Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Browser LabLD-SOC2-LAB-007Hard
Browser LabLD-SOC2-LAB-007Hard22 min

Engineer a Detection From a Confirmed TTP

Threat intelligence handed you a confirmed TTP: an Office application spawning an encoded PowerShell child. A junior analyst drafted a rule that alerts on all PowerShell. You have the TTP, the draft rule, a real attack event and a sample of benign activity. Turn the draft into a detection you can trust.

What you will be able to do

  • Target the behaviour, not the indicator, for durability.
  • Tune precision with the distinguishing field and an allowlist.
  • Test against benign data and plan for decay.
Detection EngineeringSIEM OperationT1059.001Command and Scripting Interpreter: PowerShellT1566.001Phishing: Spearphishing Attachment

Sign in to start this lab.

Sign in