The analysis covered 29 observed techniques or detection signals across three scenarios. I evaluated ATT&CK mapping, execution stage, impact, detection feasibility, required telemetry and likely fidelity. That connected the detection requirements to activity demonstrated in the assessment.
Viewed
UK Water Utility
Translate attacker behaviour into detection requirements
From Red Team findings to SQL and SMB detections
Return to the full story ←