Attack Chokepoints {% if cp.Chokepoints %} {{ cp.Chokepoints | size | escape }} invariant stage{% if cp.Chokepoints.size != 1 %}s{% endif %} {% endif %}
Applying the chokepoint framework to {{ cp.Name | escape }}. Learn the framework →
-
{% for item in cp.AttackerControls %}
- {{ item | escape }} {% endfor %}
-
{% for item in cp.AttackerCannotControl %}
- {{ item | escape }} {% endfor %}
Each stage is an invariant condition the attacker must satisfy, regardless of tool, variant, or threat actor. Detection at any stage breaks the chain.
{% endif %}{{ forloop.index }} {{ stage.Stage | escape }} ▶
-
{% for prereq in cp.Prerequisites %}
- {{ prereq | escape }} {% endfor %}
-
{% for src in stage.LogSources %}
- {{ src | escape }} {% endfor %}
{{ stage.TruePositive.Title | escape }} ▶
Attack Chokepoints data not yet structured for this page. See the YAML source for prerequisites and detection logic.
{% endif %}Variations {{ cp.Variations | size | escape }} variant{% if cp.Variations.size != 1 %}s{% endif %} tracked
Tools and methods that exploit this chokepoint. The list grows. The chokepoint doesn't change.
{{ v.Name | escape }} {{ v.FirstSeen | escape }} {{ v.Status | escape }} ▶
{{ p.Command | xml_escape }}
{% if p.Note %}{{ v.Command.Invocation | xml_escape }}
{% endif %}
{% if v.Command.Artifacts %}
-
{% for a in v.Command.Artifacts %}
- {{ a | escape }} {% endfor %}
Detection Strategy
Rules organized by the chokepoint stage they detect. Each stage has one or more rules at different maturity levels.
{% for stage in cp.Chokepoints %}
{{ ed.Layer | default: "Pre-Execution Detection" | escape }}
Pre-Exec
{% if ed.ExpectedFPRate %}
{% assign fp_lower = ed.ExpectedFPRate | downcase %}
{{ ed.ExpectedFPRate | escape }} FP
{% endif %}
▶
{{ ed.Logic | strip | escape }}
{% endif %}
{{ ed._rule_content | xml_escape }}
{% else %}
Rule file not found. Contribute one.
{% endif %}
{{ det.Description | truncate: 80 }}
{% if badge_class == "det-badge-research" %}
{% elsif badge_class == "det-badge-hunt" %}
{% elsif badge_class == "det-badge-analyst" %}
{% endif %}{{ det.Level }}
{% assign fp_lower = det.ExpectedFPRate | downcase %}
{% if fp_lower == "high" %}
High FP
{% elsif fp_lower == "medium" %}
Med FP
{% elsif fp_lower == "low" %}
Low FP
{% endif %}
▶
{{ det.Logic | strip }}
{% endif %}
{% if det.Description contains "correlate" or det.Description contains "Correlate" %}
{{ sigma_content | xml_escape }}
{% else %}
Sigma rule not yet available. Contribute one.
{% endif %}
Browser-Spawned Interpreter Outbound Connection
Hunt
Med FP
New
▶
Additional behavioral variants beyond the three core tiers. Experimental / unvalidated — tune before production use.
{% for k in supp_keys %} {% assign supp_content = cp[k] %} {% if supp_content %} {% assign idx = forloop.index0 %} {% endif %} {% endfor %}Build detections iteratively. Start broad to understand your baseline, then tighten to production-ready alerting.
{% endif %}
{{ ed._rule_content | xml_escape }}
{% else %}
Rule file not found. Contribute one.
{% endif %}Pre-execution detection content not yet available. Contribute one.
{% endif %}{{ detection.Logic | strip | escape }}
{% endif %}
{% endif %}
{{ sigma_content | xml_escape }}
{% else %}
Sigma rule not yet available for this level. Contribute one.
{% endif %}Prevention Opportunities
{{ cp.PreventionSummary | escape }}
{% endif %} {% if cp.PreventionOpportunities %}{{ opp.Control }}
{{ opp.Impact }}
{% if opp.MagicSwordFit and site.magic_sword_enabled and site.magic_sword_affiliate_url %} {% endif %}Raw Log Samples {{ cp.RawLogs.size }} sample{% if cp.RawLogs.size != 1 %}s{% endif %}
Real-world log events produced by this technique and which Sigma rules they trigger.
{% if log.EventId %}EID {{ log.EventId | escape }}{% endif %} {{ log.Type | escape }} {{ log.Description | escape }} ▶
Emulation
{% if emu.AtomicRef %}ATT&CK: {{ emu.AtomicRef }}{% endif %} {{ emu.Description }} {{ emu.Language }} ▶
OSINT Pivots
{{ src.Query | escape }}
References
-
{% for ref in cp.References %}
- {{ ref }} {% endfor %}