Skip to main content
CYBER-RESILIENCE5 MIN READ

Turn an Attack Technique Into a Detection

Create a detection hypothesis from an adversary technique and available log source.

The SOC claims it detects credential dumping, but cannot tie the claim to adversary behavior, telemetry, test evidence, or response action. Technique -> data source -> analytic -> test -> response action. Counting SIEM rules creates comfort without proving coverage of the behavior that matters. Technique Name the behavior: credential access through attempts to read LSASS memory or dump credential material. The technique anchors the detection to adversary behavior instead of a tool name that can change. Data source Choose telemetry that can show the behavior: EDR process access events, command-line telemetry, Windows security logs, and privileged logon context. If…

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us