You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
first of all, thanks for the great work around the Top ATT&CK Techniques Calculator.
My issue is the following: whether I set 'process Monitoring Components' to 'high' or to 'none', I get the same top 10 list, which is:
T1059 Command and Scripting Interpreter
T1053 Scheduled Task/Job
T1562 Impair Defenses
T1055 Process Injection
T1543 Create or Modify System Process
T1218 System Binary Proxy Execution
T1047 Windows Management Instrumentation
T1574 Hijack Execution Flow
T1036 Masquerading
T1112 Modify Registry
The point is that this list does not seem to be consistent with my choices, because the following TTP are unlikely to be detected with no process monitoring (like EDR), right?
T1055 Process Injection
T1059 Command and Scripting Interpreter
T1218 System Binary Proxy Execution
T1047 Windows Management Instrumentation
T1574 Hijack Execution Flow
T1036 Masquerading
therefore, when I set 'process monitoring' to 'none', I do expect that top TTP list to change, unless I got lost somewhere.
Many thanks and regards,
--
Philippe VIALLE
The text was updated successfully, but these errors were encountered:
Hi all,
first of all, thanks for the great work around the Top ATT&CK Techniques Calculator.
My issue is the following: whether I set 'process Monitoring Components' to 'high' or to 'none', I get the same top 10 list, which is:
The point is that this list does not seem to be consistent with my choices, because the following TTP are unlikely to be detected with no process monitoring (like EDR), right?
T1055 Process Injection
T1059 Command and Scripting Interpreter
T1218 System Binary Proxy Execution
T1047 Windows Management Instrumentation
T1574 Hijack Execution Flow
T1036 Masquerading
therefore, when I set 'process monitoring' to 'none', I do expect that top TTP list to change, unless I got lost somewhere.
Many thanks and regards,
--
Philippe VIALLE
The text was updated successfully, but these errors were encountered: