Attack to detection
One attacker move a week, and what the rules actually saw.
We run a single technique several ways on a lab machine we own, capture the telemetry, and read the detection rules that are meant to catch it against what was recorded. The grid under every piece is that reading - not alert results, and it says so on its face.
2 pieces published
T1518.001
The three rules we run for this technique all name a tool
A detection anchored to a tool is a detection of that tool. The behaviour outlives the tool.
1 / 5routes to the same outcome, caught by any of the 3 rules read5 routes run3 rules read as textlab capture 2026-09-13Read the piece →T1053.005
The scheduled-task alert that only knows one word for it
The lesson is not that the rule is bad. It is that a detection anchored to one tool's name inherits that tool's blind spots. Persistence is an outcome. Assert the outcome — a task was registered, read from 4698 — not the name of whichever program registered it this time.
0 / 2routes to the same outcome, caught by any of the 1 rule read2 routes run1 rule read as textlab capture 2026-09-12Read the piece →