Yes, when the threat model includes cheap model-assisted iteration. Blocking known bad still matters, but it is no longer enough on its own because the attacker can cheaply change tactics. Behavioural detection gives defenders a better chance of catching intent before identity abuse turns into exfiltration or persistence.
Why behavioural detection deserves priority when attackers can iterate cheaply
Behavioural detection becomes more valuable when the adversary can quickly rotate infrastructure, payloads, domains, hashes, prompts, or other static indicators. Known-bad blocking still removes repeatable infrastructure, but it is structurally behind the attacker’s ability to reissue the campaign. Detection that looks at sequence, intent, privilege use, and abnormal interaction patterns is harder to evade because it targets the abuse pattern, not just the current artifact.
A practical way to think about the trade-off is that indicator blocking is best at compressing noise from previously seen threats, while behavioural detection is better at surfacing first-time or slightly modified abuse. In environments with heavy automation, that distinction matters because the attacker can change the outer shape of the event faster than defenders can curate lists. MITRE D3FEND is useful here because it frames defence in terms of countermeasures against adversary behaviour, not just signature matching.
That does not make blocking obsolete. Known-bad controls still reduce exposed surface area, stop commodity reuse, and give defenders a fast rejection layer for high-confidence indicators. The point is that blocking should be treated as a containment layer, not the main decision engine, because static lists degrade quickly when an attacker can cheaply vary the campaign.
What changes in the defender’s signal when tactics are mutable
When tactics are mutable, the defender should expect the same intent to appear through different infrastructure and different execution details. A campaign may keep the same objective, such as credential theft or persistence, while swapping delivery paths, user-agent strings, network destinations, or abuse patterns. Behavioural detection helps correlate those changes into one malicious pattern even when the raw indicators are novel.
This is especially important for identity abuse. If the attacker can retool the delivery but still needs to authenticate, move laterally, or trigger unusual privileged actions, behavioural telemetry can reveal the compromise earlier than a blocklist ever will. Detection logic should therefore pay attention to sequences such as impossible timing, abnormal tool use, unusual privilege escalation, and out-of-profile access paths rather than relying only on known malicious markers. SANS Security Resources is a good practical reference point for teams building detection engineering and incident handling around those kinds of behavioural cues.
Known-bad indicators still have a role in prevention and triage, but they are brittle when the attacker controls variation. Behavioural approaches are more resilient because they force the attacker to change the underlying operation, not merely the visible wrapper.
How to decide where the line belongs in practice
The right answer is usually not “behavioural only” or “blocking only.” The stronger model is layered: use blocking for commodity suppression and rapid rejection, then use behavioural detection for adaptive adversaries, insider-like misuse, and multi-stage intrusion paths. That combination gives you a faster first line and a better chance of seeing the campaign after the first mutation.
Teams should also separate what is cheap to block from what is expensive to reason about. Simple commodity artifacts belong in blocklists and allowlists; low-frequency but high-impact actions, such as abnormal authentication chains or privilege use, belong in behavioural rules, correlation, and investigation workflows. If the control can be bypassed by changing a hash or domain name, it is not a sufficient primary defence against a learning adversary.
Practitioner takeaway: Use known-bad blocking to reduce noise and stop repeatable commodity abuse, but put your primary detection investment into behaviours that survive attacker iteration and reveal intent before the intrusion matures.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1021 — Remote Services | Behavioural detection often spots lateral movement that follows initial access. |
| T1078 — Valid Accounts | The question centers on identity abuse that static indicators often miss. | |
| Recommendation — Correlate remote-access abuse and lateral movement patterns to detect post-compromise activity. Hunt for valid-account misuse rather than relying only on blocked indicators. | ||
| CIS Controls v8 | CIS-8 — Audit Log Management | Behavioural detection depends on telemetry and correlation across events. |
| Recommendation — Centralize and review logs so behaviour-based detections can surface anomalous activity. | ||
| NIST CSF 2.0 | DE.CM-01 — Networks and network services are monitored to find potential cybersecurity events | The answer prioritises detecting adversary behaviour rather than only blocking indicators. |
| PR.AA-04 — Identity assertions are validated | Behavioural detection is especially important when attackers abuse authentication and identity flows. | |
| Recommendation — Monitor network activity for suspicious patterns that indicate active compromise. Validate identity assertions and flag anomalous authentication behaviour. | ||
Related resources from NHI Mgmt Group
- Should organisations prioritise token rotation or behavioural detection first?
- When should organisations prioritise credential rotation over more detection rules?
- When should organisations prioritise AI security posture management over broader detection tuning?
- When should organisations prioritise remediation of known exploited vulnerabilities over routine patch work?