directly surface and enable timely response to SIP/trust-provider hijacking once underway, but the clause's scope is set by org requirements rather than mandating universal coverage of this specific technique.
- T1553.004detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, malware-associated activity, unusual system behaviour, and security tool logs (AV/IDS/IPS), which would surface many (but not all) root-certificate installation events; the clause's scope is set by organisational requirements rather than mandating universal coverage of every certificate-store change.
- T1553.005detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, malware-associated activity, unusual system behaviour, and real-time/periodic anomaly detection against a baseline, which can surface MOTW-bypass execution or related anomalies (e.g. via logs, resource use, or signatures); however the clause sets scope by organisational requirements rather than mandating detection of this specific technique, leaving many implementations without coverage of the container extraction or file-tagging bypass itself.
- T1553.006detects — A.8.16 explicitly lists monitoring for process injection, unauthorized code execution, anomalous system behaviour, and integrity checks on executed code against a baseline, which surfaces many (but not all) policy-modification artifacts or their downstream effects on macOS/Windows.
- T1554detects — A.8.16 explicitly lists monitoring for process injection, unauthorized code execution, tampered binaries (via integrity checks on executed code), anomalous system behaviour, and deviations from baseline — all of which surface T1554's binary modification or patching in flight or on execution.
- T1554prevents — A.8.16's baseline monitoring and anomaly detection (including code tampering checks, unauthorized access, process anomalies, and known attack patterns) can surface or block some binary modification techniques before persistence is fully realized, but the clause sets scope by organizational requirements rather than mandating universal mechanisms that stop all such modifications.
- T1554responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. process injection, tampered code, unauthorized access, malware patterns), alerting, and procedures to respond to positive indicators directly address an in-flight or just-realized T1554 modification once underway, containing/eradication impact per the event-lane definition of responds; partial because scope is set by org requirements rather than mandating universal binary-integrity coverage.
- T1555detects — A.8.16 requires monitoring of network/system/application traffic, access events, logs from security tools, resource use, and specific anomalous behaviours (including process injection and deviations), which can surface credential-access activity when it triggers observable anomalies or known patterns, but the clause's scope is set by organisational requirements rather than mandating coverage of all password-store searches, leaving a large slice of stealthy file/registry reads undetected.
- T1555.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access attempts, unusual system behaviour, and security-tool logs (e.g. IDS/IPS), which can surface Keychain dumping via command-line utilities or file reads when they deviate from baseline; however the clause's scope is set by organisational requirements rather than mandating coverage of every credential-access technique, leaving many stealthy or in-memory Keychain accesses outside the chosen monitoring slice.
- T1555.002detects — A.8.16 explicitly lists process injection, memory anomalies, unusual system behaviour, resource use, and privileged access attempts within its baseline/anomaly detection scope, which would surface the technique of scanning securityd memory; however the clause sets scope by organisational requirements rather than mandating universal deep memory inspection, leaving a slice of implementations that would miss it.
- T1555.003detects — A.8.16 explicitly lists process injection, anomalous resource use, unauthorized access attempts, and deviations from baseline (including in memory and file access patterns) as detectable anomalies, which would surface many T1555.003 file/memory reads on browser credential stores; however the clause's scope is set by organizational requirements rather than mandating universal coverage of every credential-stealing pattern or platform-specific store.
- T1555.004detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access attempts, unusual system behaviour, and security-tool logs (e.g. AV/IDS), which can surface many T1555.004 mechanisms (e.g. vaultcmd.exe, CredEnumerate API abuse, Mimikatz-like tools, or anomalous file reads) once the baseline is tuned; it does not cover every stealthy or file-level variant outside the chosen monitoring scope.
- T1555.004responds — A.8.16's real-time/periodic anomaly detection, baseline monitoring for unusual behaviour (incl. process injection, unauthorized access, malware patterns), alerting, and procedures to respond to positive indicators directly surface and enable timely response to T1555.004 execution (e.g. vaultcmd.exe, CredEnumerateA, file reads, or recovery tools) once underway, but scope is set by org requirements so coverage of this specific credential-theft vector is not assured.
- T1555.005detects — A.8.16 explicitly lists monitoring for process injection, memory anomalies, unusual system behaviour, access to critical applications, and deviations from baseline (including resource use and malware-like activity), which surfaces many T1555.005 realizations in memory or via exploitation; it does not cover all vectors such as offline brute-force of the master password or non-monitored disk-based extraction.
- T1555.006detects — A.8.16 explicitly lists monitoring of access to systems/critical apps, admin configs, security tool logs, anomalous behaviour (incl. unauthorized access attempts and unusual system behaviour), and real-time/periodic anomaly detection against baselines, which can surface the privileged API calls that realise T1555.006; however the clause's scope is set by organisational requirements rather than mandating coverage of all cloud secrets-manager interactions, leaving a large slice of cloud-native API traffic outside guaranteed detection.
- T1556detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized access attempts, and deviations from baseline (including admin/config changes and code tampering checks) as detectable anomalies, which directly surface many T1556 realizations; however the clause's scope is set by organizational requirements rather than mandating coverage of all authentication-process modifications (e.g. PAM hooks or plugin tampering on unmonitored platforms), making the coverage a chosen slice rather than a bounded remainder.
- T1556prevents — A.8.16's baseline monitoring for anomalies (including process injection, unauthorized access, code tampering, and unusual behaviour) can surface some T1556 modifications in real time or near-real time, but the control only sets scope per business needs and does not mandate instrumentation that would stop the modification from occurring.
- T1556responds — A.8.16 configures monitoring (incl. process injection, anomalous behaviour, unauthorized access attempts) to generate alerts on T1556 indicators once underway, with dedicated response personnel and procedures (see 5.26), but scope is set by org requirements so coverage of auth-process mods is not guaranteed across all platforms or stealthy variants.
- T1556.001detects — A.8.16 explicitly lists process injection, anomalous system behaviour, code tampering checks, and real-time/baseline monitoring of LSASS-like processes as detection targets, but the control's scope is set by organisational requirements rather than mandating universal coverage of domain-controller authentication patching.
- T1556.001prevents — A.8.16's baseline monitoring for anomalies (incl. process injection, unauthorized code execution, LSASS-like tampering, and unusual auth behaviour) can surface the patch/malware before or during its use on a DC, thereby preventing successful technique execution in monitored environments, but the clause only sets scope per business needs and does not mandate the specific sensors or real-time depth required to catch every variant on every DC.
- T1556.001responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (incl. process injection, unauthorized access, unusual system behaviour, and deviations from baseline), which directly feeds the incident response procedures referenced in its own text (see 5.26) once the T1556.001 patch is active and observable; the remainder is that detection depends on the chosen monitoring scope and may miss in-memory LSASS patches that produce no detectable anomaly within the configured baseline.
- T1556.002detects — A.8.16 explicitly lists process injection and anomalous system behaviour (plus code tampering checks) among the monitored indicators, which would surface a malicious password filter DLL once loaded and active; however the clause's scope is set by organisational requirements rather than mandating universal coverage of authentication-path DLL registration, leaving a genuine slice of implementations that would miss it.
- T1556.002prevents — A.8.16's baseline monitoring for anomalous behaviour, process integrity checks (f), resource/performance deviations, and real-time alerts can surface the registration and execution of a malicious password filter DLL (explicitly listed under unusual behaviour like process injection), thereby preventing the technique from completing undetected on monitored systems; however the clause sets scope by organisational requirements rather than mandating universal coverage of all authentication paths or LSA interactions, leaving a slice unmonitored.
- T1556.003detects — A.8.16 explicitly lists monitoring for process injection, unauthorized access attempts, anomalous system behaviour, code tampering, and deviations from baseline (including admin/config changes and resource anomalies), which surfaces many PAM modifications in real time or near-real time; it is only partial because the clause's scope is set by organisational requirements rather than mandating universal coverage of every PAM library or credential-harvest vector on every Linux/macOS host.
- T1556.004detects — A.8.16 explicitly lists monitoring for process injection, unauthorized access attempts, anomalous system behaviour, code tampering, and deviations from baseline (including on network devices via traffic, logs, resource use, and real-time tools), which can surface the post-patching authentication bypass in flight or via its effects, but the control's scope is set by organizational requirements so coverage of network-device firmware/OS images is not mandated.
- T1556.005detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access attempts, unusual system behaviour, and deviations in protocols, plus real-time/periodic anomaly detection against a baseline; this surfaces the technique when the adversary sets the reversible-encryption property or when the resulting credential exposure is later used, but the clause's scope is set by organisational requirements so many implementations will miss the configuration change itself.
- T1556.006detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access attempts, configuration file changes, unusual system behaviour, and admin-level activity that can surface many T1556.006 realizations (e.g. patching MFA binaries, hosts-file tampering, Conditional Access exclusions), but its scope is set by organizational requirements rather than mandating coverage of all MFA-modification vectors on all platforms, leaving a genuine implementer-chosen slice.
- T1556.007detects — A.8.16 explicitly lists process injection, anomalous system behaviour, config-file access, and unauthorized access attempts among the observables its monitoring scope can cover, which surfaces the PTA/AD FS backdoor techniques in the source prose; the remainder is the cloud-side registration of a new PTA agent (outside on-prem monitoring) plus any implementation whose scope excludes host telemetry.
- T1556.007prevents — A.8.16's baseline monitoring for anomalies (incl. process injection, config-file tampering, unauthorized access, and unusual auth behaviour) can surface the on-prem DLL injection or AD FS config edit before or while the backdoor runs, thereby preventing some realisations of the technique; it does not stop the cloud-side PTA-agent registration or block the modification itself.
- T1556.008detects — A.8.16 explicitly lists monitoring for process injection, anomalous system behaviour, unauthorized access attempts, and deviations from baseline (including resource and logon patterns), which can surface the DLL registration or mpnotify.exe credential-sharing anomaly in real time or via logs; however the clause sets scope by organisational requirements rather than mandating universal coverage of Registry changes or every credential-manager hook, leaving a slice determined by the implementer.
- T1556.008responds — A.8.16 configures monitoring (incl. anomalous behaviour, process injection, unauthorized access, registry changes via event logs) to surface the technique once it has run and is in flight, with dedicated personnel and procedures to respond to alerts (see 5.26), but scope is set by the organization so coverage of this specific credential-theft vector is not assured.
- T1556.009detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access attempts, unusual system behaviour (including process injection), and deviations from baseline (e.g. access patterns, admin config changes), which surfaces T1556.009 activity when it triggers observable indicators inside the chosen scope; it is partial because the clause sets the monitoring scope by business requirements rather than mandating coverage of identity-provider policy modifications, so an implementation limited to network/application layers sees none of it.
- T1557detects — A.8.16 explicitly lists monitoring of inbound/outbound network traffic, anomalous behaviour patterns (including known attack characteristics and deviations in protocols), security tool logs (IDS/IPS/firewalls), and real-time/continuous anomaly detection against a baseline, which surfaces many AiTM indicators such as ARP/DNS/LLMNR abuse, unexpected redirects, or traffic manipulation; however, the clause's scope is set by organisational requirements rather than mandating universal coverage of all AiTM variants (e.g. those on unmonitored segments, physical-layer, or post-compromise inside encrypted channels), making the coverage a chosen slice per the event-lane anchor for A.8.16 vs T1055.
- T1557prevents — A.8.16's real-time/periodic monitoring of network traffic, anomalous behaviour, known attack patterns (DoS, buffer overflows), unauthorized access/scanning, and baseline deviations can surface many AiTM indicators (e.g. ARP/DNS poisoning, unexpected redirects, protocol downgrades, or traffic anomalies) before full positioning or follow-on succeeds, but does not stop the initial protocol abuse or force the technique from ever running.
- T1557responds — A.8.16 explicitly requires real-time/periodic monitoring for anomalous behaviour (including known attack characteristics, unauthorized access, unusual system/network behaviour, and traffic patterns), dedicated trained personnel to respond to generated alerts, and timely procedures to address positive indicators per 5.26, which bounds an in-progress AiTM once detected; partial because the clause sets scope by organisational requirements rather than mandating universal coverage of all AiTM vectors (e.g. ARP/DNS manipulation on unmonitored segments).
- T1557.001detects — A.8.16 explicitly requires monitoring of inbound/outbound network traffic, access attempts, security-tool logs (IDS/IPS/firewalls), event logs, anomalous behaviour patterns (including known attack characteristics and unusual system behaviour), and real-time/periodic anomaly detection against a baseline, which directly surfaces LLMNR/NBT-NS/mDNS spoofing, NTLM hash transmission, and relay activity on Windows networks as observable events.
- T1557.001prevents — A.8.16 mandates real-time/periodic monitoring of network traffic, anomalous behaviour (including known attack patterns and deviations in protocols), and generation of tuned alerts with response procedures; this can block successful poisoning/relay by enabling timely containment before hashes are cracked or relayed, but the control only sets scope per business needs and does not mandate disabling LLMNR/NBT-NS/mDNS or enforcing signed name resolution, leaving the root technique able to run on many conformant implementations.
- T1557.001responds — A.8.16's real-time/periodic monitoring of network traffic, anomalous behaviour (including known attack patterns and unauthorized access), security-tool logs, and alerting feeds directly into 5.26 incident response once the poisoning/relay is underway on the monitored network; it does not contain/eradicate the adversary-controlled system or relayed session itself.
- T1557.002detects — A.8.16 explicitly requires monitoring of network traffic, anomalous behaviour, known attack characteristics, and deviations such as process injection or protocol misuse; ARP cache poisoning produces observable network anomalies (gratuitous replies, duplicate MACs, unexpected traffic redirection) that fall inside the mandated baseline-driven detection scope, with only a bounded remainder (e.g., fully passive poisoning on unmonitored segments) left unreached.
- T1557.002prevents — A.8.16's real-time/periodic monitoring of network traffic, anomalous behaviour (incl. known attack patterns and deviations in protocols), resource use, and alerting can surface ARP poisoning in flight on covered segments, but the control only sets a scoped monitoring requirement rather than mandating any preventive mechanism (e.g. static ARP, ARP validation, or port security) that stops the cache from being poisoned.
- T1557.002responds — A.8.16's real-time/periodic monitoring, anomaly detection (including unusual network behaviour, known attack characteristics, and unauthorized access), alerting, and procedures to respond to positive indicators directly enable containment/eradication once ARP poisoning (a MITM technique with observable network anomalies) is underway, but scope is set by organizational requirements rather than mandating universal coverage of all ARP traffic or platforms.
- T1557.003detects — A.8.16 explicitly includes monitoring of inbound/outbound network traffic, access to systems/networking equipment, security tool logs (e.g. IDS/IPS/firewalls), anomalous behaviour against baseline (e.g. unusual system behaviour, unauthorized access/scanning, known attack characteristics), and real-time/continuous tools that recognize signatures/patterns and generate alerts; this surfaces rogue DHCP server activity, malicious offers, and resulting AiTM/redirection on covered networks, with the bounded remainder being unmonitored segments or stealthy variants outside the defined scope.
- T1557.003prevents — A.8.16 requires monitoring of inbound/outbound network traffic, access events, anomalous behaviour (including known attack patterns and deviations in protocols), and real-time/periodic anomaly detection against a baseline; this can surface rogue DHCP OFFER/ACK messages or unusual DHCP traffic before clients fully adopt malicious configs, but the control only observes and alerts rather than blocking the spoofed responses or AiTM setup itself.
- T1557.003responds — A.8.16's real-time/periodic monitoring of network traffic, anomalous behaviour (incl. known attack patterns and unauthorized access), baseline deviations, and alert/response procedures can surface and feed into incident response for an in-progress DHCP spoofing AiTM or exhaustion attack on the monitored network, but the clause itself performs no containment/eradication and many stealthy or pre-compromise DHCP exchanges fall outside its configurable scope.
