---
layout: default
title: Chokepoint Identification Framework
description: A practical methodology for identifying durable detection chokepoints. For every technique, ask what must be true and what the attacker cannot control. Detect the invariant, detect all variations.
---
For every technique: what must be true, and what can't the attacker control? Those invariants are chokepoints - detect them, catch every variant.
Adapted from Matt Graeber's threat research methodology at Red Canary.
Chokepoint Identification Framework
Steps 1–3 scope the technique. Step 4 finds the chokepoint. Steps 5–6 make it a detection.
Define the objective. What does the attacker need to accomplish? Gain initial access? Move laterally? Evade defenses?
Identify the required components. Every prerequisite that must be satisfied, regardless of the tool used.
The variables. Tool choice (Impacket, CrackMapExec, PsExec), obfuscation methods, infrastructure, binary names.
The prerequisites from step 2 that no tool rotation, obfuscation, or variant can eliminate. These are your detection anchors.
Map to log sources and telemetry. Sysmon event IDs, ETW providers, network artifacts, EDR hooks.
Every tool and method that shares this chokepoint. One detection anchored to the invariant covers all of them.
Start broad, refine to production. Don't skip levels - the research rule is the baseline you tune from.
Baseline understanding of the chokepoint in your environment. High false positive rate expected. Not for alerting.
process_creation
where ParentImage endswith
'services.exe'
and LogonType = 3
Add context: parent process constraints, user filtering, timing windows. Noise drops. Coverage holds.
process_creation
where ParentImage endswith
'services.exe'
and LogonType = 3
and User != 'SYSTEM'
and Image not in
(known_service_binaries)
High-fidelity, correlated events. Minimal false positives. Your SOC acts on these without second-guessing.
process_creation
where ParentImage endswith
'services.exe'
and LogonType = 3
and User != 'SYSTEM'
and Image not in
(known_service_binaries)
and Image path not in
(Program Files, System32)
and correlated with
EID 4624 Type 3 within 5s
CommandLine contains "psexec.exe"
// Bypassed by: renaming, different tools
Service creation via network logon
// Catches: psexec, wmiexec, smbexec, future tools
How chokepoints connect to MITRE ATT&CK techniques, tactics, and tool variations. Click a tactic to filter. Click any node to explore.
Four questions. All must be yes for a valid, durable chokepoint.
Can they achieve the objective without meeting these conditions? If no, valid chokepoint.
Does this detection break if the attacker switches tools? If no, good chokepoint.
Does this detection apply to more than one tool or malware family? If yes, strong chokepoint.
Is this detection likely to remain effective without constant tuning? If yes, durable chokepoint.
Pick a chokepoint. Apply the 6 steps. Write your first detection.