--- layout: default --- {% assign cp = site.data.chokepoints | where: "_slug", page.slug | first %} {% if cp == nil %}

Chokepoint data not found for slug: {{ page.slug }}

{% else %}
← All Chokepoints {{ cp.DetectionPriority | escape }}

{{ cp.Name | escape }}

{% if cp.TheConstant %}

{{ cp.TheConstant | escape }}

{% endif %}
{% for tactic in cp.Tactics %} {{ tactic | escape }} {% endfor %} {% for mid in cp.MitreIds %} {{ mid | escape }} {% endfor %} Detection difficulty: {{ cp.DetectionDifficulty | escape }} Prevalence: {{ cp.ThreatPrevalence | escape }}

{{ cp.Description | escape }}

Attack Chokepoints {% if cp.Chokepoints %} {{ cp.Chokepoints | size | escape }} invariant stage{% if cp.Chokepoints.size != 1 %}s{% endif %} {% endif %}

{% if cp.Chokepoints %} {% if cp.AttackerControls or cp.AttackerCannotControl %}

Applying the chokepoint framework to {{ cp.Name | escape }}. Learn the framework →

{% if cp.AttackerControls %}
Attacker controls (variables)
    {% for item in cp.AttackerControls %}
  • {{ item | escape }}
  • {% endfor %}
{% endif %} {% if cp.AttackerCannotControl %}
Attacker cannot control (chokepoints)
    {% for item in cp.AttackerCannotControl %}
  • {{ item | escape }}
  • {% endfor %}
{% endif %}
{% else %}

Each stage is an invariant condition the attacker must satisfy, regardless of tool, variant, or threat actor. Detection at any stage breaks the chain.

{% endif %}
{% for stage in cp.Chokepoints %} {% if forloop.index > 1 %}
↓ {% if stage.Input %}{{ stage.Input | truncate: 60 | escape }}{% else %}next stage{% endif %}
{% endif %}
{{ forloop.index }} {{ stage.Stage | escape }} ▶
{% if forloop.first and cp.Prerequisites %}
    {% for prereq in cp.Prerequisites %}
  • {{ prereq | escape }}
  • {% endfor %}
{% endif %} {% if stage.Input %}
Input {{ stage.Input | escape }}
{% endif %} {% if stage.Input %}
Chokepoint {{ stage.Invariant | escape }}
{% if stage.Observable %}
Observable {{ stage.Observable | escape }}
{% endif %} {% if stage.WhyCantBypass %}
Why unavoidable
{{ stage.WhyCantBypass | escape }}
{% endif %} {% else %}
Invariant Condition
{{ stage.Invariant | escape }}
{% endif %} {% if stage.LogSources %}
    {% for src in stage.LogSources %}
  • {{ src | escape }}
  • {% endfor %}
{% endif %} {% if stage.BypassNote %}
⚠ Bypass risk: {{ stage.BypassNote | escape }}
{% endif %} {% if stage.TruePositive %}
{{ stage.TruePositive.Title | escape }} ▶
{{ stage.TruePositive.Log | xml_escape }}{% if stage.TruePositive.KeySignal %} Key signal: {{ stage.TruePositive.KeySignal | escape }}{% endif %}
{% endif %} {% if stage.SigmaRef and stage.SigmaRef != "" %} View rule → {% endif %}
{% endfor %}
{% else %}

Attack Chokepoints data not yet structured for this page. See the YAML source for prerequisites and detection logic.

{% endif %}
{% if cp.Variations %}

Variations {{ cp.Variations | size | escape }} variant{% if cp.Variations.size != 1 %}s{% endif %} tracked

Tools and methods that exploit this chokepoint. The list grows. The chokepoint doesn't change.

