transform_provenance.py short() hard-truncated the AS org description at 28 chars, cutting mid-word -- the top provider read "Emil Vitukhnovskii trading a". Fall back to the AS handle when the org would overflow, so the label reads the recognizable "GreatFlower". Labels that already fit are unchanged. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Bx33CDbC3G8DQMQMARewof
Detection Chokepoints
TTPs evolve. Chokepoints don't.
A community detection engineering resource organized around invariant prerequisites. Every chokepoint here is a condition the attacker cannot avoid, no matter which tool they pick or how they obfuscate it. Detect the prerequisite, catch every variant that needs it.
Live site: iimp0ster.github.io/detection-chokepoints
Why This Exists
Kaspersky analyzed eight major ransomware operations in 2022 and found they all share the same core kill chain. External Remote Services, command and scripting interpreters, WMI, and LSASS credential dumping show up in every single group. Shadow copy deletion and service stopping appear in 7 of 8. The tools rotate constantly. The requirements don't.
That pattern is not ransomware-specific. We rebuilt the TTP overlap analysis across 5 attack chains using Kitsune, an AI-driven threat intelligence pipeline, correlating procedure-level data from 60+ vendor and government reports sourced via ORKL. Every chain converges on a handful of unavoidable chokepoints. The framework is the same every time.
Meanwhile attacker speed keeps compressing the response window. Mandiant M-Trends 2025 puts global median dwell time at 11 days, down from 416 in 2011 — and Unit 42's 2026 Global Incident Response Report clocks the fastest quartile of intrusions at 72 minutes from compromise to data exfiltration. There is no time to chase tool signatures. You need detections that survive tool rotation on the first try.
Chokepoint Index
13 chokepoints tracked. Each has a canonical YAML entry and Sigma rules at three maturity levels; endpoint-side chokepoints also ship PowerShell emulation scripts for lab validation.
| Chokepoint | Tactic | Priority | Prevalence | Difficulty |
|---|---|---|---|---|
| LSASS Credential Dumping | Credential Access | CRITICAL | VERY HIGH | MEDIUM |
| AiTM WebSocket Kit Relay | Credential Access | CRITICAL | HIGH | MEDIUM |
| Infostealer Browser Credential Theft | Credential Access / Collection / Exfiltration | CRITICAL | HIGH | MEDIUM |
| EDR Bypass Techniques | Defense Evasion | CRITICAL | HIGH | HIGH |
| Ransomware Service Manipulation | Defense Evasion / Impact | CRITICAL | HIGH | LOW |
| Web Shell Persistence | Persistence / Initial Access / Execution | CRITICAL | HIGH | MEDIUM |
| ClickFix Techniques | Initial Access | HIGH | HIGH | LOW |
| Renamed RMM Tools | Initial Access / C2 | HIGH | HIGH | MEDIUM |
| Remote Execution Tools (HackTools) | Lateral Movement / Execution | HIGH | HIGH | MEDIUM |
| BYOSI Scripting Interpreters | Defense Evasion / Execution | HIGH | EMERGING | HIGH |
| OAuth Device Code Phishing via Auth Broker | Defense Evasion | HIGH | MEDIUM | LOW |
| Post-AiTM Graph API Reconnaissance Burst | Discovery | HIGH | MEDIUM | MEDIUM |
| AiTM Kit Device PRT Enrollment | Persistence | HIGH | MEDIUM | LOW |
Attack Chains
Each chain maps 5 actors against the same kill chain to show where every group converges. Research-backed TTP data via Kitsune + ORKL.
| Chain | Actors Tracked | Shared Techniques |
|---|---|---|
| Ransomware | BlackBasta, LockBit 3.0, Akira, Alphv/BlackCat, Play | 260 procedures, 36 reports |
| Infostealers | RedLine, LummaC2, Vidar, StealC, Raccoon | 28 shared |
| AiTM / Phishing Kits | Tycoon 2FA, Evilginx, EvilProxy, Sneaky 2FA, Device Code | 12 shared |
| Hypervisor Compromise | BRICKSTORM/UNC5221, UNC3886, Scattered Spider, Play, Alphv | 22 shared |
| AD / Identity Domination | APT29, Storm-0501, Storm-2372, Scattered Spider, Ransomware ops | 23 shared |
The Framework
Adapted from Matt Graeber's threat research methodology at Red Canary. For every technique, ask six questions in order:
- What is this technique at a technical level?
- What must be true for it to succeed?
- What does the attacker control?
- What can't the attacker control? ← the chokepoint
- Can we observe it?
- What are all the variations?
Steps 1-3 build understanding. Step 4 identifies the chokepoint. Steps 5-6 turn it into a detection.
Full walkthrough with worked examples, the interactive chokepoint relationship map (chokepoints ↔ ATT&CK techniques ↔ tool variations, filterable by tactic), and the maturity model: Framework page.
