iimp0ster 9464482335 Merge pull request #167 from iimp0ster/data/edge-jul16-infra-refresh
edge-exploits: fix stale SAP/SonicWall prose + rebuild infra tables from live data
2026-07-16 21:18:51 -06:00

Detection Chokepoints

Detection Chokepoints — 16-bit arcade fighting-game scene of a jiu-jitsu rear naked choke with body triangle: the fighter in red has back control and strangles the fighter in blue, with health bars and a match timer overhead

TTPs evolve. Chokepoints don't.

A community detection engineering resource organized around invariant prerequisites. Every chokepoint here is a condition the attacker cannot avoid, no matter which tool they pick or how they obfuscate it. Detect the prerequisite, catch every variant that needs it.

Live site: iimp0ster.github.io/detection-chokepoints


Why This Exists

Kaspersky analyzed eight major ransomware operations in 2022 and found they all share the same core kill chain. External Remote Services, command and scripting interpreters, WMI, and LSASS credential dumping show up in every single group. Shadow copy deletion and service stopping appear in 7 of 8. The tools rotate constantly. The requirements don't.

That pattern is not ransomware-specific. We rebuilt the TTP overlap analysis across 5 attack chains using Kitsune, an AI-driven threat intelligence pipeline, correlating procedure-level data from 60+ vendor and government reports sourced via ORKL. Every chain converges on a handful of unavoidable chokepoints. The framework is the same every time.

Meanwhile attacker speed keeps compressing the response window. Mandiant M-Trends 2025 puts global median dwell time at 11 days, down from 416 in 2011 — and Unit 42's 2026 Global Incident Response Report clocks the fastest quartile of intrusions at 72 minutes from compromise to data exfiltration. There is no time to chase tool signatures. You need detections that survive tool rotation on the first try.


Chokepoint Index

13 chokepoints tracked. Each has a canonical YAML entry and Sigma rules at three maturity levels; endpoint-side chokepoints also ship PowerShell emulation scripts for lab validation.

Chokepoint Tactic Priority Prevalence Difficulty
LSASS Credential Dumping Credential Access CRITICAL VERY HIGH MEDIUM
AiTM WebSocket Kit Relay Credential Access CRITICAL HIGH MEDIUM
Infostealer Browser Credential Theft Credential Access / Collection / Exfiltration CRITICAL HIGH MEDIUM
EDR Bypass Techniques Defense Evasion CRITICAL HIGH HIGH
Ransomware Service Manipulation Defense Evasion / Impact CRITICAL HIGH LOW
Web Shell Persistence Persistence / Initial Access / Execution CRITICAL HIGH MEDIUM
ClickFix Techniques Initial Access HIGH HIGH LOW
Renamed RMM Tools Initial Access / C2 HIGH HIGH MEDIUM
Remote Execution Tools (HackTools) Lateral Movement / Execution HIGH HIGH MEDIUM
BYOSI Scripting Interpreters Defense Evasion / Execution HIGH EMERGING HIGH
OAuth Device Code Phishing via Auth Broker Defense Evasion HIGH MEDIUM LOW
Post-AiTM Graph API Reconnaissance Burst Discovery HIGH MEDIUM MEDIUM
AiTM Kit Device PRT Enrollment Persistence HIGH MEDIUM LOW

Attack Chains

Each chain maps 5 actors against the same kill chain to show where every group converges. Research-backed TTP data via Kitsune + ORKL.

Chain Actors Tracked Shared Techniques
Ransomware BlackBasta, LockBit 3.0, Akira, Alphv/BlackCat, Play 260 procedures, 36 reports
Infostealers RedLine, LummaC2, Vidar, StealC, Raccoon 28 shared
AiTM / Phishing Kits Tycoon 2FA, Evilginx, EvilProxy, Sneaky 2FA, Device Code 12 shared
Hypervisor Compromise BRICKSTORM/UNC5221, UNC3886, Scattered Spider, Play, Alphv 22 shared
AD / Identity Domination APT29, Storm-0501, Storm-2372, Scattered Spider, Ransomware ops 23 shared

The Framework

Adapted from Matt Graeber's threat research methodology at Red Canary. For every technique, ask six questions in order:

  1. What is this technique at a technical level?
  2. What must be true for it to succeed?
  3. What does the attacker control?
  4. What can't the attacker control? ← the chokepoint
  5. Can we observe it?
  6. What are all the variations?

Steps 1-3 build understanding. Step 4 identifies the chokepoint. Steps 5-6 turn it into a detection.

Full walkthrough with worked examples, the interactive chokepoint relationship map (chokepoints ↔ ATT&CK techniques ↔ tool variations, filterable by tactic), and the maturity model: Framework page.


Detection Maturity Model

Every chokepoint ships with Sigma rules at three levels. Don't skip ahead.