{% for v in cp.Variations %} {% assign status_lower = v.Status | downcase %} {% if status_lower contains 'legacy' %} {% assign vstatus_class = 'status-legacy' %} {% elsif status_lower contains 'declining' %} {% assign vstatus_class = 'status-declining' %} {% elsif status_lower contains 'disrupted' %} {% assign vstatus_class = 'status-disrupted' %} {% elsif status_lower contains 'emerging' %} {% assign vstatus_class = 'status-emerging' %} {% else %} {% assign vstatus_class = 'status-active' %} {% endif %}
{{ v.Name | escape }} {{ v.FirstSeen | escape }} {{ v.Status | escape }} ▶
{{ v.Notes | default: v.NotesShort | xml_escape }} {% if v.Lure %} {% if v.LurePreview %}
Simulated lure
{% endif %}
{{ v.Lure | escape }}
{% if v.LureTags %}
{% for tag in v.LureTags %}{{ tag | escape }}{% endfor %}
{% endif %} {% endif %} {% if v.Payloads %} {% for p in v.Payloads %} {% if v.Payloads.size > 1 %}{% endif %}
{{ p.Command | xml_escape }}
{% if p.Note %}
{{ p.Note | xml_escape }}
{% endif %} {% endfor %} {% endif %} {% if v.Command %} {% if v.Command.Context %}
{{ v.Command.Context | escape }}
{% endif %} {% if v.Command.Invocation %}
{{ v.Command.Invocation | xml_escape }}
{% endif %} {% if v.Command.Artifacts %}
    {% for a in v.Command.Artifacts %}
  • {{ a | escape }}
  • {% endfor %}
{% endif %} {% endif %} {% if v.ChokepointMapping %}
Same chokepoint: {{ v.ChokepointMapping | escape }}
{% endif %} {% if v.SourceURL %} {% if v.SourceURL.first %} {% for src in v.SourceURL %} Source: {{ src | split: '/' | slice: 2, 1 | first | escape }} → {% endfor %} {% else %} Source: {{ v.SourceURL | split: '/' | slice: 2, 1 | first | escape }} → {% endif %} {% else %} Source link needed → {% endif %}
{% endfor %}
{% endif %}

Detection Strategy

{% if cp.Chokepoints and cp.Chokepoints.size > 0 %} {%- comment -%} ── Stage-grouped layout (new) ── {%- endcomment -%}

Rules organized by the chokepoint stage they detect. Each stage has one or more rules at different maturity levels.

{% for stage in cp.Chokepoints %}
{{ forloop.index }} {{ stage.Stage | escape }}
{%- comment -%} Stage 1: Early Detections (ETW, IOK) {%- endcomment -%} {% if forloop.index == 1 and cp.EarlyDetections and cp.EarlyDetections.size > 0 %} {% for ed in cp.EarlyDetections %}
{{ ed.Layer | default: "Pre-Execution Detection" | escape }}
Pre-Exec {% if ed.ExpectedFPRate %} {% assign fp_lower = ed.ExpectedFPRate | downcase %} {{ ed.ExpectedFPRate | escape }} FP {% endif %}
▶
Goal
{{ ed.Description | escape }}
Log Sources
    {% for src in ed.LogSources %}
  • {{ src | escape }}
  • {% endfor %}
{% if ed.Logic %}
{{ ed.Logic | strip | escape }}
{% endif %}
{% if ed.IokRule %} IOK Rule - {{ ed.Layer | escape }} {% else %} Sigma Rule - {{ ed.Layer | escape }} {% endif %}
{% assign ed_rule_path = ed.SigmaRule | default: ed.IokRule %} {% if ed_rule_path %} GitHub → Download {% endif %}
{% if ed._rule_content %}
{{ ed._rule_content | xml_escape }}
{% else %}

Rule file not found. Contribute one.

