Detection logic is mapped to the MITRE ATT&CK framework, so coverage is described in the same terms security teams already use for threat hunting, incident response, and tracking adversary behavior — including techniques such as:
Detect suspicious manipulation of legitimate processes and identify behaviors that may indicate code injection or evasion.
ATT&CK T1055.012Identify suspicious DLL execution patterns that may indicate malicious payload execution.
ATT&CK T1218.011Distinguish legitimate administrative behavior from credential misuse and privilege escalation — the way most attackers actually get in — including potential insider threat indicators.
ATT&CK T1078Extend detection coverage using custom YARA rules designed around evolving malicious artifacts and behaviors.
ATT&CK-mapped, ongoing