- T1557.004detects — A.8.16 explicitly lists monitoring of network traffic, anomalous behaviour (including known attack characteristics and deviations in protocols), resource use, and real-time/continuous tools that surface indicators such as unauthorized access or malicious patterns; this catches many Evil Twin observables (rogue AP signals, probe responses, traffic anomalies) once present, but scope is set by organizational requirements so coverage of all possible Evil Twin deployments (e.g. physical placement outside monitored perimeters or non-network layers) remains a chosen slice rather than a bounded remainder.
- T1557.004responds — A.8.16's real-time/periodic monitoring of network traffic, anomalous behaviour (including known attack patterns and unauthorized access), and dedicated alert-response procedures can surface and trigger timely response to an Evil Twin once it is active on the network, but the control's scope is set by organisational requirements rather than mandating detection of all rogue-AP variants (e.g. probe-response or physical-signal attacks outside monitored boundaries), so only a slice is covered.
- T1558detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unusual access patterns, and monitoring of access/logs/traffic as detection targets, which surface some T1558 indicators (e.g. anomalous KDC traffic, unusual ticket requests, or klist-like enumeration), but the clause's scope is set by organisational requirements rather than mandating coverage of all Kerberos-ticket theft or forgery vectors.
- T1558responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (incl. process injection, unauthorized access, unusual system behaviour) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26; this catches and acts on realized T1558 artifacts (e.g. anomalous klist use, ticket-related network patterns) once underway but scope is set by org requirements so coverage of all T1558 vectors is a chosen slice rather than bounded remainder
- T1558.001detects — A.8.16 explicitly lists process injection, unusual system behaviour, anomalous access patterns, and known attack characteristics (including traffic from malicious domains) as detectable via real-time/periodic monitoring against a baseline, which can surface golden ticket usage or its precursors; however the clause's scope is set by organisational requirements rather than mandating coverage of all Kerberos/KDC interactions or domain-controller specifics, leaving a large slice of the technique unseen.
- T1558.001responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (incl. process injection, unusual system behaviour, unauthorized access, known attack characteristics) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26, which directly matches the responds verb once the golden-ticket technique is underway; partial because the clause sets scope by business requirements rather than mandating universal detection of every golden-ticket indicator (e.g. specific KRBTGT hash usage or forged TGT patterns may fall outside chosen baselines/tools).
- T1558.002detects — A.8.16 explicitly lists process injection, anomalous resource use, unusual system behaviour, known attack characteristics, and deviations in standard protocols (plus real-time/baseline monitoring of logs, traffic, access, and security tools) as things it surfaces; silver-ticket use can produce observable anomalies in those categories on Windows, but the technique's offline forging and lack of KDC interaction leave a large, nameable remainder that evades many common monitoring configurations.
- T1558.002responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (incl. process injection, unauthorized access, unusual system behaviour) plus dedicated trained personnel and procedures to respond to alerts (see 5.26), which matches the event-lane definition of `responds` once the silver-ticket use is underway; extent is only partial because the clause's scope is set by organisational requirements rather than mandating universal coverage of all silver-ticket indicators (e.g. offline forging without KDC interaction).
- T1558.003detects — A.8.16 explicitly lists monitoring of network traffic, access to systems/servers, event logs, anomalous behaviour (including known attack characteristics and unusual system behaviour), and real-time/continuous tools that generate alerts on deviations from baseline; Kerberoasting is visible in network traffic (TGS requests for arbitrary SPNs), unusual access patterns to DCs, and anomalous Kerberos behaviour, all of which fall inside the clause's defined scope for detection.
- T1558.003prevents — A.8.16's real-time/periodic monitoring of network traffic, anomalous behaviour, known attack patterns, and unauthorized access can surface Kerberoasting (TGS requests or RC4-encrypted tickets) before the offline brute-force succeeds, but the control only sets scope per business needs and does not mandate the specific detections, encryption upgrades, or policy enforcement that would stop the technique outright.
- T1558.004detects — A.8.16 requires monitoring of network traffic, access attempts, event logs, anomalous behaviour patterns (including unusual system behaviour and unauthorized access), and real-time/periodic anomaly detection against a baseline, which can surface AS-REP roasting indicators such as unusual AS-REQ/AS-REP traffic, LDAP enumeration, or cracking-related anomalies; however, the clause sets scope by organisational requirements rather than mandating universal coverage of all Kerberos or authentication-protocol specifics, leaving a large slice of stealthy or non-anomalous instances undetected.
- T1558.005detects — A.8.16 requires monitoring of network/system/application traffic, access events, logs, resource use, baselines for anomalies (incl. process injection, unusual behaviour, unauthorized access), and real-time/periodic alerting; this surfaces ccache theft on Linux disk paths or anomalous klist/kinit use but does not cover in-memory macOS ccache extraction or all stealthy collection methods, as scope is set by org requirements rather than mandating universal credential-file instrumentation.
- T1559detects — A.8.16 explicitly lists process injection, anomalous system behaviour, and deviations in standard protocols as detectable anomalies against a behavioural baseline, and IPC abuse (especially via COM/DDE/sockets/pipes for execution) produces observable process, resource or network artefacts that fall inside the clause's broad monitoring scope when those telemetry sources are selected; it is only partial because the clause itself sets the monitoring scope rather than mandating coverage of every IPC channel or OS-specific mechanism.
- T1559responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (including process injection and deviations in protocols) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26, which matches the `responds` verb of containing/eradication once the IPC-abuse technique is underway; partial because the clause sets scope by business requirements rather than mandating universal coverage of all IPC surfaces.
- T1559.001detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized code execution, resource anomalies, and malware-associated activity in its monitoring scope and baseline, which directly surfaces COM abuse for local execution on Windows; the remainder is COM objects used only for non-observable side effects such as pure privilege-escalation without process or network artefacts.
- T1559.001responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection and deviations in protocols) and requires timely response procedures to minimize adverse effects once an incident is underway, but the control's scope is set by organizational requirements rather than mandating detection of all COM abuse vectors.
- T1559.002detects — A.8.16 requires monitoring of network/system/application traffic, event logs, resource use, baselines of normal behaviour, and explicit anomalous indicators including process injection and deviations in standard protocols; DDE (an IPC mechanism for command execution, often via Office/CSV poisoning or DCOM) can surface in those observables when it produces detectable anomalies, but the clause sets scope by organisational requirements rather than mandating coverage of all DDE use, leaving a large slice unseen.
- T1559.002responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unusual system behaviour, malware-associated activity, and deviations from baseline), which surfaces T1559.002 once it runs and enables timely response per linked procedures (5.26); it is not the response itself and coverage is scoped by organisational requirements rather than universal.
- T1559.003detects — A.8.16 explicitly lists process injection, anomalous system behaviour, and deviations in protocols as items to baseline and alert on, which can surface some XPC abuse (especially when it manifests as unexpected process or resource behaviour); however the clause's scope is set by organisational requirements rather than mandating coverage of all XPC service calls or client-validation failures, leaving a large slice of this macOS-specific technique outside typical monitoring.
- T1559.003prevents — A.8.16's real-time/periodic monitoring of system behaviour, process activity, resource use, known attack patterns and anomalies (including process injection) can surface or block some XPC abuse vectors on macOS, but the control's scope is set by organisational requirements rather than mandating universal coverage of all XPC service daemons or input sanitisation flaws, leaving a large slice of the technique untouched.
- T1559.003responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection and deviations), which surfaces an in-flight XPC abuse event for dedicated personnel to contain/eradicate per linked 5.26 procedures; this is exactly `responds` but only partial because the clause sets scope by business needs rather than mandating universal instrumentation of all XPC traffic or client-validation failures.
- T1560detects — A.8.16 explicitly lists monitoring for anomalous behaviour patterns, malware-associated activity, known attack characteristics, process injection, deviations in protocols, and resource anomalies, which can surface many T1560 implementations (esp. via anomalous process, file, or network behaviour) but leaves a bounded remainder where the compression/encryption is performed quietly by utilities or libraries that blend with baseline activity.
- T1560.001detects — A.8.16 requires monitoring for anomalous behaviour and known attack characteristics including process injection and deviations in protocols, which can surface many instances of utility-based archiving (e.g. via resource spikes, unusual command lines, or signatures in monitored traffic/logs), but the clause's scope is set by organisational requirements rather than mandating coverage of all such utilities or exfil-prep activity, leaving a large slice unseen.
- T1560.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour patterns, process injection, malware-associated activity, resource use deviations, and unauthorized access attempts, which can surface library-based archiving (especially when it deviates from baseline or matches known malicious patterns), but the control's scope is set by organizational requirements and does not mandate coverage of all library-linked compression prior to exfiltration.
- T1560.003detects — A.8.16 explicitly lists monitoring for process injection, anomalous system behaviour, malware-associated activity, deviations in protocols, resource use baselines, and real-time anomaly detection against a normal baseline, which surfaces many (but not all) custom archival implementations that deviate from expected patterns or leave observable artifacts.
- T1560.003responds — A.8.16's real-time/periodic monitoring for anomalous behaviour (incl. malware-associated activity, process injection, unusual system behaviour, and resource anomalies) can surface the custom archival step once it is underway, enabling timely response per linked 5.26 procedures; partial because the technique is a post-collection data transformation that can be made to blend with normal compression/encryption patterns and is not guaranteed to trigger the configured baseline or signatures.
- T1561detects — A.8.16 explicitly lists monitoring for anomalous behaviour, resource use, unplanned terminations, malware-associated activity, known attack characteristics, unusual system behaviour (including process injection), unauthorized access, and deviations from baseline, which surfaces most T1561 disk-wipe activity in real time or near-real time; the named remainder is fully stealthy wipes that produce none of the listed observables.
- T1561responds — A.8.16's real-time/periodic anomaly detection, baseline monitoring for destructive patterns (e.g. unusual system behaviour, resource overloads, unauthorized access), alerting, and procedures to respond to positive indicators (see 5.26) enable containment once disk-wipe activity is underway, but the clause's scope is set by organizational requirements rather than mandating coverage of all wipe vectors (raw disk writes, MBR corruption, network device erase) so only a slice is addressed.
- T1561.001detects — A.8.16 explicitly lists monitoring of disk/CPU/memory use, anomalous system behaviour (including process injection and deviations), event logs, security-tool logs, and baselines for anomalies such as unplanned terminations or malware-like activity; disk-wiping directly produces observable deviations in resource use, I/O patterns, and system behaviour on the monitored estate, with only the bounded remainder of completely offline or non-monitored devices left uncovered.
- T1561.001recovers — A.8.13 (backup) is the explicit recovery control, but A.8.16's real-time anomaly detection (resource use, unauthorized access, malware-like patterns, process tampering) surfaces the wipe in flight or immediately after, enabling the separate recovery procedures referenced in its own text (see 5.26) to restore from backups before total loss propagates.
- T1561.001responds — A.8.16's real-time/periodic monitoring, anomaly detection (including unusual system behaviour, resource use, unauthorized access), alerting, and procedures to respond to positive indicators in a timely manner (explicitly referencing 5.26 incident response) allow detection and response once disk-wipe activity is underway, but the clause's scope is set by business requirements rather than mandating universal coverage of all wipe vectors (e.g. direct raw-disk drivers or worm-like propagation), leaving a genuine implementation-dependent slice.
- T1561.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour including known attack characteristics (DoS, buffer overflows), unusual system behaviour (process injection, deviations in protocols), resource use anomalies, unauthorized access/scanning, and baseline deviations; disk structure wipe produces observable effects in these categories (e.g. unplanned process termination, boot failures, resource spikes, or MBR/partition anomalies) on the monitored estate, with the bounded remainder being pre-compromise acquisition or purely offline wipes that leave no runtime footprint.
- T1561.002recovers — A.8.13 (backup) is the explicit recovery control, but A.8.16's monitoring of disk/system anomalies, resource use, unauthorized access, and malware-like behaviour (including the explicit example of process injection) surfaces the wipe early enough for timely response procedures (cross-referenced to 5.26) to limit propagation and trigger recovery from intact backups on unaffected systems; the named remainder is systems already wiped before detection.
- T1561.002responds — A.8.16's real-time/continuous monitoring, anomaly detection (including unusual system behaviour, process injection, unauthorized access, resource anomalies), alerting, and explicit procedures to respond to positive indicators in a timely manner (cross-referenced to 5.26 incident response) directly enable containment and eradication once a disk-structure wipe technique is underway.
- T1563detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access attempts, unusual system behaviour, and deviations in protocols, which surfaces many session-hijacking indicators in real time or near-real time; however the clause's scope is set by organisational requirements rather than mandating universal coverage of all hijack vectors (e.g. certain in-memory RDP/SSH manipulations may fall outside chosen telemetry), making the coverage a chosen slice rather than a bounded remainder.
- T1563prevents — A.8.16's real-time/anomaly monitoring (including access to systems/servers, admin configs, event logs, process injection indicators, unauthorized access attempts, and deviations from baseline) can surface session hijacking in flight or block some vectors via detection of anomalous behavior, but does not stop the initial hijack of an existing legitimate remote session (e.g. via stolen tokens/cookies or MITM on telnet/SSH/RDP).
- T1563responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (incl. process injection, unauthorized access, unusual system behaviour) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26, which matches the `responds` verb once the hijack is underway; partial because the clause sets scope by business requirements rather than mandating universal coverage of all hijack indicators across every remote service.
- T1563.001detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized access attempts, and deviations from baseline (including unusual resource use or session patterns) as detectable anomalies, which can surface SSH hijacking in flight; however the clause sets scope by organisational requirements rather than mandating universal coverage of agent sockets, root-level hijacks, or all Linux/macOS behaviours, so only a chosen slice is guaranteed.
- T1563.002detects — A.8.16 explicitly lists process injection, unauthorized access attempts, unusual system behaviour, and anomalous resource/performance deviations in its baseline and anomaly criteria, which surface RDP hijacking (tscon.exe abuse, session theft) when it matches those observables; however the clause's scope is set by organisational requirements rather than mandating host-level session telemetry, leaving many hijacks outside the monitored slice.
- T1563.002prevents — A.8.16's real-time monitoring of network traffic, access attempts, admin configs, anomalous behaviour (including process injection and unauthorized access), and baseline deviations can surface RDP hijacking indicators before or during execution on covered systems, but the clause only sets scope per organisational requirements rather than mandating universal instrumentation that stops the tscon.exe technique outright.
- T1563.002responds — A.8.16 requires real-time/near-real-time monitoring of network, access, system, and anomalous behaviour (including process injection and unauthorized access), plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26, which directly matches the incident-response act of containing/eradication once RDP hijacking is underway.
- T1564detects — A.8.16 explicitly lists monitoring for process injection, unauthorized access, anomalous behaviour, known attack characteristics, and deviations from baseline (including system activity and resource use), which surfaces many T1564 hiding techniques once they produce observable artifacts; it does not cover hidden artifacts that produce no deviation or reside entirely in isolated regions outside the defined monitoring scope.
- T1564prevents — A.8.16 mandates monitoring (incl. baselines, anomalous behaviour, process injection, unauthorized access, resource use, code integrity checks) that can surface many T1564 hiding techniques in real time or near-real time, but the control's scope is set by organisational requirements rather than universal coverage, leaving slices such as isolated virtualised regions or stealth that evades the chosen instrumentation unaddressed.
- T1564responds — A.8.16's real-time/periodic monitoring, anomaly detection (including process injection and unauthorized activity), alerting, and procedures to respond to positive indicators directly address containment once T1564 hiding is underway, but only for detectable artifacts within the scoped baseline rather than all hidden or isolated regions.
- T1564.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, unusual system behaviour, and deviations from baseline (with real-time/continuous tools and alerts), which can surface hidden-file artifacts when they produce observable anomalies, but the clause's scope is set by organisational requirements and does not mandate checking hidden files/directories themselves.