{% endif %}
{% endfor %} {% endif %} {%- comment -%} Map stages to detection levels by DetectionTier {%- endcomment -%} {% assign tier_lower = stage.DetectionTier | downcase %} {%- comment -%} Show the stage's primary detection (matching tier) {%- endcomment -%} {% for det in cp.Detections %} {% assign det_lower = det.Level | downcase %} {%- comment -%} Stage 1 only gets EarlyDetections (ETW/IOK) - no sigma rules here {%- endcomment -%} {%- comment -%} A single chokepoint stage owns every maturity tier. {%- endcomment -%} {% if cp.Chokepoints.size == 1 %} {% assign show_rule = true %} {% assign sigma_key = "_sigma_" | append: det_lower %} {% assign badge_class = "det-badge-" | append: det_lower %} {%- comment -%} Stage 2 (Hunt tier) gets hunt AND analyst detections {%- endcomment -%} {% elsif forloop.parentloop.index == 2 and tier_lower == "hunt" and det_lower == "hunt" %} {% assign show_rule = true %} {% assign sigma_key = "_sigma_hunt" %} {% assign badge_class = "det-badge-hunt" %} {% elsif forloop.parentloop.index == 2 and tier_lower == "hunt" and det_lower == "analyst" %} {% assign show_rule = true %} {% assign sigma_key = "_sigma_analyst" %} {% assign badge_class = "det-badge-analyst" %} {%- comment -%} Stage 3 (Analyst tier) gets research (baseline) {%- endcomment -%} {% elsif forloop.parentloop.index == 3 and tier_lower == "analyst" and det_lower == "research" %} {% assign show_rule = true %} {% assign sigma_key = "_sigma_research" %} {% assign badge_class = "det-badge-research" %} {% else %} {% assign show_rule = false %} {% endif %} {% if show_rule %}
{{ det.Description | truncate: 80 }}
{% if badge_class == "det-badge-research" %}{% elsif badge_class == "det-badge-hunt" %}{% elsif badge_class == "det-badge-analyst" %}{% endif %}{{ det.Level }} {% assign fp_lower = det.ExpectedFPRate | downcase %} {% if fp_lower == "high" %} High FP {% elsif fp_lower == "medium" %} Med FP {% elsif fp_lower == "low" %} Low FP {% endif %}
▶
Goal
{{ det.Description }}
Log Sources
    {% for src in det.LogSources %}
  • {{ src | escape }}
  • {% endfor %}
FP Rate
{{ det.ExpectedFPRate }}
Use Case
{{ det.UseCase }}
{% if det.Logic %}
{{ det.Logic | strip }}
{% endif %} {% if det.Description contains "correlate" or det.Description contains "Correlate" %}
⚠ Correlation required: This rule covers one stage only. See the description for SIEM-side join guidance.
{% endif %}
Sigma Rule - {{ det.Level }} Level
{% if det.SigmaRule %} GitHub → Download {% endif %}
{% assign sigma_content = cp[sigma_key] %} {% if sigma_content %}
{{ sigma_content | xml_escape }}
{% else %}

Sigma rule not yet available. Contribute one.

{% endif %}
{% endif %} {% endfor %} {%- comment -%} Stage 3: Also show hunt-network.yml if it exists {%- endcomment -%} {% if forloop.index == 3 and cp["_sigma_hunt-network"] %}
Browser-Spawned Interpreter Outbound Connection
Hunt Med FP New
▶
Goal
Detect scripting interpreters initiating outbound connections to external (non-RFC1918) addresses. Correlate ProcessGuid with hunt.yml to confirm the browser/explorer parent chain from Stage 2.
Log Sources
  • Sysmon Event ID 3 (Network Connection)
⚠ SIEM correlation required: Join this event's ProcessGuid with hunt.yml (Sysmon EID 1) where ParentImage is a browser/explorer/wt.exe and time delta < 300 seconds.
Sigma Rule - Hunt Level (Network)
{{ cp["_sigma_hunt-network"] | xml_escape }}
{% endif %}
{% endfor %} {%- comment -%} Supplementary detection variants — render any present for this chokepoint {%- endcomment -%} {% assign supp_keys = "_sigma_hunt-registry,_sigma_hunt-downloadfix,_sigma_hunt-signer,_sigma_hunt-process" | split: "," %} {% assign supp_paths = "sigma-rules/clickfix/hunt-registry.yml,sigma-rules/clickfix/hunt-downloadfix.yml,sigma-rules/renamed-rmm/hunt-signer.yml,sigma-rules/ransomware-service/hunt-process.yml" | split: "," %} {% assign supp_titles = "Clipboard Command in Explorer RunMRU/TypedPaths (Registry),DownloadFix: Downloaded File with Mark-of-the-Web,Renamed RMM by Authenticode Company/Signer,Direct EDR Process Kill via taskkill" | split: "," %} {% assign has_supp = false %} {% for k in supp_keys %}{% if cp[k] %}{% assign has_supp = true %}{% endif %}{% endfor %} {% if has_supp %}

Additional behavioral variants beyond the three core tiers. Experimental / unvalidated — tune before production use.

{% for k in supp_keys %} {% assign supp_content = cp[k] %} {% if supp_content %} {% assign idx = forloop.index0 %}
{{ supp_titles[idx] }}
Hunt New
▶
Sigma Rule — Supplementary (experimental)
{{ supp_content | xml_escape }}
{% endif %} {% endfor %}
{% endif %} {% else %} {%- comment -%} ── Legacy tab layout (pages without stages) ── {%- endcomment -%}

Build detections iteratively. Start broad to understand your baseline, then tighten to production-ready alerting.

