Detection Engineering Lesson 2: ATT&CK Detection Strategies
Table of Contents
Return to the Detection Engineering and Incident Response Course
ATT&CK describes adversary behavior and defensive knowledge. A technique label does not prove intent, attribution, or compromise.
Use Current Objects
ATT&CK v18 replaced technique-level detection text with Detection Strategies and platform-specific Analytics. ATT&CK v19.2 is current on October 10, 2026.
| Object | Purpose | Analyst use |
|---|---|---|
| Technique | Describes adversary behavior | Name the behavior under review |
| Detection Strategy | Groups a high-level detection approach | State the behavior chain and needed evidence |
| Analytic | Gives platform-specific logic | Adapt conditions to available telemetry |
| Data Component | Names an observable event property | Check whether collection supports the logic |
Legacy Data Sources were deprecated in v18. Keep older mappings for historical work, then review current Data Components and Analytics before creating new coverage claims.
Map the Scenario
Start with facts from the sample data. Use a confidence label for each mapping.
| Evidence | Candidate behavior | Confidence |
|---|---|---|
A-1004 successful legacy-protocol sign-in after failures | Valid Accounts, T1078 | High for credential use, low for actor identity |
E-2003 Word launches encoded PowerShell | PowerShell, T1059.001 | High |
E-2005 scheduled task starts a script | Scheduled Task/Job: Scheduled Task, T1053.005 | High |
E-2006 plus D-3002 process connects after name resolution | Outbound network communication to a resolved destination | High for connection, unknown for application protocol or command purpose |
A-1005 hidden mailbox rule | Email Collection or account manipulation behavior | Medium, review exact ATT&CK object and provider audit detail |
Do not force every event into ATT&CK. Business context, incident impact, and response authority sit outside a technique map.
Write a Strategy Card
Create a card for the Word-to-PowerShell behavior.
Behavior: Office process starts PowerShell with encoded content
Question: Did a document trigger script execution outside approved automation?
Required observations: parent process, child process, command line, user, host, time
Correlation: same host and user within 60 seconds
Exclusions: signed enterprise add-ins with documented child-process behavior
Escalation: decoded content, file creation, persistence, or outbound connection
Missing evidence: script block logs and file origin metadata
ATT&CK references: technique T1059.001 plus relevant Detection Strategy and Analytic
The card starts with behavior and evidence. ATT&CK supplies vocabulary and related logic. Your environment supplies thresholds, exclusions, and response actions.
Practice Steps
- Pick
E-2003,E-2005, andA-1004. - Find the current ATT&CK technique page for each behavior.
- Follow its Detection Strategy and Analytic links.
- Record the required Data Components.
- Compare the requirements with the course telemetry inventory.
- Mark each supported field, missing field, and ambiguous field.
- Write one strategy card.
Expected Result: the card names a behavior, required observations, a correlation window, exclusions, escalation evidence, and collection gaps.
Troubleshooting
| Problem | Fix |
|---|---|
| Search results show old detection text | Check the ATT&CK version and use the current v19.2 site |
| Several techniques fit | Keep multiple candidates until evidence supports a narrower statement |
| An Analytic names unavailable fields | Record the gap and adapt the logic without claiming full coverage |
| A rule matches one command string only | Reframe the strategy around behavior and add platform-specific indicators later |
Verify Your Work
- Every mapping points to source evidence
- Confidence is explicit
- Current Detection Strategies and Analytics replace deprecated Data Source planning
- Missing telemetry appears in the card
- No mapping is presented as proof of malicious intent
Primary references, checked 2026-10-10: ATT&CK version history , Detection Strategies , Analytics , and ATT&CK v18 defensive changes .
Next Steps
Continue to Lesson 3: Detection Hypotheses and Rules . Turn the strategy card into testable logic.