- T1564.002detects — A.8.16 requires monitoring of access, configuration files, event logs, anomalous behaviour (including unusual user/system behaviour and unauthorized access attempts), and baselines of normal access patterns, which can surface hidden-user artifacts on supported platforms when those changes produce observable deviations; the clause sets scope by organisational requirements rather than mandating universal coverage of every hiding method or platform, so only a slice is caught.
- T1564.003detects — A.8.16 explicitly lists process injection, unusual system behaviour, anomalous resource use, and deviations from baseline as things the monitoring system should surface; hidden-window techniques produce observable anomalies in process trees, window management, registry/plist changes, or off-screen desktops that fall inside the named scope, but the clause sets scope by organisational requirements rather than mandating universal coverage of every hiding method on every platform, leaving a genuine slice unreached.
- T1564.003responds — A.8.16's real-time/periodic monitoring, anomaly detection (including process injection, unusual behaviour, unauthorized access), alerting, and procedures to respond to positive indicators in a timely manner (cross-referencing 5.26 incident response) can surface and trigger response to a realized hidden-window technique once it produces observable deviations from baseline, but this is only a slice of the technique's stealthy variants that may produce no detectable anomaly.
- T1564.004detects — A.8.16 explicitly lists monitoring for process injection, anomalous behaviour, malware-associated activity, unauthorized access, and deviations from baseline (including file-system and resource anomalies), which can surface NTFS ADS/EA abuse in real-time or periodic monitoring of logs, file activity and system behaviour; however the clause's scope is set by organisational requirements rather than mandating universal deep filesystem attribute inspection, leaving many stealthy uses outside typical coverage.
- T1564.005detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection), resource use, file system deviations, and security tool logs, which can surface many hidden file system implementations as anomalies or via signatures/patterns; however the clause's scope is set by organisational requirements rather than mandating universal deep storage or boot-sector inspection, leaving a genuine slice of stealth implementations (e.g. reserved sectors or non-standard fragmentation on unmonitored platforms) unseen.
- T1564.005responds — A.8.16 configures monitoring (incl. anomalous file-system behaviour, resource use, malware patterns and real-time alerts) to surface and enable timely response to an in-progress hidden file system technique, but the clause itself only detects and notifies rather than performing containment/eradication.
- T1564.006detects — A.8.16 explicitly lists monitoring for process injection, anomalous system behaviour, resource usage deviations, unauthorized access attempts, and network traffic patterns, which can surface many (but not all) indicators of a virtual instance running on the host; however, activity wholly inside the guest (especially with hidden/rogue VMs or non-bridged networking) evades host-level monitoring by design, and the clause's scope is set by organisational requirements rather than mandating guest introspection.
- T1564.006responds — A.8.16 requires real-time/periodic monitoring, anomaly detection against baseline (incl. process injection, unusual behaviour, unauthorized access), alerting and dedicated response personnel/procedures that act on positive indicators to contain adverse events once underway; this surfaces and responds to many T1564.006 indicators on the host but cannot see inside the virtual instance itself, leaving a genuine slice of the technique (and its artifacts) unreachable.
- T1564.007detects — A.8.16 explicitly lists process injection, code tampering checks, anomalous behaviour baselines, and real-time/periodic monitoring of system/application activity and security-tool logs, which can surface VBA stomping when it manifests as unexpected p-code execution, macro anomalies, or process behaviour; however the clause's scope is set by organisational requirements rather than mandating VBA/p-code-specific inspection, leaving many document-based stomps outside monitored telemetry.
- T1564.008detects — A.8.16 explicitly lists monitoring of inbound/outbound email traffic, access to critical applications (including email systems), event logs, anomalous behaviour patterns, and real-time alerting tuned to a baseline; this surfaces the creation or effect of hiding rules (e.g. via unusual mailbox activity or suppressed alerts) within the chosen monitoring scope, but the clause itself sets that scope by business requirements so coverage of mailbox-rule artefacts is an implementer-chosen slice rather than a bounded remainder.
- T1564.009detects — A.8.16 explicitly lists process injection and anomalous system behaviour as detectable via baseline monitoring of system activity, resource use, and code execution integrity, which can surface resource-fork abuse when it manifests as unusual file attributes, offsets, or execution patterns; however the clause's scope is set by organisational requirements rather than mandating universal coverage of macOS-specific extended-attribute or resource-fork artefacts, leaving a genuine implementation-dependent slice undetected.
- T1564.009prevents — A.8.16's baseline monitoring for anomalies (incl. process injection, unauthorized code execution, resource use deviations, and file attribute anomalies) can surface resource-fork abuse on macOS when it deviates from the established normal, but the control only sets scope and does not mandate detection of every possible fork-based hiding or execution path.
- T1564.009responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. process injection, unauthorized access, malware patterns), alerting, and timely response procedures directly surface and enable response to resource-fork hiding once the technique is in flight on monitored macOS systems, but scope is set by org requirements so coverage of this macOS-specific technique is not assured.
- T1564.010detects — A.8.16 explicitly lists process injection and anomalous system behaviour as items to baseline and monitor for in real time, which surfaces many T1564.010 realizations that combine with or follow injection; it does not guarantee detection of every in-memory PEB overwrite, especially when the final observed command line matches the benign baseline.
- T1564.010responds — A.8.16's real-time/periodic monitoring, anomaly detection (including process injection and unusual behaviour), alerting, and procedures to respond to positive indicators directly enable containment/eradication once the PEB-overwrite technique is underway on Windows, but the clause sets scope by requirements rather than mandating universal depth so coverage of this specific in-memory manipulation is an implementer-chosen slice.
- T1564.011detects — A.8.16 explicitly lists process injection, anomalous process termination, unusual system behaviour, and deviations from baseline as detectable via continuous monitoring of system activity, resource use, and event logs; however the specific mechanism of ignoring interrupt signals (e.g. nohup or -ErrorAction SilentlyContinue) is a narrow, command-line evasion slice that is not named and may produce no observable anomaly if the process simply continues without triggering listed indicators.
- T1564.011responds — A.8.16's real-time/periodic monitoring, anomaly detection (including process injection and unusual behaviour), alerting, and procedures to respond to positive indicators directly enable containment/eradication once the ignore-interrupts technique is underway, but scope is set by organisational requirements rather than mandating coverage of this specific evasion.
- T1564.012detects — A.8.16 explicitly lists monitoring for anomalous behaviour, malware-associated activity, process injection, unauthorized access, and security tool logs (including AV), which can surface abuse of existing exclusions when the drop or subsequent activity deviates from the established baseline; however the control sets its own scope by business requirements rather than mandating coverage of every exclusion or every hidden artifact, leaving a slice determined by the implementer.
- T1564.013detects — A.8.16 explicitly lists process injection, anomalous system behaviour, resource use deviations, and monitoring of system/network activity and logs as detection targets; bind mounts that falsify /proc for utilities like ps/top produce observable anomalies in process metadata, resource patterns or kernel-level discrepancies that fall inside the clause's baseline-driven, real-time/periodic monitoring scope, but the control's scope is set by organisational requirements rather than mandating universal deep host/process instrumentation, leaving a genuine slice of stealthy implementations undetected.
- T1564.014detects — A.8.16 explicitly lists monitoring for process injection, anomalous behaviour, integrity deviations, and malware-associated activity, which can surface xattr abuse when the loader or extraction step produces observable anomalies; the clause's scope is set by organisational requirements rather than mandating xattr inspection, so only a slice is covered.
- T1565detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection), unauthorized access, and deviations from baseline that can surface data manipulation when it produces observable anomalies or signatures; however the clause's scope is set by organisational requirements rather than mandating coverage of every stealthy or non-anomalous data manipulation, leaving a large slice of T1565 (especially silent or in-band changes) unreached.
- T1565responds — A.8.16 requires real-time/periodic monitoring, anomaly detection against baseline (including process injection, unauthorized access, unusual behaviour), alert generation, and timely procedures to respond to positive indicators per 5.26, which directly matches the `responds` verb once manipulation is underway; partial because scope is set by organisational requirements rather than mandating universal coverage of all T1565 vectors (e.g. subtle post-gathering manipulation in complex offline systems may not trigger monitored anomalies).
- T1565.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access, unusual system behaviour (including process injection), integrity checks on executed code, and deviations from baseline that can surface stored-data manipulation after the fact; however the clause's scope is set by organisational requirements rather than mandating coverage of every stored-data target, leaving a large slice of file/database tampering outside monitored observables.
- T1565.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, process injection, unauthorized access, unusual system behaviour, network traffic, and resource anomalies, which can surface some instances of in-transit data manipulation (especially network-borne or process-intercept cases that deviate from baseline), but the clause's scope is set by organisational requirements rather than mandating coverage of all transmission mechanisms or process-memory manipulations, leaving a large implementer-chosen slice unreached.
- T1565.002responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (incl. process injection, unauthorized access, malware patterns, unusual system behaviour) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26, which directly matches the `responds` verb once the technique is underway; partial because the clause sets scope by business requirements rather than mandating universal coverage of all transmission paths or process-intercept opportunities named in the technique.
- T1565.003detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized access attempts, and baseline deviations as detectable items, which surface many runtime manipulation precursors or effects (esp. binary tampering or process anomalies); however the clause's scope is set by organisational requirements rather than mandating coverage of all runtime data manipulation vectors (e.g. complex in-memory data alteration without observable process or network artefacts), leaving a genuine slice uncovered.
- T1565.003responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (incl. process injection, unauthorized access, unusual system behaviour, malware patterns) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26, which directly matches the `responds` verb once the technique is underway; partial because the clause sets scope by business needs rather than mandating universal coverage of every runtime data manipulation vector (e.g. binary alterations or masquerading on unmonitored complex systems).
- T1566detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, malware-associated traffic, unauthorized access attempts, and unusual user/system behaviour (including process injection), which surfaces many post-delivery indicators of a phishing campaign once it reaches the victim environment; it does not detect the social-engineering delivery or spoofing before the message arrives, and scope is set by organisational requirements rather than mandating universal coverage.
- T1566responds — A.8.16 explicitly requires timely procedures to respond to positive indicators from monitoring (including anomalous behaviour tied to phishing such as malicious links, attachments, or known attack patterns) in order to minimize adverse effects, with dedicated personnel and alerting; this is the `responds` act once the technique is underway, but only for the monitored slice rather than all delivery vectors or social-engineering aspects.
- T1566.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour, malware-associated activity, known attack characteristics, process injection, unauthorized access attempts, and real-time alerts on deviations from baseline, which surfaces spearphishing attachment delivery and execution artifacts in scope (e.g. email traffic, attachment opens, payload behaviour); it does not cover the social-engineering lure or email boundary evasion before delivery.
- T1566.001responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. malware signatures, process injection, unauthorized access), alerting, and procedures to respond to positive indicators directly enable containment/eradication once a spearphishing attachment has been opened and is executing, but only for the post-delivery execution slice (not the email delivery or social engineering itself).
- T1566.002detects — A.8.16 explicitly lists monitoring of inbound/outbound traffic, access attempts, logs from security tools (firewalls, web filters, IDS/IPS), anomalous user/system behaviour, and known attack patterns, which can surface many post-delivery indicators of a spearphishing link (e.g. unusual clicks, malicious domain access, OAuth consent anomalies); it does not cover the email vector itself or pre-click social engineering.
- T1566.002responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. malicious links, unauthorized access, malware patterns), alerting, and procedures to respond to positive indicators directly enable timely response to minimize adverse effects once a spearphishing link is delivered and acted on (see 5.26 cross-ref), but this is only a slice as the control is scoped by org requirements and does not itself perform containment/eradication.
- T1566.003detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection), unauthorized access attempts, and real-time alerts on deviations from baseline, which can surface post-delivery indicators of a successful spearphishing-via-service payload; however the technique's core (social engineering via external non-enterprise services) occurs outside the monitored enterprise scope and leaves a large pre-compromise slice undetected.
- T1566.003responds — A.8.16 requires real-time/periodic monitoring of network traffic, access attempts, anomalous behaviour (including malware patterns and unauthorized access), and dedicated response to alerts, which can surface and trigger response to spearphishing delivery via third-party services once it reaches monitored enterprise endpoints or networks; partial because the technique occurs on external non-enterprise services outside the monitoring scope set by business requirements.
- T1566.004detects — A.8.16 explicitly lists monitoring for anomalous user/system behaviour, unusual access patterns, unauthorized access attempts, and social-engineering-linked indicators (e.g. process injection, malware activity, anomalous traffic), which surfaces many post-vishing execution artifacts on supported platforms, but the control's scope is set by organizational requirements and does not mandate coverage of the voice channel or pre-execution social engineering itself.
- T1566.004responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (incl. unusual user behaviour, unauthorized access attempts, and social-engineering-linked patterns such as malicious domains or MFA-prompt anomalies) plus dedicated, trained personnel and procedures to respond to alerts in a timely manner per 5.26, which directly matches the `responds` verb once the vishing technique is underway; partial because the clause's scope is set by organisational requirements rather than mandating universal voice-channel or telephony monitoring, leaving a slice of vishing calls outside the monitored baseline.
- T1567detects — A.8.16 explicitly requires monitoring of outbound network traffic, anomalous behaviour patterns, activity from known malicious domains/IPs, deviations in protocols, and real-time alerting on baseline deviations; T1567 is outbound exfiltration that routinely produces observable anomalies in traffic volume, destinations, or patterns even when disguised over legitimate web services.
- T1567prevents — A.8.16 requires monitoring of outbound network traffic, anomalous behaviour, known attack patterns and deviations from baseline (including unusual data flows), which can surface and thereby stop some exfiltration-over-web-service attempts before completion, but the control's scope is set by organisational requirements rather than mandating universal outbound inspection or blocking, leaving many legitimate-looking exfil cases untouched.
- T1567responds — A.8.16 requires real-time/periodic monitoring of network traffic, anomalous behaviour (incl. unusual outbound patterns), security-tool logs and alert generation; this surfaces an ongoing exfiltration-over-web-service event so dedicated personnel can respond per linked 5.26, but the clause itself only detects and notifies rather than performing the containment/eradication act named by `responds`.
- T1567.001detects — A.8.16 explicitly includes monitoring of outbound network traffic, anomalous behaviour patterns, known malicious domains/IPs, and unusual system behaviour (with process injection as an explicit example), which can surface exfiltration to a code repo when it deviates from the established baseline; however the clause sets monitoring scope by organisational requirements rather than mandating universal coverage of all API-based HTTPS exfil, leaving a large slice of conformant implementations that would miss it.
- T1567.001responds — A.8.16 requires real-time/periodic monitoring of network traffic, anomalous behaviour (incl. unusual outbound patterns), security-tool logs and alert generation; this surfaces an ongoing exfiltration once underway so that 5.26 response procedures can contain/eradicate it, but the clause's scope is set by organisational requirements rather than mandating universal coverage of all API-based HTTPS exfil to code repos (e.g. legitimate-looking GitHub traffic from approved hosts may stay inside the chosen baseline).
- T1567.002detects — A.8.16 explicitly requires monitoring of outbound network traffic, anomalous behaviour patterns, known malicious domains/IPs, unusual system behaviour, and real-time alerting on deviations from baseline, which directly surfaces exfiltration to cloud storage when it deviates from normal (the bulk of cases), with the bounded remainder being fully covert use that blends with legitimate traffic to the same services.
- T1567.002responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (incl. unusual outbound traffic, known malicious patterns, and deviations from baseline), alerting, and timely response procedures to minimize adverse-event impact once the exfiltration is underway; this matches `responds` but is only partial because the clause sets scope by org requirements rather than mandating universal coverage of all cloud-storage exfil channels or guaranteeing containment/eradication.