{% if cp.EarlyDetections and cp.EarlyDetections.size > 0 %} {% for ed in cp.EarlyDetections %} {% if forloop.index > 1 %}
{% endif %}
Goal - {{ ed.Layer | escape }}
{{ ed.Description | escape }}
Log Sources
    {% for src in ed.LogSources %}
  • {{ src | escape }}
  • {% endfor %}
{% if ed.IokRule %} IOK Rule - {{ ed.Layer | escape }} {% else %} Sigma Rule - {{ ed.Layer | escape }} {% endif %}
{% assign ed_rule_path = ed.SigmaRule | default: ed.IokRule %} {% if ed_rule_path %} GitHub → Download {% endif %}
{% if ed._rule_content %}
{{ ed._rule_content | xml_escape }}
{% else %}

Rule file not found. Contribute one.

{% endif %}
{% endfor %} {% else %}

Pre-execution detection content not yet available. Contribute one.

{% endif %}
{% assign det_levels = "Research,Hunt,Analyst" | split: "," %} {% for level in det_levels %} {% assign level_lower = level | downcase %} {% assign detection = cp.Detections | where: "Level", level | first %} {% assign sigma_key = "_sigma_" | append: level_lower %}
{% if detection %}
Goal
{{ detection.Description | escape }}
Log Sources
    {% for src in detection.LogSources %}
  • {{ src | escape }}
  • {% endfor %}
{% if detection.Logic %}
{{ detection.Logic | strip | escape }}
{% endif %} {% endif %}
Sigma Rule - {{ level }} Level
{% if detection.SigmaRule %} GitHub → Download {% endif %}
{% assign sigma_content = cp[sigma_key] %} {% if sigma_content %}
{{ sigma_content | xml_escape }}
{% else %}

Sigma rule not yet available for this level. Contribute one.

{% endif %}
{% endfor %} {% endif %}
{% if cp.PreventionSummary or cp.PreventionOpportunities %}

Prevention Opportunities

{% if cp.PreventionSummary %}

{{ cp.PreventionSummary | escape }}

{% endif %} {% if cp.PreventionOpportunities %}
{% for opp in cp.PreventionOpportunities %}
{{ opp.Category }}

{{ opp.Control }}

{{ opp.Impact }}

{% if opp.MagicSwordFit and site.magic_sword_enabled and site.magic_sword_affiliate_url %} {% endif %}
{% endfor %}
{% assign ms_opps = "" %}{% for opp in cp.PreventionOpportunities %}{% if opp.MagicSwordFit %}{% assign ms_opps = "yes" %}{% endif %}{% endfor %} {% endif %}
{% endif %} {% if cp.RawLogs %}

Raw Log Samples {{ cp.RawLogs.size }} sample{% if cp.RawLogs.size != 1 %}s{% endif %}

Real-world log events produced by this technique and which Sigma rules they trigger.

{% for log in cp.RawLogs %}
{% if log.EventId %}EID {{ log.EventId | escape }}{% endif %} {{ log.Type | escape }} {{ log.Description | escape }} ▶
{{ log.Sample | xml_escape }}
{% endfor %}
{% endif %} {% if cp.EmulationScript and cp._emulation_content %}
{% assign emu = cp.EmulationScript %}

Emulation

{% if emu.AtomicRef %}ATT&CK: {{ emu.AtomicRef }}{% endif %} {{ emu.Description }} {{ emu.Language }} ▶
{% if emu.SafetyNotes %}
⚠ Lab use only. {{ emu.SafetyNotes }}
{% endif %}
{{ emu.Language | upcase | default: "Script" }}
{% if emu.File %} GitHub → Download {% endif %}
{% assign emu_lang_raw = emu.Language | downcase | default: "plaintext" %} {% assign emu_lang = "language-" | append: emu_lang_raw %}
{{ cp._emulation_content | xml_escape }}
{% endif %} {% if cp.OsintSources %}

OSINT Pivots

{% endif %} {% if cp.RelatedChokepoints %} {% endif %} {% if cp.References %}

References

    {% for ref in cp.References %}
  • {{ ref }}
  • {% endfor %}
{% endif %}
{% endif %}