Table of Contents

Return to the Detection Engineering and Incident Response Course

ATT&CK describes adversary behavior and defensive knowledge. A technique label does not prove intent, attribution, or compromise.

Use Current Objects

ATT&CK v18 replaced technique-level detection text with Detection Strategies and platform-specific Analytics. ATT&CK v19.2 is current on October 10, 2026.

ObjectPurposeAnalyst use
TechniqueDescribes adversary behaviorName the behavior under review
Detection StrategyGroups a high-level detection approachState the behavior chain and needed evidence
AnalyticGives platform-specific logicAdapt conditions to available telemetry
Data ComponentNames an observable event propertyCheck whether collection supports the logic

Legacy Data Sources were deprecated in v18. Keep older mappings for historical work, then review current Data Components and Analytics before creating new coverage claims.

Map the Scenario

Start with facts from the sample data. Use a confidence label for each mapping.

EvidenceCandidate behaviorConfidence
A-1004 successful legacy-protocol sign-in after failuresValid Accounts, T1078High for credential use, low for actor identity
E-2003 Word launches encoded PowerShellPowerShell, T1059.001High
E-2005 scheduled task starts a scriptScheduled Task/Job: Scheduled Task, T1053.005High
E-2006 plus D-3002 process connects after name resolutionOutbound network communication to a resolved destinationHigh for connection, unknown for application protocol or command purpose
A-1005 hidden mailbox ruleEmail Collection or account manipulation behaviorMedium, review exact ATT&CK object and provider audit detail

Do not force every event into ATT&CK. Business context, incident impact, and response authority sit outside a technique map.

Write a Strategy Card

Create a card for the Word-to-PowerShell behavior.

Behavior: Office process starts PowerShell with encoded content
Question: Did a document trigger script execution outside approved automation?
Required observations: parent process, child process, command line, user, host, time
Correlation: same host and user within 60 seconds
Exclusions: signed enterprise add-ins with documented child-process behavior
Escalation: decoded content, file creation, persistence, or outbound connection
Missing evidence: script block logs and file origin metadata
ATT&CK references: technique T1059.001 plus relevant Detection Strategy and Analytic

The card starts with behavior and evidence. ATT&CK supplies vocabulary and related logic. Your environment supplies thresholds, exclusions, and response actions.

Practice Steps

  1. Pick E-2003, E-2005, and A-1004.
  2. Find the current ATT&CK technique page for each behavior.
  3. Follow its Detection Strategy and Analytic links.
  4. Record the required Data Components.
  5. Compare the requirements with the course telemetry inventory.
  6. Mark each supported field, missing field, and ambiguous field.
  7. Write one strategy card.

Expected Result: the card names a behavior, required observations, a correlation window, exclusions, escalation evidence, and collection gaps.

Troubleshooting

ProblemFix
Search results show old detection textCheck the ATT&CK version and use the current v19.2 site
Several techniques fitKeep multiple candidates until evidence supports a narrower statement
An Analytic names unavailable fieldsRecord the gap and adapt the logic without claiming full coverage
A rule matches one command string onlyReframe the strategy around behavior and add platform-specific indicators later

Verify Your Work

  • Every mapping points to source evidence
  • Confidence is explicit
  • Current Detection Strategies and Analytics replace deprecated Data Source planning
  • Missing telemetry appears in the card
  • No mapping is presented as proof of malicious intent

Primary references, checked 2026-10-10: ATT&CK version history , Detection Strategies , Analytics , and ATT&CK v18 defensive changes .

Next Steps

Continue to Lesson 3: Detection Hypotheses and Rules . Turn the strategy card into testable logic.