- T1567.003detects — A.8.16 explicitly lists monitoring of outbound network traffic, anomalous behaviour patterns, known malicious domains/IPs, and unusual system behaviour (including deviations that could surface pastebin exfil), but the clause sets scope by organisational requirements rather than mandating universal coverage of all possible text-storage exfil channels or payloads.
- T1567.003prevents — A.8.16's outbound network traffic monitoring, baseline of normal behaviour, anomaly detection (including known malicious domains/IPs and unusual patterns), and real-time alerts can surface or block some exfiltration to pastebin-like sites when it deviates from the established baseline, but the clause only sets monitoring scope per organisational requirements rather than mandating universal outbound controls or DLP that would stop the technique outright.
- T1567.003responds — A.8.16 requires real-time/periodic monitoring of network traffic, anomalous behaviour (incl. unusual outbound patterns), security-tool logs, and alert generation on deviations from baseline; this surfaces an ongoing exfiltration to a text-storage site once underway so dedicated personnel can respond per linked 5.26, but the clause itself only detects and notifies rather than performing containment/eradication.
- T1567.004detects — A.8.16 explicitly includes monitoring of outbound network traffic, anomalous behaviour, known malicious patterns, unusual system behaviour and real-time alerts tuned to a baseline; this surfaces webhook exfiltration when it deviates from the baseline or matches signatures, but the clause sets scope by organisational requirements rather than mandating universal coverage of all HTTPS/SaaS blends, leaving a large slice unseen.
- T1567.004prevents — A.8.16 requires monitoring of network traffic, anomalous behaviour, known malicious patterns/IPs, and deviations from baseline (including outbound HTTPS to SaaS), which can block some webhook exfil that deviates from normal but not the bulk that blends with legitimate SaaS traffic or uses approved endpoints.
- T1567.004responds — A.8.16 surfaces anomalous outbound traffic, webhook patterns, or deviations from baseline (e.g. unusual HTTPS posts to SaaS endpoints) once underway and feeds them to 5.26 response procedures, but its core mechanism is detection/monitoring rather than containment or eradication of the exfiltration event itself.
- T1568detects — A.8.16 explicitly lists monitoring for anomalous behaviour, malware-associated traffic, known malicious IPs/domains, unusual system behaviour (including process injection), and real-time/periodic anomaly detection against a baseline, which surfaces many T1568 manifestations (e.g. unexpected C2 domains or connections); it does not guarantee detection of novel algorithmically-generated or encrypted dynamic resolutions outside the configured scope or signature set.
- T1568responds — A.8.16's real-time/periodic anomaly detection, baseline comparison, and alert/response procedures surface and enable timely reaction to dynamic-resolution C2 indicators (e.g. unusual domains, IPs, traffic patterns, or malware beacons) once underway, but the clause's scope is set by organizational requirements rather than mandating universal coverage of all resolution algorithms or platforms.
- T1568.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, malicious IP/domain traffic, unusual system behaviour (including process injection), and real-time/periodic anomaly detection against a baseline, which surfaces fast-flux C2 patterns when they match those observables; however the clause sets scope by organisational requirements rather than mandating universal DNS-specific instrumentation, leaving a slice of fast-flux (e.g. purely passive double-flux without observable anomalies) unreached.
- T1568.001responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. malicious domains, unusual traffic/behaviour), alerting and timely response procedures directly enable containment/eradication once Fast Flux DNS C2 is underway, but scope is set by org requirements so coverage of this specific technique is not guaranteed.
- T1568.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour, malware-associated traffic, known malicious domains, process injection, and deviations in protocols, which surfaces DGA-generated C2 traffic or fallback channel activity when it crosses monitored networks, logs, or baselines; however the technique's domain generation occurs on adversary infrastructure and many DGA domains are never contacted, leaving a large slice unseen.
- T1568.002responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. malicious domains, botnet C2, unusual traffic/behaviour), alerting and response procedures can surface and trigger response to DGA-driven C2 once underway, but the clause's scope is set by org requirements so coverage of DGA-generated domains is not mandated.
- T1568.003detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection and protocol deviations), network traffic, and baseline deviations that can surface DNS-calculation C2; scope is set by organisational requirements rather than mandating coverage of every DNS-response calculation, leaving a genuine slice uncovered.
- T1568.003responds — A.8.16's real-time/periodic monitoring, anomaly detection (including known attack patterns, unusual system behaviour, and traffic), alerting, and timely response procedures can surface and trigger response to DNS-calculation C2 once underway, but the clause's scope is set by organisational requirements rather than mandating coverage of this specific calculation technique.
- T1569detects — A.8.16 explicitly lists monitoring for process injection, anomalous system behaviour, resource use, unauthorized access, event logs, security tool logs and deviations from baseline, all of which surface T1569 service abuse either in real time or near-real time; the named remainder is service creations or executions that produce no observable deviation within the scoped items.
- T1569responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. process injection, unauthorized access, malware-like activity), alerting, and procedures to respond to positive indicators in a timely manner (explicitly linking to 5.26 incident response) allow containment/eradication once T1569 service abuse is underway, but scope is set by org requirements so coverage of all service-abuse vectors is not assured.
- T1569.001detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unusual resource use, and deviations in standard protocols as detectable anomalies, and launchctl abuse to load/start agents or daemons produces observable process, launchd, and resource events that fall inside the clause's configurable monitoring scope; however the clause sets scope by organisational requirements rather than mandating universal coverage of every macOS launchctl invocation, leaving a slice determined by the implementer
- T1569.001prevents — A.8.16's baseline monitoring for anomalous behaviour, process activity, unauthorized access, and known attack patterns (including process injection) can surface or constrain some launchctl abuse on macOS, but the clause sets scope by organisational requirements rather than mandating universal instrumentation of launchd/launchctl calls, leaving a large slice of possible abuse undetected at source.
- T1569.001responds — A.8.16 requires real-time/periodic monitoring of system activity, process anomalies, and alerts with dedicated response personnel and procedures that feed into 5.26 incident response once an event is underway; this surfaces and enables response to launchctl abuse (e.g. via anomalous process, unauthorized load/start, or deviation from baseline) but only for the monitored slice, as scope is set by organizational requirements rather than mandating universal coverage of macOS launchd activity.
- T1569.002detects — A.8.16 explicitly lists monitoring of system/network activity, event logs, resource use, process anomalies, unauthorized access attempts, and specifically calls out process injection and malware-associated behaviour; service execution via the service control manager (services.exe, sc.exe, PsExec) produces observable artifacts (new/modified services, anomalous process starts, resource spikes, event log entries) that fall inside the defined baseline-and-anomaly scope, with only the bounded remainder of completely stealthy or non-logged service creations outside monitored coverage.
- T1569.002prevents — A.8.16's baseline-driven anomaly detection (incl. process injection, unauthorized access, unusual system behaviour, resource use, and real-time alerts) can surface or block some service-control-manager abuse when it deviates from the established normal, but the control only sets monitoring scope and does not prohibit the technique itself.
- T1569.002responds — A.8.16 surfaces anomalous service-related activity (e.g. process injection, unauthorized access, unusual system behaviour, resource anomalies) in real time or near-real time and feeds it to the 5.26 response procedure for containment/eradication once the technique is underway; partial because the clause sets scope by business requirements rather than mandating universal coverage of every service execution vector or remote sc.exe/PsExec use.
- T1569.003detects — A.8.16 requires monitoring of system/network activity, resource use, process anomalies, and deviations from baseline (including process injection and unusual behaviour), which can surface systemctl abuse when it produces observable anomalies, but the clause sets scope by organisational requirements rather than mandating detection of every legitimate-looking service start/stop/enable via systemctl.
- T1569.003prevents — A.8.16 requires monitoring (incl. system/network activity, resource use, process anomalies, and baseline deviations such as unusual behaviour or unauthorized access) that can surface systemctl abuse when it deviates from the established baseline, thereby preventing some but not all instances of the technique depending on scope and configuration.
- T1569.003responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (including process injection, unauthorized access, unusual system behaviour, and resource anomalies) plus dedicated trained personnel and procedures to respond to alerts in a timely manner per 5.26, which directly matches the responds verb once the systemctl abuse is underway; partial because the clause sets scope by business requirements rather than mandating universal coverage of every possible Linux systemctl invocation.
- T1570detects — A.8.16 explicitly lists monitoring of network traffic, file-access events, resource anomalies, process injection indicators, and deviations from baseline (including unusual system behaviour), which surfaces many T1570 file-copy events (especially SMB/RDP, native tools, or anomalous patterns), but the clause sets scope by organisational requirements rather than mandating universal coverage of every lateral-transfer vector or platform.
- T1570responds — A.8.16's real-time/periodic monitoring, anomaly detection (including unusual file-transfer patterns, resource spikes, or known attack signatures), alerting, and procedures to respond to positive indicators directly enable containment/eradication once lateral tool transfer is underway, but the clause's scope is set by business requirements rather than mandating universal coverage of all transfer vectors or platforms.
- T1571detects — A.8.16 explicitly includes monitoring of inbound/outbound network traffic, baselines for normal behaviour, anomalous patterns, and known attack characteristics, which can surface non-standard port usage when it deviates from the established baseline or matches signatures; however the clause sets scope by organisational requirements rather than mandating universal deep packet or protocol-anomaly instrumentation, so only a slice chosen by the implementer is guaranteed to be caught.
- T1571prevents — A.8.16 requires monitoring of network traffic, baselines, anomalous patterns (incl. non-standard ports, protocol deviations, known attack characteristics), and real-time alerts, which can block or deter use of non-standard ports when they deviate from the established baseline; however, the control sets scope by business requirements rather than mandating universal detection of all such pairings, leaving a slice of implementations that miss it.
- T1571responds — A.8.16's real-time/periodic monitoring, anomaly detection (including unusual protocols, non-standard traffic patterns, and deviations), alerting, and procedures to respond to positive indicators directly enable containment/eradication once T1571 is underway, but the clause sets scope by business needs rather than mandating universal coverage of all non-standard port abuse.
- T1572detects — A.8.16 explicitly lists monitoring of inbound/outbound network traffic, anomalous behaviour patterns, known attack characteristics, deviations in standard protocols, and real-time signature/behaviour-based tools that can surface protocol tunneling (e.g. unexpected encapsulation, DoH, or SSH tunnels) when it falls inside the scoped baseline; the remainder is implementation-defined scope that may lawfully omit the specific traffic or layer where tunneling occurs.
- T1572prevents — A.8.16 mandates monitoring of network traffic, anomalous behaviour, known attack characteristics, unusual protocols, and deviations from baseline (including encrypted tunnels that blend with or deviate from expected patterns), which can block the technique from succeeding when it produces detectable anomalies; however the clause sets scope by organisational requirements rather than mandating universal deep-packet or protocol-decapsulation coverage, leaving many stealthy or low-volume tunnels inside the implementer-chosen slice.
- T1572responds — A.8.16's real-time/periodic monitoring of network traffic, anomalous behaviour, known attack patterns, and alerting feeds directly into 5.26 response procedures once tunneling is underway, but the control's scope is set by organisational requirements rather than mandating coverage of all tunneling variants (e.g. encrypted SSH, DoH) and its mechanism stops at detection/alerting without performing containment or eradication itself.
- T1573detects — A.8.16 explicitly lists monitoring for anomalous behaviour, malware-associated traffic, known attack characteristics, process injection, deviations in protocols, and real-time alerts on patterns, which surfaces many (but not all) observable indicators of custom C2 encryption channels; the remainder is fully encrypted traffic that blends with legitimate TLS without triggering those signatures or baselines.
- T1573.001detects — A.8.16 explicitly lists monitoring for anomalous network traffic, known attack characteristics, malware-associated patterns, deviations in protocols, and real-time anomaly detection against baselines, which can surface C2 traffic concealed by symmetric crypto (e.g. via signatures or behavioral deviations); however the clause sets scope by organizational requirements rather than mandating universal coverage of all encrypted flows, leaving a large slice of implementations that see nothing of it
- T1573.002detects — A.8.16 explicitly lists monitoring for anomalous network traffic, known attack characteristics, malware-associated patterns, unusual system behaviour (including process injection), and deviations in protocols, which can surface C2 using asymmetric crypto when it produces observable anomalies or signatures, but the control's scope is set by organisational requirements rather than mandating coverage of all encrypted C2, leaving a large slice of stealthy implementations undetected.
- T1574detects — A.8.16 explicitly lists process injection, anomalous code execution, unauthorized binaries, and baseline deviations among the monitored items, which surface many (but not all) hijack techniques such as DLL search-order or registry poisoning after they occur.
- T1574prevents — A.8.16's baseline monitoring and anomaly detection (including process injection, unauthorized code execution, tampering checks, and unusual system behaviour) can surface some hijack techniques in flight but does not stop the initial execution-flow manipulation from occurring.
- T1574responds — A.8.16 configures monitoring (incl. process injection, anomalous behaviour, code tampering, resource use) to surface T1574 in flight and generate tuned alerts for dedicated personnel to respond to, but the clause itself performs only detection and notification, not the containment/eradication act named by `responds` (see 5.26).
- T1574.001detects — A.8.16 explicitly lists process injection and anomalous system behaviour (plus code-integrity checks, resource baselines, and real-time anomaly alerting) as monitoring targets, which surfaces many DLL-hijacking manifestations after they occur; it does not instrument every possible side-load, search-order, or phantom variant, especially those that stay within the chosen monitoring scope.
- T1574.001prevents — A.8.16's baseline monitoring for anomalous behaviour (incl. process injection, unauthorized code execution, and deviations in standard protocols) can surface and thereby constrain some DLL sideloading/hijacking attempts in real time, but the clause sets scope by organisational requirements rather than mandating universal detection of all search-order or phantom hijacks, leaving a large slice of the technique untouched.
- T1574.001responds — A.8.16 surfaces anomalous behaviour (incl. process injection and deviations) in real time or near-real time and feeds alerts to the 5.26 response procedure, but the control itself performs none of the core respond activities (contain/eradicate) and the technique's in-process mechanics often leave no observable artefact at the network/application layers the clause explicitly scopes
- T1574.004detects — A.8.16 explicitly lists process injection and anomalous system behaviour (plus resource/performance deviations, unsigned/tampered code execution) among the anomalies its monitoring baseline and tools are configured to surface in real time or at intervals; dylib hijacking is a form of library-based injection that can manifest in those observables, but the clause's scope is set by organisational requirements rather than mandating universal coverage of every macOS loader search-path attack, leaving a genuine slice uncovered.
- T1574.004prevents — A.8.16 requires monitoring of system behaviour, resource use, code execution authorisation, and anomalies such as process injection or deviations, which can surface dylib hijacking in flight on covered macOS systems; however the clause sets scope by organisational requirements rather than mandating universal instrumentation of all dylib loads or search-path checks, leaving a slice determined by the implementer.
- T1574.004responds — A.8.16's real-time/periodic monitoring, anomaly detection (including process injection and unusual behaviour), alerting, and procedures to respond to positive indicators directly address an in-flight dylib hijacking once underway, but the clause's scope is set by organisational requirements rather than mandating universal coverage of all dylib loads or paths.
- T1574.005detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized code execution, resource anomalies, and baseline deviation monitoring (including file-system and installer-related activity via logs, integrity checks, and real-time tools), which surfaces many instances of T1574.005 in flight or post-execution; it is scoped by organizational requirements rather than mandating universal coverage of all installer/temp/permission-hijack variants.
- T1574.005responds — A.8.16's real-time/periodic monitoring, anomaly detection (including process injection and unauthorized access), alerting, and procedures to respond to positive indicators in a timely manner (see 5.26) allow response once the installer-hijacking technique is underway, but the clause's scope is set by organizational requirements rather than mandating coverage of installer/TEMP behavior or privilege-escalation artifacts, leaving a large slice uncovered.
