mirror of
https://github.com/iimp0ster/detection-chokepoints
synced 2026-08-09 12:41:00 +00:00
Commit 5: Trim Intel Resources to foundational-only (per-chokepoint judgment)
YAML: Removed variant-specific, single-incident, secondary, and annual report entries from all 7 chokepoint Intel sections. Migrated variant- specific sources to SourceURL on variation cards (Commit 3). Added Tier: primary to entries that lacked the field. No Tier: supporting entries remain in any chokepoint file. Entry counts after trim: clickfix: 18 → 9 renamed-rmm: 7 → 4 edr-bypass: 10 → 4 (Tier field added to all kept entries) ransomware-svc: 8 → 3 browser-credential: 9 → 5 (Tier field added to all kept entries) web-shells: 10 → 5 (Tier field added to all kept entries) remote-execution: 9 → 7 Layout: Replaced tiered Intel rendering (primary card grid + supporting collapsible toggle) with a uniform flat link list — title (link) + one sentence description. Removed intel-card, intel-grid, intel-card-name, intel-card-desc, intel-linked, intel-link-tag, intel-supporting-toggle CSS. Removed intel-supporting-toggle JS event handler. https://claude.ai/code/session_018xsxUHnwvGtKP6J2W69qa5
This commit is contained in:
@@ -191,7 +191,7 @@ Intel:
|
||||
URL: https://attack.mitre.org/software/S0357/
|
||||
Description: Lists every known threat actor (APT groups, ransomware operators) documented using Impacket; far more useful to a defender than the raw GitHub repo for understanding real-world prevalence
|
||||
- Name: MITRE ATT&CK — T1021.003 DCOM
|
||||
Tier: supporting
|
||||
Tier: primary
|
||||
URL: https://attack.mitre.org/techniques/T1021/003/
|
||||
Description: Technique definition for DCOM-based lateral movement; covers dcomexec.py usage and detection guidance
|
||||
- Name: MITRE ATT&CK — T1569.002 Service Execution
|
||||
@@ -203,27 +203,19 @@ Intel:
|
||||
URL: https://www.microsoft.com/en-us/security/blog/2024/09/26/storm-0501-ransomware-attacks-expanding-to-hybrid-cloud-environments/
|
||||
Description: Documents Storm-0501 using Impacket SecretsDump for lateral movement in hybrid cloud environments; concrete example of Impacket use in a 2024 ransomware campaign
|
||||
LinkedFrom: ["Impacket"]
|
||||
- Name: ThreatLocker — Top 10 Post-Exploitation Tools Threat Actors Use
|
||||
Tier: primary
|
||||
URL: https://www.threatlocker.com/blog/top-post-exploitation-tools-threat-actors-use
|
||||
Description: Real-world prevalence data for post-exploitation tooling including Impacket, NetExec, and C2 frameworks observed across actual intrusions
|
||||
- Name: Impacket GitHub
|
||||
Tier: supporting
|
||||
Tier: primary
|
||||
URL: https://github.com/fortra/impacket
|
||||
Description: Monitor releases and PRs for new execution modules; source of truth for what capabilities the suite currently covers
|
||||
- Name: NetExec GitHub
|
||||
Tier: supporting
|
||||
Tier: primary
|
||||
URL: https://github.com/Pennyw0rth/NetExec
|
||||
Description: Active successor to CrackMapExec; track new protocol support and OPSEC improvements that affect detection
|
||||
- Name: SOC Investigation — Event ID 5145 Threat Hunting
|
||||
Tier: supporting
|
||||
Tier: primary
|
||||
URL: https://www.socinvestigation.com/threat-hunting-with-eventid-5145-object-access-detailed-file-share/
|
||||
Description: Detailed guidance on using Event ID 5145 (Detailed File Share) for lateral movement detection; covers IPC$ access correlation
|
||||
LinkedFrom: ["Remote Execution Primitive"]
|
||||
- Name: "hunt.io — C2 Infrastructure Tracking"
|
||||
Tier: supporting
|
||||
URL: "https://hunt.io"
|
||||
Description: "Real-time C2 infrastructure map; AttackCapture feed tags Cobalt Strike, Sliver, Havoc, and Metasploit servers by banner and certificate fingerprint."
|
||||
|
||||
RelatedChokepoints:
|
||||
- ransomware-service-manipulation
|
||||
|
||||
Reference in New Issue
Block a user