Level Goal FP Rate Use Case
Research Establish visibility, baseline behavior High Threat research, log source validation
Hunt Reduce noise, keep coverage Medium Active hunting, campaign detection
Analyst Production SOC alerting Low Automated alerting, IR escalation

Start with Research to learn what's in your environment. Tune to Hunt. Harden to Analyst. Each level feeds the next.


Prevention Layer

Detection is half the value. Every chokepoint also documents categorized prevention opportunities — application control, LOLBAS/interpreter blocking, Credential Guard/PPL, MFA enforcement — mapped where applicable to MagicSword threat-driven application control profiles.


Data-driven analysis of shifts in the chokepoint landscape. What cradles dominate, which evasion techniques are rising, what infrastructure actors reuse.

  • ClickFix Delivery Chain: a year of MHaggis ClickGrab / ClickFix Hunter crawl data — 21,500+ sites analyzed, 20,500+ malicious. Tracks cradle family evolution (the IWR→curl pivot), 18x growth in Base64 evasion, self-delete emergence, and CDN staging.
  • Edge Device Exploit Trends: Defused Cyber honeypot telemetry across 25 decoy types and 40+ CVEs — 15,000+ exploit attempts. CitrixBleed 2 toolkit prevalence, the CVE-2022-22536 SAP burst, multi-stage kill chains, self-replicating worms.
  • Software Impersonation Infrastructure: validated favicon-pivot hunts plus a 1,500+ record IOC pipeline (MalwareBazaar, ThreatFox, URLScan). JavaScript-gated EXE delivery, ClickFix install modals, developer-tool domain squats.

Repository Structure

chokepoints/      # Canonical YAML entries, one file per chokepoint, organized by tactic
sigma-rules/      # Sigma rules at three maturity levels (research / hunt / analyst)
iok-rules/        # Indicator of Knowledge rules for lure/phishing page detection
emulation/        # PowerShell scripts to validate detections in a lab
attack-chains/    # Full kill chain documentation with actor convergence matrices
trends/           # Threat trend analyses and chokepoint evolution tracking
intel/            # Free intelligence resources tied to specific chokepoints
templates/        # Templates for contributors (chokepoint YAML, quick-add, evolution tracker)
scripts/          # Data ingestion and overlap-builder scripts (Kitsune + ORKL pipeline artifacts)
schema/           # Field definitions and valid values for chokepoint entries
_data/            # Jekyll data files (chokepoints, TTP overlap per attack chain)

How to Use This Repository

Threat hunters

  1. Browse chokepoints/ by tactic
  2. Grab the Sigma rule at your target maturity level from sigma-rules/
  3. Check trends/ for current telemetry on what's actually in the wild

Detection engineers

  1. Deploy the Research rule to baseline behavior in your environment
  2. Tune the Hunt rule against your baseline
  3. Promote to Analyst once false positives are acceptable
  4. Validate with the PowerShell emulation scripts in emulation/ in an isolated lab

Phishing and lure detection

  1. Check iok-rules/ for Indicator of Knowledge rules at the web proxy or phish.report layer
  2. IOK rules detect invariant page-side behaviors (clipboard seeding + execution instruction) regardless of visual design or obfuscation

Tracking threat evolution


Contributing

You don't need to submit a complete chokepoint page to contribute. Every empty field on an existing page is an open contribution. Pick what you can fill in.

Ask yourself before submitting: if the attacker switches tools tomorrow, does this detection still fire? If yes, it's a chokepoint. If no, it may be a useful IOC, but it isn't a chokepoint entry.

Paths that need help:

  • Missing Sigma rules at any tier (research, hunt, analyst)
  • OSINT pivot queries for platforms not yet covered
  • Log samples for stages with empty RawLogs
  • Emulation scripts for chokepoints that don't have one
  • EvolutionTimeline entries for newly reported variants
  • BypassNote entries documenting known evasion paths

Full contribution guide, schema reference, and PR checklist: CONTRIBUTING.md.


Resources

Resource Used for
MITRE ATT&CK Technique taxonomy for all chokepoint mappings
Sigma Specification Rule format across all detection levels
Kitsune AI-driven threat intelligence pipeline used to extract and correlate procedure-level data
ORKL Open Repository of Knowledge on Libraries, source corpus for attack chain analysis
Kaspersky: Common TTPs of Modern Ransomware (2022) Empirical foundation for the chokepoint approach
Mandiant M-Trends Source for TTR compression data
Red Canary: The Why, What, and How of Threat Research Matt Graeber's research methodology that this framework adapts
MHaggis ClickGrab Live ClickFix crawl data feeding the trends analysis
Defused Cyber Honeypot telemetry feeding the edge-exploit trends analysis
Huntress: Don't Sweat the ClickFix Techniques In-the-wild ClickFix variant breakdown

Detection is a game of economics. Make it expensive for attackers to avoid your detections.

S
Description
Automated archival mirror of github.com/iimp0ster/detection-chokepoints
Readme
6.2 MiB
Languages
Python 47.1%
HTML 30%
CSS 9.4%
JavaScript 8.1%
PowerShell 5.3%
Other 0.1%