- T1574.006detects — A.8.16 explicitly lists process injection and anomalous system behaviour (including deviations in standard protocols or library loading) among the monitored anomalies, and requires real-time/periodic monitoring of system activity, resource use, and security-tool logs that can surface LD_PRELOAD-style hijacks; however the clause leaves final scope to organisational requirements, so coverage of this Linux/macOS technique is a chosen slice rather than guaranteed.
- T1574.006prevents — A.8.16's baseline monitoring for anomalous behaviour, process injection signatures, unauthorized library loads, and real-time alerts can stop many LD_PRELOAD/DYLD_INSERT_LIBRARIES hijacks before payload execution succeeds, but the clause sets scope by organisational requirements rather than mandating universal detection of every environment-variable manipulation, leaving a slice uncovered.
- T1574.007detects — A.8.16 explicitly lists monitoring for process injection, anomalous system behaviour, unauthorized access attempts, unusual resource use, and deviations from baseline (including via real-time/continuous tools and alerts), which surfaces many instances of PATH hijacking when it manifests as anomalous execution or process behaviour; it does not guarantee coverage of stealthy or non-anomalous modifications to $PATH/$HOME or /etc/paths.d that produce no observable deviation.
- T1574.007prevents — A.8.16's real-time/periodic monitoring of system behaviour, resource use, process termination, known attack patterns and anomalous activity (including process injection and deviations) can surface PATH hijacking when it manifests as unusual execution or resource patterns, but the control only detects after the technique has already run and does not stop the environment-variable modification or the resulting malicious binary execution.
- T1574.008detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized access attempts, and deviations from baseline (including resource/performance anomalies and known attack patterns) as detectable via continuous monitoring of system activity, logs, and code execution integrity; search-order hijacking produces observable artifacts in those categories on Windows but is only a slice of what the control's configurable scope and tooling will surface.
- T1574.008prevents — A.8.16's baseline monitoring for anomalous behaviour, process injection indicators, unauthorized file execution, and real-time alerts can surface or block some search-order hijack executions (e.g. via known malicious patterns or resource anomalies), but the control only sets a scoped monitoring practice rather than mandating mechanisms that stop the placement or loading of the hijacking binary itself.
- T1574.008responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. process injection, unauthorized access, malware-like activity), alerting, and procedures to respond to positive indicators directly enable containment/eradication once a search-order hijacking payload executes and produces observable effects, but scope is set by org requirements so coverage of this specific technique is not guaranteed.
- T1574.009detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized access attempts, and baseline-deviation monitoring (including executable authorization and tampering checks) that can surface T1574.009 when it triggers observable anomalies, but the control's scope is set by organisational requirements rather than mandating coverage of all unquoted-path hijacks, leaving a large slice unseen.
- T1574.009prevents — A.8.16's baseline + anomaly detection (incl. process injection, unauthorized executables, unusual system behaviour, and code-tampering checks) can surface the hijack when the malicious binary runs or when anomalous access occurs, but does not stop the unquoted path from being created or resolved in the first place.
- T1574.009responds — A.8.16 configures monitoring (incl. process injection, anomalous behaviour, unauthorized access, and real-time alerts) that surfaces an in-flight path-interception execution so dedicated personnel can respond per 5.26 procedures; it is not the response itself and coverage is scoped by organisational requirements rather than mandating detection of every unquoted-path case.
- T1574.010detects — A.8.16 explicitly lists process injection, anomalous system behaviour, unauthorized access attempts, and deviations from baseline (including resource use and executed code integrity) as detectable anomalies, which surfaces many instances of this hijack technique in real time or near-real time; it is only partial because the clause sets scope by organisational requirements rather than mandating universal coverage of every service binary or permission change.
- T1574.010responds — A.8.16's real-time/periodic monitoring of system behaviour, process anomalies, unauthorized access attempts, and known attack patterns (including process injection) can surface the hijack once the malicious binary executes under the service, enabling timely response per linked 5.26 procedures; it is not guaranteed for all variants and does not act on the permission flaw itself.
- T1574.011detects — A.8.16 requires monitoring of Registry-related activity (access to critical config files, event logs, anomalous behaviour such as unauthorized access or process injection) and can surface the hijacking when it occurs or produces observable anomalies, but the clause sets scope by organisational requirements rather than mandating universal deep Registry auditing, leaving many permission-weakness exploits outside the monitored slice.
- T1574.012detects — A.8.16 explicitly lists process injection and anomalous system behaviour (including deviations in standard protocols) among the items its monitoring baseline and tools are configured to surface in real time or at intervals; COR_PROFILER is a form of in-process execution-flow hijacking that can produce observable anomalies in .NET process loading and behaviour, but the clause's scope is set by organisational requirements rather than mandating universal host-level instrumentation, so only a slice is covered.
- T1574.012prevents — A.8.16's baseline monitoring for anomalous behaviour, process injection signatures, unauthorized code execution, and real-time alerts can stop many COR_PROFILER hijacks from succeeding or persisting, but the clause sets scope by organisational requirements rather than mandating universal instrumentation of every .NET CLR load or in-memory environment variable manipulation.
- T1574.012responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection and deviations from baseline), which surfaces the technique once underway so dedicated personnel can respond per linked 5.26 procedures; partial because the clause sets scope by organisational requirements rather than mandating universal detection of every in-memory or registry-based COR_PROFILER abuse.
- T1574.013detects — A.8.16 explicitly lists process injection, anomalous system behaviour, and code-tampering checks as monitoring targets, which directly surface KernelCallbackTable hijacks when they deviate from the established baseline; the remainder is that the clause sets scope by organisational requirements rather than mandating universal deep host instrumentation, so some implementations remain blind to in-process PEB mutations.
- T1574.013prevents — A.8.16 requires monitoring for anomalous behaviour including process injection and deviations in standard protocols, which surfaces many (but not all) KernelCallbackTable hijacks once they trigger a monitored event; the control's scope is set by organisational requirements rather than mandating universal coverage of in-process memory tampering, leaving a slice of stealthy or out-of-scope instances unprevented.
- T1574.013responds — A.8.16 surfaces anomalous behaviour such as process injection and unusual system behaviour in real time or near-real time, enabling the 5.26 response procedure once the KernelCallbackTable hijack (a stealthy form of execution-flow tampering) is underway; the remainder is that the technique can complete and self-restore before detection occurs, and the clause's scope is set by organisational requirements rather than mandating universal coverage of every in-process callback-table mutation.
- T1574.014detects — A.8.16 explicitly lists process injection and anomalous system behaviour as monitoring targets, which surfaces AppDomainManager hijacking when it deviates from baseline; scope is set by organisational requirements rather than mandating host-level visibility of every .NET AppDomain load, leaving a slice unseen
- T1574.014prevents — A.8.16's baseline monitoring for anomalous behaviour, process injection signatures, unauthorized code execution, and real-time alerts can surface or constrain some AppDomainManager hijacking vectors (especially runtime anomalies), but does not stop the technique from running via config tampering or custom domain creation.
- T1574.014responds — A.8.16 configures monitoring (incl. process injection, anomalous behaviour, code tampering, resource use) to surface the technique once underway and generate tuned alerts for dedicated response personnel, but scope is set by org requirements rather than mandating universal coverage of .NET AppDomainManager hijacks.
- T1578detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access attempts, unusual system behaviour (including process injection), admin-level configuration changes, resource anomalies, and real-time/periodic alerts against a baseline, which surfaces many T1578 modifications in IaaS (e.g. unexpected instance/snapshot changes); however the clause's scope is set by organisational requirements rather than mandating coverage of all cloud compute infrastructure events, leaving a genuine slice unseen.
- T1578responds — A.8.16 requires real-time/near-real-time monitoring of anomalous behaviour (incl. unauthorized access, config changes, unusual system behaviour, and resource anomalies) plus dedicated trained personnel and procedures to respond to alerts, which can contain/eradicate an in-flight T1578 modification once detected; partial because the clause sets scope by business requirements rather than mandating universal cloud/IaaS coverage, leaving some modifications outside monitored baselines.
- T1578.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour including unauthorized access/attempts, unusual system behaviour (e.g. process injection), resource/performance deviations, and known attack patterns, which can surface snapshot creation as an anomaly if it deviates from the established baseline of normal cloud activity; however the clause's scope is set by organizational requirements rather than mandating coverage of all IaaS snapshot actions, leaving a large slice of stealthy or policy-compliant creations undetected.
- T1578.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access attempts, unusual system behaviour (including process injection), resource use deviations, and real-time/periodic alerts against a baseline, which can surface cloud instance creation as an anomaly in IaaS environments; however, the control's scope is set by organizational requirements rather than mandating coverage of all cloud compute events, leaving a large slice of stealthy or policy-compliant creations undetected.
- T1578.003detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection), resource use deviations, and unauthorized access attempts, which can surface the deletion of a cloud instance as an anomaly or post-activity indicator when it deviates from the established baseline; however, the control's scope is set by organizational requirements rather than mandating coverage of all cloud IaaS deletions, leaving a large slice (e.g., unmonitored or short-lived instances) unreached.
- T1578.003responds — A.8.16's real-time/periodic anomaly detection, alerting, and procedures to respond to positive indicators (including via 5.26) can surface and trigger response to the deletion activity or its precursors once underway, but the clause's scope is set by organizational requirements rather than mandating coverage of all cloud-instance terminations, leaving a large slice of IaaS events outside monitored baselines.
- T1578.004detects — A.8.16 requires monitoring of system/network activity, baselines, anomalies (incl. process injection, unauthorized access, unusual behaviour), logs from security tools, and real-time/periodic checks that can surface snapshot-restore or ephemeral-reset actions when they deviate from the established baseline or match known attack patterns, but the clause's scope is set by organisational requirements rather than mandating cloud-specific coverage of management APIs or VM lifecycle events.
- T1578.004responds — A.8.16's real-time/periodic anomaly detection, baseline monitoring for unusual behaviour (incl. process injection, unauthorized access, config changes), and alert-driven response procedures can surface and trigger timely reaction to a revert that deviates from baseline, but the control's scope is set by org requirements and does not guarantee coverage of cloud API/snapshot actions or post-revert cleanup.
- T1578.005detects — A.8.16 explicitly lists monitoring for anomalous behaviour, resource usage deviations, configuration file access/changes, unauthorized access attempts, and known attack patterns (including process injection and policy-like deviations), which surfaces some T1578.005 modifications (e.g. quota or tenant policy changes that produce detectable anomalies or resource spikes) but leaves a large remainder for stealthy or approved-looking config changes in cloud IaaS that fall outside the clause's scoped baseline and tooling.
- T1578.005responds — A.8.16's real-time/periodic anomaly detection (resource usage spikes, config-file changes, unusual behaviour, alerts to responders) can surface post-modification quota/policy/region changes as anomalous once they deviate from baseline, enabling timely response per linked 5.26, but the technique's stealthy approval path and lack of execution impact leave a large unaddressed slice.
- T1580detects — A.8.16 requires monitoring of network traffic, access attempts, configuration files, event logs, resource use, and explicit anomalous behaviours including unauthorized scanning and access to systems/information; this surfaces many T1580 API/CLI calls (especially from compromised credentials) as anomalous but leaves a slice of legitimate-looking discovery (e.g. low-volume, from expected locations, or non-signatured) outside the mandated baseline and scope.
- T1583.001detects — OWNER RULING 2026-09-15, per-item. T1583.001 is registering a domain, which occurs entirely on a registrar's infrastructure; every item in A.8.16's monitoring scope is the organization's own estate, so there is no vantage point. The rationale this replaces credited A.8.16 with surfacing adversary domains 'once they are used (e.g. in C2, phishing, or scanning)' -- that is detecting T1566 or T1071, both of which have their own rows, and crediting it here. This row is now an ANCHOR (EVENT_LANE_ANCHORS v1.40), the TECHNICAL counterpart of the at-2 `none`, because `detects` taught all three rungs and still returned 0 `none` in 17,621 rows.
- T1584detects — A.8.16 requires monitoring of network traffic, access, logs, anomalous behaviour (incl. botnet C2, malicious domains/IPs, unusual system behaviour) and baselines that can surface indicators of infrastructure compromise or its use, but scope is set by the organization so detection is not guaranteed for all T1584 vectors (e.g. pre-compromise or stealthy WiFi proximity cases).
- T1584.007detects — A.8.16 requires monitoring of network, system, application traffic, anomalous behaviour, known attack patterns, and deviations such as process injection or unusual traffic; this can surface serverless compromise or its proxy/hide effects when they produce observable anomalies inside the chosen scope, but the clause explicitly sets scope by business requirements rather than mandating universal coverage of ephemeral serverless runtimes or cloud-provider subdomains, leaving a large slice unseen.
- T1584.008detects — A.8.16 explicitly lists monitoring of network traffic, access to networking equipment, configuration files, security tool logs, anomalous behaviour (including known attack characteristics and deviations in protocols), and real-time/periodic anomaly detection against baselines, which surfaces many compromise indicators on network devices; however the clause's scope is set by organisational requirements rather than mandating coverage of all third-party/pre-owned edge devices, leaving a genuine slice unreached.
- T1587.002detects — A.8.16 explicitly lists monitoring for code tampering, unauthorized code execution, process injection, and anomalous behaviour against a baseline, which can surface self-signed certificate creation or use in the monitored environment, but the control's scope is set by organisational requirements and does not mandate coverage of pre-attack adversary development on PRE platforms.
- T1588.003detects — A.8.16 explicitly lists monitoring for code tampering (f), unauthorized access/scanning, anomalous behaviour including process injection and malware patterns, and baseline deviations that can surface stolen or misused code-signing certs post-acquisition, but the technique occurs in the pre-attack phase on external third-party certificate providers where the organization's monitoring scope does not reach.
- T1590.006detects — A.8.16 explicitly lists monitoring of network traffic, security tool logs (IDS/IPS/firewalls), anomalous scanning, known attack patterns, and deviations such as process injection or unauthorized access attempts, which can surface active scanning or phishing-for-info actions that gather appliance details; however the clause's scope is set by organizational requirements rather than mandating universal coverage of all PRE reconnaissance, leaving a large slice of passive or external data-set exposure unseen.
- T1595detects — A.8.16 explicitly lists monitoring of inbound/outbound traffic, unauthorized scanning of networks/systems/applications, and anomalous behaviour patterns that surface active scanning (especially when it triggers known attack characteristics or deviates from baseline), but the control's scope is set by the organization and limited to its own estate — it cannot observe pre-compromise scanning of third-party or unrelated infrastructure that the technique also permits.
- T1595prevents — A.8.16 explicitly includes monitoring for unauthorized scanning of business applications, systems and networks plus anomalous traffic and known attack characteristics, which can block some active scans from succeeding or continuing; however the control only sets requirements for monitoring scope and does not mandate preventive blocks or filters on the traffic itself.
- T1595.001detects — A.8.16 explicitly requires monitoring of inbound/outbound network traffic, unauthorized scanning of systems/networks, and anomalous behaviour (including known attack patterns), which directly surfaces IP block scanning as it occurs; the remainder is scans that fall outside the organization-defined monitoring scope.
- T1595.001prevents — A.8.16 requires monitoring of inbound/outbound network traffic, anomalous scanning activity, unauthorized access attempts, and known attack patterns (including scanning), which can detect/prevent the technique from completing undetected on monitored networks; however, the control's scope is set by organizational requirements rather than mandating universal coverage, leaving unmonitored blocks or pre-detection scans as a slice.
- T1595.001responds — A.8.16 surfaces the scan via network traffic, anomalous patterns or unauthorized scanning alerts (items a, d, g, h, i in guidance) once it touches monitored assets, feeding real-time alerts and response procedures per 5.26; partial because pre-compromise external scans on unowned IP space often generate no organizational event or artifact to contain/eradicate, leaving a large slice untouched per the event-lane anchor for this exact pair.
