Browser LabLD-SOC2-LAB-007Hard
Browser LabLD-SOC2-LAB-007Hard22 min
Engineer a Detection From a Confirmed TTP
Threat intelligence handed you a confirmed TTP: an Office application spawning an encoded PowerShell child. A junior analyst drafted a rule that alerts on all PowerShell. You have the TTP, the draft rule, a real attack event and a sample of benign activity. Turn the draft into a detection you can trust.
What you will be able to do
- Target the behaviour, not the indicator, for durability.
- Tune precision with the distinguishing field and an allowlist.
- Test against benign data and plan for decay.
Detection EngineeringSIEM OperationT1059.001 — Command and Scripting Interpreter: PowerShellT1566.001 — Phishing: Spearphishing Attachment
Sign in to start this lab.
Sign in