2 Comments

User's avatar
Jordan A's avatar

Gabriel, I agree with a lot of this! I've been working to identify the techniques that should only be detected *opportunistically* - that is, with no expectation of complete coverage. Powershell is the perfect example. Interestingly some techniques *can* be detected comprehensively because their procedures can be enumerated and each procedure can be detected theoretically. Love to hear more about what you think about this. https://thrivingdefense.com/principles/some-techniques-should-only-be-detected-opportunistically

Sam Bodine's avatar

great point. wondering what, if any, semi automated system can provide mechanical objectivity for sales and still be useful for detection engineering prioritization. perhaps some sort of visually weighted matrix? e.g. a technique is larger if it's commonly abused.

the depth problem is especially hard to automate. though perhaps you could feed the procedure examples to an LLM with your detections and estimate (though imperfectly) the coverage across many procedures

No posts

Ready for more?