- T1595.002detects — A.8.16 explicitly lists monitoring for unauthorized scanning of business applications/systems/networks, known attack characteristics, anomalous behaviour, and real-time/periodic alerts on deviations from baseline, which surfaces vulnerability scanning activity when it occurs within the defined scope; however the clause sets its own monitoring scope by business requirements rather than mandating universal coverage of all possible pre-attack scans (especially external/pre-compromise ones on non-monitored assets), so only a slice is covered.
- T1595.003detects — A.8.16 explicitly lists monitoring for unauthorized scanning of business applications/systems/networks, unusual user/system behaviour, access attempts to protected resources, and anomalous traffic/baselines that can surface wordlist-driven directory/bucket enumeration in real time or near-real time; however the clause sets scope by organisational requirements rather than mandating universal coverage of all PRE/externally-targeted reconnaissance, leaving a large slice unseen.
- T1595.003prevents — A.8.16 requires monitoring of network traffic, access attempts, unauthorized scanning, and anomalous behaviour (including against a baseline of normal access patterns), which can block or deter wordlist-driven discovery scans when they produce detectable signatures or deviations; however the control only sets scope by organisational requirements and does not mandate universal blocking or rate-limiting of all reconnaissance crawling.
- T1598detects — A.8.16 explicitly configures monitoring to surface anomalous behaviour patterns including known attack characteristics, unusual user/system behaviour, and activity associated with phishing vectors (e.g. spoofed emails, urgent messaging, callback attempts), but the control's scope is set by organisational requirements rather than mandating coverage of all PRE phishing-for-information delivery channels (e.g. non-monitored SMS, voice, or external social media).
- T1598.001detects — A.8.16 explicitly lists monitoring of inbound/outbound network traffic, application behaviour, anomalous user/system patterns, and real-time alerts tuned to a baseline, which can surface spearphishing messages or related anomalies when they traverse monitored enterprise channels or trigger observable effects, but the technique occurs on third-party non-enterprise services outside the monitoring scope that the control itself sets by business requirements.
- T1598.002detects — A.8.16 explicitly lists monitoring of inbound network/application traffic, security tool logs (e.g. email/web filters), anomalous user/system behaviour, and known attack patterns, which can surface spearphishing attachment delivery or related anomalies in real time or periodically; however the control's scope is set by organisational requirements rather than mandating coverage of all social-engineering lures or pre-execution email content, leaving a large slice of T1598.002 (especially non-technical variants) unreached.
- T1598.003detects — A.8.16 explicitly lists monitoring of inbound/outbound traffic, email/web patterns, anomalous user behaviour, known attack characteristics and real-time alerts that can surface spearphishing delivery or the subsequent credential-harvesting site visit, but the technique is primarily social-engineering pre-delivery with heavy obfuscation/QR variants that frequently evade signature- and baseline-based detection, so only a minority slice is covered.
- T1598.004detects — A.8.16 requires monitoring of network traffic, access attempts, anomalous user/system behaviour, and real-time alerts tuned to a baseline, which can surface vishing indicators such as spoofed calls, unusual inbound voice traffic patterns, or anomalous access behaviours after reconnaissance; however, the control's scope is set by organisational requirements and focuses on electronic/network observables, leaving most social-engineering voice calls (especially non-technical or callback variants) outside typical monitored channels.
- T1599detects — A.8.16 explicitly lists monitoring of network traffic, perimeter devices, configuration files, anomalous behaviour (including known attack patterns and unauthorized access), and real-time alerts, which surfaces boundary-bridging activity on monitored network devices; however the clause's scope is set by organisational requirements rather than mandating universal coverage of all perimeter or segmentation devices, leaving a slice determined by the implementer.
- T1599.001detects — A.8.16 explicitly lists monitoring of network traffic, configuration files, anomalous behaviour (including deviations in protocols and unauthorized access), and baselines that can surface NAT modifications or unexpected boundary bridging, but scope is set by the organization so coverage of device-level NAT changes on all network devices is not mandated.
- T1600detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, known attack characteristics, unusual system behaviour, and deviations in protocols, which surfaces many T1600 sub-techniques (e.g. Modify System Image, Disable Crypto Hardware) once they run on monitored network devices; it does not cover the full class because scope is set by organisational requirements rather than mandating universal coverage of all encryption-weakening activity on all devices.
- T1600.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection and deviations in protocols), config file changes, resource anomalies, and real-time/automated alerts against a baseline, which can surface the network-device CLI/config changes and resulting weak-cipher traffic patterns; however the clause's scope is set by organisational requirements rather than mandating coverage of all network-device firmware modifications or post-compromise crypto-parameter changes, leaving a genuine slice unreached.
- T1600.002detects — A.8.16 requires monitoring of network traffic, device access, configuration files, system/network activity, resource use, and explicit anomalies such as process injection or deviations in standard protocols, which can surface the disabling of hardware crypto (or its downstream effects) when inside the chosen scope; however the clause sets scope by business requirements rather than mandating universal coverage of network-device firmware changes, leaving a large slice of T1600.002 outside any given implementation.
- T1601detects — A.8.16 explicitly lists monitoring for process injection, unauthorized code execution/tampering, anomalous system behaviour, and baseline deviations (including in network devices via traffic, logs, resource use, and real-time tools), which surfaces many T1601 instances in flight or on boot; it is only partial because the clause sets scope by organisational requirements rather than mandating universal deep inspection of monolithic firmware images in all embedded devices.
- T1601.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour (including process injection, unauthorized access, unusual system behaviour, admin config changes, resource anomalies, and known attack patterns) plus real-time/continuous tools that can surface the memory or storage modification steps of T1601.001; it does not cover every vector (e.g. offline flash or bootloader implants outside monitored scope) so the coverage is a chosen slice rather than a bounded remainder.
- T1601.002detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, unusual system behaviour, known attack characteristics, and deviations from baseline (e.g. resource use, config changes, reboots), which can surface a downgrade on monitored network devices; however the clause's scope is set by organisational requirements so coverage of embedded network-device firmware/OS replacement is not mandated and remains a chosen slice.
- T1602detects — A.8.16 explicitly lists monitoring of network traffic, access to systems/servers/networking equipment, critical configuration files, event logs, admin activity, baselines for anomalies, and signatures/patterns including unauthorized access/scanning; this surfaces T1602 activity when it triggers observable indicators inside the chosen scope, but the clause sets scope by business requirements rather than mandating coverage of all configuration-repository protocols or device classes, leaving a slice determined by the implementer
- T1602.001detects — A.8.16 explicitly lists monitoring of network traffic, system/network activity logs, configuration files, resource use, and anomalous behaviour patterns (including unusual system behaviour and unauthorized access/scanning), which can surface SNMP queries or MIB access as an anomaly against baseline; however the clause sets scope by organisational requirements rather than mandating universal SNMP/MIB instrumentation, so only a chosen slice is covered.
- T1602.001prevents — A.8.16's real-time/periodic monitoring of network traffic, access attempts, anomalous behaviour (incl. unusual scanning or access to protected resources like SNMP), and baselines can detect and thereby prevent some instances of the SNMP MIB query technique, but the clause sets scope by organisational requirements rather than mandating universal SNMP-specific blocks, leaving many conformant implementations that miss it.
- T1602.002detects — A.8.16 explicitly requires monitoring of network traffic, access to networking equipment, critical configuration files, security-tool logs, event logs, resource use, and anomalous behaviour including unauthorized access/scanning and known attack patterns; this surfaces the technique of dumping network device configs via management protocols or file access on the monitored estate, with the bounded remainder being pre-compromise external reconnaissance that never touches organizational assets.
- T1602.002prevents — A.8.16 requires monitoring of access to systems/servers/networking equipment, critical configuration files, event logs, and anomalous behaviour (including unauthorized access attempts and unusual system behaviour), which can prevent the technique from succeeding when the access or export is observable and blocked in real time; however the clause sets scope by organisational requirements rather than mandating universal prevention of all network-device config access vectors such as SNMP or SMI on unmonitored devices.
- T1606detects — A.8.16 explicitly lists monitoring for anomalous behaviour patterns, known attack characteristics, unauthorized access attempts, unusual system behaviour (including process injection), and resource/performance deviations that can surface many T1606 indicators once the forged credential is used or generated via APIs/commands, but the control's scope is set by organizational requirements rather than mandating coverage of all forging techniques (e.g. offline private-key use or SaaS token generation outside monitored baselines).
- T1606responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unauthorized access, unusual system behaviour, and known attack patterns) that can surface T1606 in flight or post-execution, with dedicated personnel and procedures to respond per 5.26; partial because the clause sets scope by business needs rather than mandating universal coverage of all forging vectors (e.g., API abuse in IaaS/SaaS outside monitored baselines).
- T1606.001detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access attempts, unusual system behaviour, and known attack characteristics, which can surface cookie forgery when it produces observable deviations from baseline (e.g. anomalous access or traffic); however the clause's scope is set by organisational requirements rather than mandating coverage of all forgery vectors or SaaS/IaaS cookie issuance, leaving a large slice unseen.
- T1606.002detects — A.8.16 requires monitoring of network, system, application traffic, access events, security tool logs, anomalous behaviour baselines, and specific patterns including unauthorized access attempts and unusual system behaviour; this surfaces some SAML token forgery indicators (e.g. anomalous admin access or traffic from unexpected sources) but the clause sets scope by organisational requirements rather than mandating detection of forged tokens themselves, leaving most forgery events (especially those using valid certificates) outside guaranteed coverage.
- T1606.002responds — A.8.16 requires real-time/periodic monitoring of network, system, application traffic, access attempts, security tool logs, anomalous behaviour (incl. process injection, unauthorized access, unusual patterns), and generating tuned alerts for dedicated response personnel per 5.26; this surfaces and enables response to SAML forgery indicators once underway (e.g. anomalous auth or privileged access), but scope is set by org requirements so coverage of the full technique (esp. offline forging or non-monitored SaaS/IdP paths) is a chosen slice.
- T1608.004detects — A.8.16's monitoring of network traffic, web content patterns, anomalous scripts, unauthorized access, and known attack characteristics (including drive-by indicators) can surface T1608.004 staging activity when it intersects monitored infrastructure or traffic, but the control's scope is set by organizational requirements and does not inherently cover adversary-controlled external sites or PRE infrastructure.
- T1608.005detects — A.8.16 requires monitoring for anomalous behaviour and known attack characteristics (incl. malicious domains/IPs, unusual web traffic, phishing indicators), which surfaces some link-target setup (e.g. cloned sites, suspicious redirects) when it intersects monitored scope, but the bulk of pre-phish infrastructure acquisition and hosting (esp. on PRE, IPFS, or unmonitored external PaaS) lies outside its reach.
- T1608.006detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection and deviations), unauthorized access/scanning, and real-time/periodic analysis of network, application, and web traffic that can surface SEO poisoning artifacts such as keyword stuffing, cloaking redirects, or anomalous inbound patterns once they reach monitored assets; however, the pre-attack staging on external search engines or unmonitored compromised sites falls outside the clause's scoped baseline and tooling.
- T1609detects — A.8.16 requires monitoring of network/system/application traffic, access, logs, resource use, baselines and anomalies (incl. process injection and unauthorized access), which can surface container admin command abuse when it produces observable signals inside the chosen scope; the clause sets that scope by org requirements rather than mandating universal container telemetry, so only a slice is covered.
- T1609responds — A.8.16 requires real-time/periodic monitoring of system/network/application behaviour (incl. process injection, anomalous commands, resource use, and admin-level activity) plus dedicated trained personnel and procedures to respond to alerts, which can surface and contain T1609 once underway; partial because the clause sets scope by organisational requirements rather than mandating universal container-specific instrumentation, leaving some realisations (e.g. silent entrypoint abuse in unmonitored clusters) outside the covered slice.
- T1610detects — A.8.16 requires monitoring of network/system/application traffic, resource use, anomalous behaviour, known attack patterns and process injection; container deployment can produce observable anomalies (e.g. unexpected container start events, privileged container creation, resource spikes or malicious image pulls) that fall inside the configurable scope, but the clause sets scope by business requirements rather than mandating universal container instrumentation, leaving many deployment vectors (e.g. silent API calls on unmonitored nodes) outside what is required.
- T1610responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, unauthorized access, unusual system behaviour, and deviations from baseline), which surfaces a deployed container once present so dedicated personnel can respond per linked 5.26 procedures; it does not itself contain or eradicate the container.
- T1611detects — A.8.16 requires monitoring of anomalous behaviour (incl. process injection, unusual system behaviour, privileged access, resource anomalies, and known attack patterns) which surfaces some T1611 instances in real time or near-real time, but scope is set by organisational requirements so an implementation can be fully compliant while missing many escape vectors (e.g. kernel-module loads, bind-mount abuse, or hypervisor escapes outside the chosen baseline).
- T1611responds — A.8.16 configures real-time/periodic monitoring, baselines, and alerts for anomalous behaviour (including process injection, unauthorized access, unusual system behaviour, and deviations that can surface container escapes in flight), with dedicated personnel and procedures to respond to positive indicators per 5.26; this bounds impact once underway but only for the observable subset of T1611 techniques that match the chosen monitoring scope, leaving many kernel-level, privileged-container, or hypervisor escapes outside the instrumented baseline.
- T1612detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, malware-associated activity, unauthorized scanning, unusual system behaviour, and deviations from baseline (CPU/disk/memory/network), which can surface the build API call, C2 download, or anomalous container build on-host; however the clause sets scope by organisational requirements rather than mandating universal coverage of container build APIs or image construction, leaving a slice determined by what the implementer chooses to instrument.
- T1612prevents — A.8.16's baseline monitoring of network traffic, system activity, resource use, anomalous behaviour (including process injection and malware-associated patterns), and real-time alerts can surface suspicious build API calls or image construction on the host, but the clause sets scope by organisational requirements rather than mandating universal instrumentation of the Docker/build API, leaving many implementations unable to stop the technique from running.
- T1612responds — A.8.16 configures real-time/periodic monitoring and alerting on anomalous behaviour (including process injection, malware-associated activity, unusual system behaviour, and deviations from baseline), which can surface an in-progress build that deviates from normal and trigger the incident response process (5.26) once underway; however, the control's scope is set by organisational requirements rather than mandating coverage of container build APIs or image construction, leaving a large slice of T1612 executions (especially those using local vanilla bases or non-baseline-deviating steps) unreached.
- T1613detects — A.8.16 requires monitoring of network/system/application traffic, access, logs, resource use, baselines, and explicit anomalies including process injection and unauthorized access/scanning; this can surface container-discovery API calls, dashboard access, or anomalous queries as part of broader anomalous behaviour, but the clause sets scope by organisational requirements rather than mandating coverage of container-specific APIs or logs, leaving a large slice of T1613 (especially in non-monitored container platforms) unreached.
- T1614detects — A.8.16 requires monitoring for anomalous behaviour and explicitly lists process injection, unusual system behaviour, network traffic, resource use, and known attack patterns; these can surface some T1614 implementations (e.g. anomalous geolocation API calls, unexpected IP lookups, or baseline-deviant locale queries) but the clause's scope is set by organisational requirements rather than mandating coverage of every locale/metadata check, leaving a large slice of stealthy or in-process discovery unseen.
- T1614.001detects — A.8.16 requires monitoring of system behaviour, resource use, event logs, configuration files, and explicit anomalies such as process injection or unusual behaviour, which can surface language-discovery actions (registry queries, locale calls, API invocations) when they deviate from the established baseline; the clause sets scope by organisational requirements rather than mandating universal coverage of every possible discovery vector, leaving a genuine slice unreached.