Detection Maturity Model
Every chokepoint ships with Sigma rules at three levels. Don't skip ahead.
| Level | Goal | FP Rate | Use Case |
|---|---|---|---|
| Research | Establish visibility, baseline behavior | High | Threat research, log source validation |
| Hunt | Reduce noise, keep coverage | Medium | Active hunting, campaign detection |
| Analyst | Production SOC alerting | Low | Automated alerting, IR escalation |
Start with Research to learn what's in your environment. Tune to Hunt. Harden to Analyst. Each level feeds the next.
Prevention Layer
Detection is half the value. Every chokepoint also documents categorized prevention opportunities — application control, LOLBAS/interpreter blocking, Credential Guard/PPL, MFA enforcement — mapped where applicable to MagicSword threat-driven application control profiles.
Trends
Data-driven analysis of shifts in the chokepoint landscape. What cradles dominate, which evasion techniques are rising, what infrastructure actors reuse.
- ClickFix Delivery Chain: a year of MHaggis ClickGrab / ClickFix Hunter crawl data — 21,500+ sites analyzed, 20,500+ malicious. Tracks cradle family evolution (the IWR→curl pivot), 18x growth in Base64 evasion, self-delete emergence, and CDN staging.
- Edge Device Exploit Trends: Defused Cyber honeypot telemetry across 25 decoy types and 40+ CVEs — 15,000+ exploit attempts. CitrixBleed 2 toolkit prevalence, the CVE-2022-22536 SAP burst, multi-stage kill chains, self-replicating worms.
- Software Impersonation Infrastructure: validated favicon-pivot hunts plus a 1,500+ record IOC pipeline (MalwareBazaar, ThreatFox, URLScan). JavaScript-gated EXE delivery, ClickFix install modals, developer-tool domain squats.
Repository Structure
chokepoints/ # Canonical YAML entries, one file per chokepoint, organized by tactic
sigma-rules/ # Sigma rules at three maturity levels (research / hunt / analyst)
iok-rules/ # Indicator of Knowledge rules for lure/phishing page detection
emulation/ # PowerShell scripts to validate detections in a lab
attack-chains/ # Full kill chain documentation with actor convergence matrices
trends/ # Threat trend analyses and chokepoint evolution tracking
intel/ # Free intelligence resources tied to specific chokepoints
templates/ # Templates for contributors (chokepoint YAML, quick-add, evolution tracker)
scripts/ # Data ingestion and overlap-builder scripts (Kitsune + ORKL pipeline artifacts)
schema/ # Field definitions and valid values for chokepoint entries
_data/ # Jekyll data files (chokepoints, TTP overlap per attack chain)
How to Use This Repository
Threat hunters
- Browse chokepoints/ by tactic
- Grab the Sigma rule at your target maturity level from sigma-rules/
- Check trends/ for current telemetry on what's actually in the wild
Detection engineers
- Deploy the Research rule to baseline behavior in your environment
- Tune the Hunt rule against your baseline
- Promote to Analyst once false positives are acceptable
- Validate with the PowerShell emulation scripts in emulation/ in an isolated lab
Phishing and lure detection
- Check iok-rules/ for Indicator of Knowledge rules at the web proxy or phish.report layer
- IOK rules detect invariant page-side behaviors (clipboard seeding + execution instruction) regardless of visual design or obfuscation
Tracking threat evolution
- New tool variant on an existing chokepoint: use templates/quick-add.md
- New technique entirely: start from templates/chokepoint-template.yml
- Complete worked example: templates/EXAMPLE-WORKFLOW.md
Contributing
You don't need to submit a complete chokepoint page to contribute. Every empty field on an existing page is an open contribution. Pick what you can fill in.
Ask yourself before submitting: if the attacker switches tools tomorrow, does this detection still fire? If yes, it's a chokepoint. If no, it may be a useful IOC, but it isn't a chokepoint entry.
Paths that need help:
- Missing Sigma rules at any tier (research, hunt, analyst)
- OSINT pivot queries for platforms not yet covered
- Log samples for stages with empty
RawLogs - Emulation scripts for chokepoints that don't have one
- EvolutionTimeline entries for newly reported variants
- BypassNote entries documenting known evasion paths
Full contribution guide, schema reference, and PR checklist: CONTRIBUTING.md.
Resources
| Resource | Used for |
|---|---|
| MITRE ATT&CK | Technique taxonomy for all chokepoint mappings |
| Sigma Specification | Rule format across all detection levels |
| Kitsune | AI-driven threat intelligence pipeline used to extract and correlate procedure-level data |
| ORKL | Open Repository of Knowledge on Libraries, source corpus for attack chain analysis |
| Kaspersky: Common TTPs of Modern Ransomware (2022) | Empirical foundation for the chokepoint approach |
| Mandiant M-Trends | Source for TTR compression data |
| Red Canary: The Why, What, and How of Threat Research | Matt Graeber's research methodology that this framework adapts |
| MHaggis ClickGrab | Live ClickFix crawl data feeding the trends analysis |
| Defused Cyber | Honeypot telemetry feeding the edge-exploit trends analysis |
| Huntress: Don't Sweat the ClickFix Techniques | In-the-wild ClickFix variant breakdown |
Detection is a game of economics. Make it expensive for attackers to avoid your detections.
