Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

top 10 doesn't change even if I set process monitoring to "none" or "high" #35

Open
cyb3rxp opened this issue Aug 28, 2024 · 1 comment

Comments

@cyb3rxp
Copy link

cyb3rxp commented Aug 28, 2024

Hi all,

first of all, thanks for the great work around the Top ATT&CK Techniques Calculator.

My issue is the following: whether I set 'process Monitoring Components' to 'high' or to 'none', I get the same top 10 list, which is:

  1. T1059 Command and Scripting Interpreter
  2. T1053 Scheduled Task/Job
  3. T1562 Impair Defenses
  4. T1055 Process Injection
  5. T1543 Create or Modify System Process
  6. T1218 System Binary Proxy Execution
  7. T1047 Windows Management Instrumentation
  8. T1574 Hijack Execution Flow
  9. T1036 Masquerading
  10. T1112 Modify Registry

The point is that this list does not seem to be consistent with my choices, because the following TTP are unlikely to be detected with no process monitoring (like EDR), right?
T1055 Process Injection
T1059 Command and Scripting Interpreter
T1218 System Binary Proxy Execution
T1047 Windows Management Instrumentation
T1574 Hijack Execution Flow
T1036 Masquerading
therefore, when I set 'process monitoring' to 'none', I do expect that top TTP list to change, unless I got lost somewhere.

Many thanks and regards,

--
Philippe VIALLE

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants
@cyb3rxp and others