- T1615detects — A.8.16 requires monitoring of network, system, application traffic, access, configuration files, event logs, resource use, and explicit anomalous behaviours including process injection and unauthorized access; Group Policy Discovery via gpresult, PowerShell cmdlets or SYSVOL file reads is observable in those logs when the monitoring scope includes them, but the clause sets scope by organisational requirements rather than mandating universal coverage of all discovery commands or paths, leaving a slice determined by the implementer.
- T1619detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access attempts, unusual system behaviour (including process injection), resource use, and known attack patterns, which can surface cloud API calls that deviate from baseline (e.g. anomalous ListObjectsV2/List Blobs volume or source); however the clause sets scope by organisational requirements rather than mandating coverage of all IaaS cloud storage enumeration, leaving a large slice of stealthy or in-scope-but-unmonitored API use undetected.
- T1620detects — A.8.16 explicitly lists process injection and anomalous code execution/memory behaviour as detectable anomalies (via baseline deviation, resource monitoring, and real-time tools), and T1620 is a closely related in-process fileless technique that can surface in the same observables; however the clause sets scope by organisational requirements rather than mandating universal deep host instrumentation, so only a chosen slice is covered.
- T1620prevents — A.8.16 mandates monitoring for anomalous behaviour including process injection, unauthorized code execution, and deviations from baseline (explicitly naming process injection and code-tampering checks), which can surface and thereby constrain some in-memory reflective loading attempts; however the clause sets scope by organisational requirements rather than mandating universal instrumentation, so many implementations see only a slice of in-process memory activity.
- T1620responds — A.8.16's real-time/continuous monitoring of anomalous behaviour (incl. process injection, unauthorized code execution, memory/resource deviations, and malware-like activity) surfaces T1620 once it is underway inside a process; alerts and procedures then feed the 5.26 response workflow for containment/eradication, exactly as the event-lane definition of `responds` requires.
- T1621detects — A.8.16 requires monitoring for anomalous behaviour (including unusual access patterns, repeated login attempts, and deviations from baseline) and can surface MFA fatigue bombing or anomalous MFA request generation when those fall inside the scoped telemetry; the clause sets scope by requirements rather than mandating universal coverage of auth flows or push-notification channels, so only a chosen slice is guaranteed to be detected.
- T1621prevents — A.8.16's real-time/periodic monitoring of network traffic, access attempts, anomalous login patterns, unusual user behaviour, and MFA-related push/SMS/call floods (via baseline deviation and alerts) can surface and enable timely response that stops the fatigue or push-abuse technique from succeeding on some vectors, but the clause sets scope by organisational requirements rather than mandating universal MFA-specific instrumentation, leaving a large slice (e.g. non-monitored identity providers or social-engineering acceptance) unreached.
- T1621responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (including unusual access patterns, repeated login attempts, and deviations from baseline), plus dedicated personnel and procedures to respond to alerts (see 5.26), which can contain an in-progress MFA fatigue campaign once the bombardment is detected; it is partial because the clause sets scope by business requirements rather than mandating universal coverage of all MFA push/SMS patterns or guaranteeing timely response before the user approves a request.
- T1622detects — A.8.16 explicitly lists process injection, unusual system behaviour, code tampering checks, and baseline anomaly detection that can surface many debugger-evasion artifacts or the altered behaviours they trigger, but the control's scope is set by organisational requirements rather than mandating debugger-specific instrumentation, leaving many low-level checks (PEB flags, SEH, timing, OutputDebugString floods) outside typical coverage.
- T1647detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unauthorized access, unusual system behaviour, and deviations in standard protocols, plus real-time/periodic tools that surface attack patterns; plist modification (a file-based config change often enabling persistence or evasion) can be surfaced when it triggers those observables, but the clause's scope is set by organisational requirements rather than mandating plist-specific or macOS file-integrity coverage, leaving a large slice of stealthy plist edits unseen.
- T1648detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, unusual system behaviour (including process injection), resource use anomalies, and real-time/periodic alerts tuned to a baseline, which can surface many T1648 indicators (e.g. unexpected serverless invocations, crypto-mining resource spikes, or event-triggered persistence); however, the clause's scope is set by organisational requirements rather than mandating coverage of all cloud/serverless layers, leaving a large slice of SaaS/Office Suite/IaaS serverless abuse outside typical monitoring instrumentation.
- T1649detects — A.8.16 explicitly lists monitoring for anomalous behaviour, known attack characteristics, process injection, unauthorized access attempts, unusual system behaviour, and resource/performance deviations, which surface many T1649 indicators (e.g. anomalous cert store/crypto API use, golden cert issuance, or enrollment anomalies) once the baseline is tuned; it does not cover all stealthy theft/forgery vectors or non-monitored platforms.
- T1651detects — A.8.16 explicitly lists monitoring for anomalous behaviour, process injection, unauthorized access, admin-level config changes, resource anomalies, and known attack patterns, which can surface cloud admin command abuse when it deviates from baseline (e.g. unusual VM agent activity or admin-driven execution); however the clause sets scope by organisational requirements rather than mandating coverage of all cloud management services or VM-agent telemetry, leaving a slice determined by the implementer
- T1651responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (incl. process injection, unauthorized access, unusual behaviour), alerting and dedicated trained personnel to respond to positive indicators, which directly matches the incident-response act of `responds` once a cloud admin command technique is underway; partial because the clause sets scope by business requirements rather than mandating universal coverage of all IaaS admin-command vectors or VM-agent behaviours.
- T1652detects — A.8.16 requires monitoring for anomalous behaviour and explicitly lists process injection, unauthorized access, and deviations from baseline (including unusual system behaviour), which can surface driver enumeration via command-line utilities, registry reads, or lsmod/modinfo when those deviate from the established baseline of normal access and resource use; however the clause sets its own scope by business requirements rather than mandating universal coverage of every discovery technique, leaving a slice determined by what the implementer actually instruments.
- T1653detects — A.8.16 explicitly lists monitoring for anomalous behaviour including unusual system behaviour (e.g. process injection), resource use (CPU/disk/memory/bandwidth), configuration file access, and deviations from baseline (e.g. unplanned terminations or lock-screen/hibernation changes), which surfaces many T1653 techniques in real time; however the clause's scope is set by organisational requirements rather than mandating coverage of all power-setting abuse vectors (especially on Linux/macOS/network devices or stealthy file-deletion methods), so only a chosen slice is guaranteed.
- T1654detects — A.8.16 explicitly requires monitoring of event logs, security-tool logs, access attempts, system/network activity, resource use, and anomalous behaviour (including process injection and known attack patterns); this directly surfaces log-enumeration activity by host tools or against a SIEM in real time or near-real time on the monitored estate.
- T1657detects — A.8.16's monitoring of anomalous behaviour, resource use, unauthorized access attempts, malware indicators, and real-time alerts can surface many T1657 precursors or sub-techniques (e.g. account compromise, exfiltration, ransomware encryption), but the ultimate financial theft act itself (e.g. authorized-looking transfer or social-engineering payment) is frequently outside the named monitoring scope and baseline, leaving an open rather than bounded remainder
- T1657responds — A.8.16 requires real-time/periodic monitoring, anomaly detection against baseline, alerts, and timely procedures to respond to positive indicators (explicitly referencing 5.26 incident response), which acts on financial theft once underway to contain/eradicate; partial because the clause sets scope by org requirements (not mandating coverage of all financial-theft vectors like social engineering or offline extortion) and detection is prerequisite rather than the full response action.
- T1659detects — A.8.16 explicitly requires monitoring of inbound/outbound network traffic, application behaviour patterns, anomalous activity (including known attack characteristics and deviations from baseline), and real-time/continuous tools that surface indicators such as malicious traffic or injected content signatures, directly detecting T1659's network-channel manipulation and content injection on the monitored estate.
- T1659prevents — A.8.16 requires monitoring of inbound/outbound network traffic, anomalous patterns (including known attack characteristics and deviations in protocols), and real-time/continuous detection against a baseline, which can block or stop many content-injection attempts from succeeding when the malicious traffic is observable inside the monitored scope; however the control only sets requirements for scope and tooling chosen by the organization, leaving upstream ISP-level or unmonitored channels (explicitly noted in the T1659 description) as an open slice rather than a bounded remainder.
- T1659responds — A.8.16 requires real-time/near-real-time monitoring of network traffic, anomalous patterns (including known attack characteristics and unauthorized access), automated alerts, and dedicated trained personnel plus procedures to respond to positive indicators in a timely manner per 5.26, which directly enacts the incident-response containment/eradication act once content injection is underway.
- T1665detects — A.8.16 requires monitoring of network traffic, anomalous behaviour, known attack patterns, and deviations from baseline (including some C2-like indicators), which can surface T1665 hiding attempts when they produce observable anomalies inside the chosen scope; however the clause explicitly sets scope by organisational requirements rather than mandating universal coverage of all hiding methods (e.g. domain masking, benign-content redirects, or geo-fencing that blends with normal traffic), leaving a large slice unseen.
- T1665prevents — A.8.16's real-time/continuous monitoring of network traffic, baselines, anomalous patterns (incl. malicious IPs, known attack characteristics, unauthorized access/scanning), and alerts directly surfaces many T1665 hiding/evasion artifacts before or as they operate, constraining the technique's undetected longevity; partial because the clause sets scope by org requirements rather than mandating universal depth, leaving slices (e.g., sophisticated domain masking or pre-filtered C2 blending) that conformant but narrowly scoped monitoring can miss.
- T1665responds — A.8.16's real-time/periodic monitoring, anomaly detection against baseline, and alert/response procedures for abnormal events (including known attack patterns and unauthorized access) surface and enable timely response to T1665's traffic manipulation once underway, but the clause's scope is set by organizational requirements rather than mandating universal coverage of all hiding methods (e.g., domain masking or trusted-service blending).
- T1666detects — A.8.16 explicitly lists monitoring of access to systems/servers/critical apps, admin-level config files, event logs, anomalous behaviour (including unauthorized access and deviations from baseline), and real-time alerting on thresholds; this surfaces many hierarchy-modification events (e.g. CreateAccount, LeaveOrganization, subscription transfers) after they occur, but the clause's scope is set by organizational requirements rather than mandating coverage of every IaaS control-plane call, leaving a genuine slice of stealthy or out-of-scope modifications undetected.
- T1667detects — A.8.16 explicitly lists monitoring of inbound network/application traffic, resource use (CPU, bandwidth, overloads), anomalous behaviour patterns, and real-time alerts tuned to a baseline; this surfaces email bombing as anomalous volume or inbox/resource flood in covered scopes, but the clause sets scope by organisational requirements so many implementations (e.g. endpoint-only or non-mail-focused) will miss it entirely.
- T1667responds — A.8.16 requires real-time/periodic monitoring of network traffic, logs, anomalies (including overloads, unusual behaviour, and known attack patterns), automated alerts, and timely response procedures to minimize adverse effects once the technique is underway; this matches the flooding/overload nature of T1667 but is scoped only to what falls inside the organisation-determined monitoring baseline rather than guaranteeing coverage of all email bombing vectors.
- T1668detects — A.8.16 explicitly configures monitoring to surface anomalous behaviour including process injection, unauthorized access attempts, unusual system behaviour, malware-associated activity, and deviations from baseline that would include an adversary patching, disabling services, stripping privileges or removing competing malware on a compromised host.
- T1669detects — A.8.16 explicitly lists monitoring of inbound/outbound network traffic, access to systems/networking equipment, anomalous behaviour (including unauthorized access attempts and deviations in protocols), and real-time/periodic anomaly detection against baselines, which surfaces many aspects of Wi-Fi connection activity on monitored networks; it does not instrument or surface the physical-proximity or pre-compromise dual-homed bridging vectors outside organizational scope.
- T1671detects — A.8.16 explicitly lists monitoring for anomalous behaviour, unauthorized access attempts, unusual system behaviour (including process injection), access to critical resources, and baseline deviations that can surface malicious OAuth integrations or service-principal activity once present, but the clause sets scope by organisational requirements rather than mandating coverage of every SaaS/OAuth integration or token usage.
- T1673detects — A.8.16 requires monitoring for anomalous behaviour and explicitly lists process injection, unusual system behaviour, resource use, and admin-level activity as items to baseline and alert on; VM enumeration via hypervisor CLI/GUI is observable as anomalous admin activity or process execution on a monitored hypervisor but is not required by the clause's scope-setting language and is absent from the named examples, leaving a genuine slice determined by the implementer.
- T1674detects — A.8.16 explicitly lists process injection, keystroke logging, unusual system behaviour, and anomalous resource use as detectable via baseline monitoring of events, logs, and real-time tools; this surfaces some but not all T1674 instances (e.g. physical HID emulation or pre-programmed non-anomalous simulation may fall outside chosen scope).
- T1674responds — A.8.16's real-time/periodic monitoring, anomaly detection (incl. keystroke logging and process injection), alerting, and procedures to respond to positive indicators directly enable containment/eradication once input injection (keystroke simulation) is underway, but scope is set by org requirements so coverage of all variants (e.g. HID hardware) is not assured.
- T1675detects — A.8.16 explicitly lists monitoring for anomalous behaviour, process injection, unusual system behaviour, admin-level access, resource use, and real-time alerts against a baseline, which surfaces many indicators of ESXi guest-command abuse (e.g. unexpected vmtoolsd activity or API-driven process execution); however the clause's scope is set by organisational requirements rather than mandating host/VM introspection depth, leaving a genuine slice of in-guest or low-and-slow ESXi administration undetected.
- T1677detects — A.8.16 explicitly lists monitoring of critical/admin config files, code execution authorization/tampering checks, anomalous system behaviour (including process injection), and baseline-deviation alerts, which can surface several poisoning vectors (esp. direct/indirect config or script changes once they execute); it does not address the public/fork PR vectors or pre-execution repository manipulation on SaaS platforms, leaving an open rather than bounded remainder.
- T1678detects — A.8.16 explicitly lists monitoring for anomalous behaviour including process injection, unusual system behaviour, resource use (CPU/memory/bandwidth), API hammering patterns, and deviations from established baselines of normal activity, which directly surfaces many T1678 timing/delay artifacts in real time or at intervals; it is only partial because the clause's scope is set by organisational requirements rather than mandating universal coverage of every possible sleep/scheduling/loop variant.
- T1679detects — A.8.16 requires monitoring for anomalous behaviour and known attack characteristics including process injection and deviations, which can surface selective-exclusion artifacts (e.g. anomalous file-access patterns or untouched system files during ransomware), but the clause's scope is set by organisational requirements rather than mandating coverage of every exclusion technique, leaving a large slice unseen.
- T1680detects — A.8.16 requires monitoring of system/network activity, resource use, anomalous behaviour (incl. unusual system behaviour and process injection), and baselines that can surface reconnaissance commands or deviations, but the clause sets scope by organisational requirements rather than mandating coverage of every discovery command or API (e.g. cloud IaaS calls, ESXi esxcli, or all Linux utilities) so only a slice is guaranteed to be detected.
- T1684detects — A.8.16 explicitly lists monitoring for anomalous user/system behaviour, unauthorized access attempts, unusual access patterns, and real-time/periodic anomaly detection against a baseline, which surfaces many social-engineering-driven actions (e.g. anomalous MFA resets, unusual help-desk or consent flows); it does not cover the purely human, non-technical, or pre-action influence phase that leaves no observable indicator.
- T1684responds — A.8.16 requires real-time/periodic monitoring for anomalous behaviour (including unusual user/system behaviour, unauthorized access attempts, and patterns tied to social engineering indicators such as phishing), plus dedicated personnel and procedures to respond to alerts in a timely manner per 5.26, which directly matches the `responds` verb once the technique is underway; partial because the clause's scope is set by organizational requirements rather than mandating universal coverage of all social engineering channels (e.g., voice, email, or non-technical influence).
- T1684.001detects — A.8.16 explicitly lists monitoring for anomalous user/system behaviour, unusual access patterns, known attack characteristics, and outbound traffic that can surface impersonation campaigns (e.g. via email anomalies, urgent language patterns, or deviations from baseline), but the control's scope is set by organisational requirements and does not mandate coverage of social-engineering signals or all preceding reconnaissance vectors, leaving a large slice of T1684.001 undetected.
- T1684.001responds — A.8.16 requires real-time/periodic monitoring, anomaly detection (including unusual user/system behaviour), alerting, and timely procedures to respond to positive indicators, which can surface impersonation campaigns once underway (e.g. via anomalous email patterns or access) for containment; this is bounded by the clause's scope-setting language and focus on technical baselines rather than social-engineering signals.
- T1684.002detects — A.8.16 explicitly lists monitoring of inbound/outbound email traffic, anomalous behaviour patterns, known attack characteristics, and deviations from baseline (including unusual user/system behaviour), which can surface email spoofing in flight or post-delivery; however the clause sets scope by organisational requirements rather than mandating universal email-header or DMARC-failure instrumentation, leaving a large slice of implementations that would miss it.
- T1685detects — A.8.16 explicitly lists monitoring of security-tool logs, event logs, system/network activity, configuration files, resource use, code tampering, and known attack patterns (including process injection and malware behaviour); these directly surface the disabling/tampering actions and their telemetry-blocking effects once they occur on the monitored estate, with the bounded remainder being pre-compromise or fully external tool tampering that leaves no observable artifact inside the organisation's scope.
- T1685responds — A.8.16 requires real-time/periodic monitoring, anomaly detection against baseline, alerts on events like unauthorized access/tampering indicators, and dedicated personnel/procedures to respond to positive indicators (explicitly referencing 5.26 incident response), which acts on the T1685 event once underway to contain/eradicate; partial because scope is set by org requirements (not mandating coverage of all tampering vectors like ETW manipulation or driver-based bypasses) and it detects/surfaces rather than fully containing all instances.
- T1685.001detects — A.8.16 explicitly includes event logs, security-tool logs, anomalous behaviour baselines, and real-time/periodic monitoring that can surface tampering with the EventLog service or audit policy (e.g. via process termination, registry changes, or auditpol.exe anomalies), but the clause sets scope by organisational requirements rather than mandating universal coverage of every Windows Event Log modification technique, leaving a slice determined by the implementer.
- T1685.002detects — A.8.16 requires monitoring of logs, access, configuration changes, anomalous behaviour and security-tool outputs (including IDS/IPS/firewalls) against a baseline, which can surface tampering with cloud logging as an anomalous event or config change; however the clause sets scope by organisational requirements rather than mandating universal coverage of every cloud logging integration, leaving a slice determined by what the implementer chooses to monitor.
- T1685.003detects — A.8.16 requires monitoring of security tool logs, anomalous behaviour (including process injection and malware-like activity), baselines, and real-time alerts to surface potential incidents, which can detect spoofed UIs as anomalies or via integrity checks on executed code; however, the control's scope is set by organizational requirements rather than mandating detection of all UI spoofing, leaving a slice dependent on implementation.
- T1685.004detects — A.8.16 requires monitoring of system/network activity, event logs, resource use, anomalous behaviour (incl. process injection and deviations), and security-tool logs (incl. IDS/IPS), which can surface auditd tampering or its absence as an anomaly against baseline; however the clause sets scope by organisational requirements rather than mandating kernel-level audit-integrity sensors, so coverage of this specific Linux technique is an implementer-chosen slice
- T1685.004responds — A.8.16 requires real-time/periodic monitoring of system activity, logs, anomalies (including process injection, unauthorized access, and deviations), with alerts and dedicated response personnel; this surfaces and enables timely response to an in-flight auditd disable/modify once it produces observable effects, but the control's scope is set by organizational requirements rather than mandating kernel-level audit integrity checks, leaving a large slice of stealthy root-privileged techniques (e.g. direct hooking or rule edits before anomalies appear) unreached.
- T1685.005detects — A.8.16 explicitly includes event logs, system/network activity, admin configuration changes, and anomalous behaviour (including unauthorized access or tampering) in its monitoring scope and baseline; clearing Windows Event Logs is a detectable anomaly against that baseline, though the control's scope is set by the organization rather than mandating universal coverage of every possible log-clearing vector.
- T1685.005responds — A.8.16's real-time/periodic monitoring of event logs, anomalous behaviour (incl. unplanned terminations, unauthorized access, and deviations), automated alerts, and procedures to respond to positive indicators (explicitly linking to 5.26 incident response) directly engages the clearing of Windows Event Logs as a detectable adverse event that triggers timely response to minimize impact.
- T1685.006detects — A.8.16 explicitly includes event logs, system/network activity, access attempts, and baseline anomalies (including unusual behaviour), which can surface log-clearing actions when they deviate from the established baseline or trigger configured alerts; however the clause sets scope by organisational requirements rather than mandating universal coverage of every log-clearing method or location, leaving a slice determined by the implementer.
- T1685.006responds — A.8.16 requires real-time/periodic monitoring of logs, anomalous behaviour (incl. unauthorized access or tampering), generation of alerts on deviations from baseline, and dedicated personnel/procedures to respond to positive indicators in a timely manner per 5.26; this surfaces and enables response to log-clearing once it occurs, but the clause's scope is set by org requirements rather than mandating coverage of all log-clearing methods or platforms, leaving a genuine slice unreached.
- T1686detects — A.8.16 explicitly lists monitoring of network traffic, firewall/security-tool logs, admin config files, anomalous behaviour (including unauthorized access/scanning and deviations from baseline), and real-time alerting on known attack patterns, which surfaces many T1686 instances once the modification occurs; it is only partial because the clause sets scope by organisational requirements rather than mandating universal coverage of every platform or every possible stealthy rule change.
- T1686responds — A.8.16's real-time/periodic monitoring, anomaly detection (including unauthorized access, config changes, and known attack patterns), alerting, and procedures to respond to positive indicators directly surface and enable timely response to firewall tampering once it occurs, but the clause's scope is set by organizational requirements rather than mandating universal coverage of all firewall-modification vectors across every platform.
- T1686.001detects — A.8.16 explicitly lists monitoring of network traffic, access to systems/networking equipment, security tool logs (incl. firewalls/IDS/IPS), anomalous behaviour patterns (incl. unauthorized access/scanning and known attack characteristics), and real-time/continuous alerting on deviations from baseline, which surfaces many instances of cloud firewall modification in IaaS; however the clause's scope is set by organisational requirements rather than mandating universal coverage of all cloud control-plane actions, leaving a genuine slice unseen.
- T1686.001responds — A.8.16's real-time/periodic monitoring, anomaly detection (including unauthorized access/scanning, config changes, and known attack patterns), alerting, and procedures to respond to positive indicators directly surface and enable timely response to firewall modifications once they occur, but the clause's scope is set by organizational requirements rather than mandating coverage of all cloud firewall rule changes.
- T1686.002detects — A.8.16 explicitly lists monitoring of network traffic, firewall/IDS/IPS logs, anomalous behaviour patterns (including known attack characteristics and deviations in protocols), and real-time/continuous tools that surface unauthorized access or configuration changes, which would flag many T1686.002 actions once underway; however, the clause's scope is set by organizational requirements rather than mandating universal coverage of all network devices or preemptive detection of every rule modification.
- T1686.002prevents — A.8.16's real-time/continuous monitoring of network traffic, configuration files, admin access, anomalous behaviour (incl. unauthorized changes, unusual protocols, and known attack patterns) and alerting can surface or block some T1686.002 executions before full bypass succeeds, but the clause sets scope by org requirements rather than mandating universal enforcement mechanisms, leaving many device-management and pre-access vectors (e.g. valid accounts, public exploits) outside its reach.
- T1686.002responds — A.8.16's real-time/periodic monitoring, anomaly detection (including unauthorized access, config changes, and known attack patterns), alerting, and procedures to respond to positive indicators directly enable timely response to firewall tampering once underway, but the clause's scope is set by organizational requirements rather than mandating coverage of all network device management interfaces or indirect host manipulations.
- T1686.003detects — A.8.16 explicitly lists monitoring of network traffic, access to systems/networking equipment, security tool logs (incl. firewalls/IDS), anomalous behaviour patterns, and known attack characteristics, which surfaces many T1686.003 artifacts (e.g. registry changes, netsh/PowerShell invocations, rule modifications) when they fall inside the chosen scope and baseline; the clause sets scope by requirements rather than mandating universal coverage of all host firewall tampering vectors, so only a chosen slice is caught.
- T1686.003responds — A.8.16 requires real-time/periodic monitoring of network traffic, firewall logs, anomalous behaviour (including unauthorized access and known attack patterns), and dedicated personnel to respond to generated alerts, which can surface and trigger response to firewall modifications once they produce observable effects; however, many modifications (e.g. registry changes or netsh commands that do not immediately generate traffic/anomalies) fall outside the explicitly listed monitoring items and baseline triggers, leaving a large slice of the technique unaddressed.
- T1687detects — A.8.16 explicitly lists monitoring of security-tool logs, anomalous behaviour patterns (including process injection, malware activity, unauthorized access, and known attack characteristics), resource use, and real-time alerting against a baseline, which surfaces exploitation of defensive components once it produces observable anomalies on the monitored estate; partial because the technique can be entirely silent, target unmonitored defensive layers, or impair the monitoring system itself before detection occurs.
- T1688detects — A.8.16 requires monitoring of system/network/application behaviour, baselines, and anomalies including process injection and unauthorized changes, which can surface safe-mode boots or the registry/BCD tampering that forces them, but the clause's scope is set by organisational requirements rather than mandating boot-time or safe-mode-specific instrumentation, leaving a large slice of this technique unseen.
- T1689detects — A.8.16's monitoring of anomalous behaviour, baselines, process injection, unauthorized access, resource use, and security-tool logs can surface many downgrade attacks (e.g. unexpected older PowerShell, boot-manager changes, protocol downgrades that trigger known attack patterns), but the clause's scope is set by organisational requirements rather than mandating coverage of every possible downgrade vector, leaving a genuine implementation-chosen slice unreached.
- T1690detects — A.8.16 explicitly lists monitoring for anomalous behaviour, process injection, unusual system behaviour, event logs, resource use, and real-time/automated alerts tuned to a baseline, which surfaces many of the visible signs of T1690 (e.g. env var changes, history file tampering, unexpected process termination); it does not cover every platform or every stealthy variant (e.g. network device CLI, prepended-space evasion on unmonitored shells).
Prevented OWASP Web Top 10 (2025) risks (32)
OWASP Web Top 10 (2025) risk categories this ISO control helps prevent or mitigate — our AI-authored analysis (authority llm_unverified, under review).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Why these map — AI rationale (under review)
- A01finds — A.8.16's monitoring for anomalous behaviour, unauthorized access attempts, and deviations from baseline directly surfaces many Broken Access Control realizations (e.g. unauthorized scanning, successful/unsuccessful protected-resource attempts, unusual access patterns), but does not discover design or code defects like missing authorization checks, IDOR, or CSRF before they are exercised.
- A01mitigates — A.8.16's real-time detection of unauthorized access attempts, anomalous behaviour, and successful/unsuccessful protected-resource accesses surfaces realized broken-access-control events (e.g. path traversal, IDOR, missing checks) so their blast radius or dwell time can be limited, which is mitigation; it does not stop the authorization decision from failing in the first place.
- A02finds — A.8.16's monitoring of traffic, access, config files, logs, resource use, baselines, attack signatures, unauthorized attempts and anomalous behaviour directly surfaces misconfigurations that leave attack surface (weak defaults, incomplete hardening, exposed settings) via real-time/periodic detection and alerts.
- A02mitigates — A.8.16's real-time anomaly detection (unauthorized access, config-file changes, unusual behaviour, malware signatures) surfaces and bounds impact of some realized misconfigurations but does not address the core weakness of insecure defaults or incomplete hardening itself.
- A03finds — A.8.16's monitoring of logs, traffic, resource use, anomalous behaviour, malware signatures, and known attack patterns can surface indicators of already-compromised supply-chain components or pipelines after the fact (e.g. via C2 traffic or process anomalies), but does not discover vulnerable/outdated dependencies themselves nor inspect build/signing infrastructure.
- A03mitigates — A.8.16's real-time anomaly detection (malware signatures, process injection, tampered code execution, unusual resource behaviour, malicious C2 traffic) can bound the consequence of a realised supply-chain compromise once it is running, but does nothing to stop the vulnerable/outdated/compromised dependency or pipeline from being introduced in the first place.
- A05finds — A.8.16's monitoring of traffic, logs, anomalous behaviour, known attack patterns (including injection signatures), and unauthorized access can surface realized injection attempts or their effects in runtime data, but does not inspect code or find the underlying neutralization defect itself.
- A05mitigates — A.8.16's real-time monitoring for attack signatures, anomalous behaviour (process injection, buffer overflows, unauthorized scanning, malicious traffic) and alerting can limit the blast radius or duration of a realised injection once it triggers detectable effects, but does not bound most members (SQLi, XSS, LDAP) whose payloads stay in-band and never cross a monitored boundary or produce the listed anomalies.
- A07finds — A.8.16's monitoring of access attempts, anomalous behaviour, unauthorized access, and known attack patterns (including those tied to credential stuffing or session anomalies) surfaces many authentication failures after they occur, but does not discover design or implementation defects such as weak password reset flows or flawed session management before exploitation.
- A07mitigates — A.8.16's real-time anomaly detection (unauthorized access attempts, unusual login patterns, brute-force indicators, session anomalies, malicious traffic) bounds the realized impact of many A07 failures without eliminating the underlying authentication defects themselves.
- A08finds — A.8.16's monitoring for anomalous behaviour, malware signatures, unauthorized changes, process injection, tampered code execution and baseline deviations directly surfaces many integrity failures (e.g. unsigned updates, CI/CD anomalies, insecure deserialization side-effects) after they occur, but does not discover all members such as purely static trust of unsigned code or deserialization logic bugs before exploitation.
- A08mitigates — A.8.16's real-time anomaly detection (tamper checks on executed code, malware signatures, process injection, unauthorized config changes, baseline deviations) bounds the realized impact of some A08 failures such as unsigned updates or CI/CD tampering once they occur, but does not address the core weakness of trusting unverified data/code (e.g. insecure deserialization) nor prevent most integrity failures from succeeding in the first place.
- A09mitigates — A.8.16 directly configures monitoring, baselines, anomaly detection, real-time alerting, and response procedures that bound the realized consequences of missing or ineffective logging/alerting (the weakness is present but its undetected-incident payoff is reduced).
- A10finds — A.8.16's monitoring for anomalous behaviour, unauthorized access attempts, malware indicators, unusual system behaviour and real-time alerts can surface many (but not all) exceptional-condition leaks, fail-open states or inconsistent error paths after they occur.
- A10mitigates — A.8.16's real-time anomaly detection (unauthorized access, process injection, unusual behaviour, malware patterns) can bound the blast radius or downstream impact of a realized exception-handling failure, but does not address the core weakness of leaky error paths, fail-open logic or inconsistent states themselves.
Control IDs, short titles and the structured attribute table (control type, CIA properties, cybersecurity-concept, operational capability, security domain) are facts from ISO/IEC 27001:2022 Annex A / ISO/IEC 27002:2022. The full implementation guidance prose lives in ISO/IEC 27002:2022 — not reproduced here. Cross-walks to NIST 800-53, NIST CSF 2.0, OWASP ASVS, CWE, MITRE ATT&CK and OWASP Web Top 10 are our own AI-authored analysis (authority llm_unverified, under review), not an ISO, NIST, MITRE or OWASP product — how ours compare.