Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

MITRE ATT&CK v18 and analytics-driven detections: what changes now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: MITRE ATT&CK v18 replaces technique-level Data Sources with Detection Strategies and Analytics, retiring the older detection model and pushing defenders toward behavior-driven telemetry mapping, according to Cymulate. The change makes detection engineering more precise, but it also raises the bar for validation, correlation, and continuous testing across SOC workflows.

NHIMG editorial — based on content published by Cymulate: MITRE ATT&CK v18: New Detection Strategies and Analytics Redefine Cyber Defense

Questions worth separating out

Q: How should SOC teams implement analytics-driven detections for identity abuse?

A: Start by mapping the behaviours you care about, such as credential access, registry queries, and suspicious process creation, to the telemetry that can actually reveal them.

Q: Why do non-human identities make detection engineering harder?

A: Because NHIs often produce legitimate-looking activity at machine speed, the same access path can support administration, automation, or attacker persistence.

Q: What breaks when detections are built only around data sources?

A: Teams end up with coverage that looks complete on paper but fails to explain attacker behaviour in practice.

Practitioner guidance

  • Remap detections to adversary behaviours Rebuild detection content around technique-level behaviours, with each rule tied to a specific strategy and analytic rather than a generic log source.
  • Validate identity abuse scenarios continuously Run simulations that exercise registry queries, suspicious process creation, and other identity-sensitive behaviours so teams can see whether detections actually fire.
  • Review detection coverage for non-human identities Check whether service accounts, tokens, and other NHIs are being monitored through behaviour, not just inventory.

What's in the full article

Cymulate's full article covers the operational detail this post intentionally leaves for the source:

  • Step-by-step examples of how ATT&CK v18 maps technique, strategy, analytic, and data component in the new model.
  • The specific SIGMA and EDR rule outputs the platform generates when tests fail or miss activity.
  • How Cymulate validates detections across more than 90,000 attack simulation tests for missed techniques.
  • The roadmap implications of splitting Defense Evasion and recategorising techniques in future ATT&CK releases.

👉 Read Cymulate's analysis of MITRE ATT&CK v18 detection strategies and analytics →

MITRE ATT&CK v18 and analytics-driven detections: what changes now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Behavior-based detection is now the minimum credible model for modern adversary visibility. Static data-source mapping was always too brittle for attacker tradecraft that blends process activity, registry access, and identity abuse. ATT&CK v18 formalises the reality that defenders need strategy and analytics, not just source lists, if they want detections to reflect how adversaries actually operate. For practitioners, the implication is straightforward: detection engineering must be behaviour-first, or it will lag the threat.

A question worth separating out:

Q: How do you know if ATT&CK-aligned detections are actually working?

A: You know they are working when they are validated against realistic attack paths and produce repeatable results across the techniques you care about. Look for confirmed detections, clear analytic logic, and correlation across stages rather than one-off alerts. If the team cannot show evidence under simulation, the control is not yet dependable.

👉 Read our full editorial: MITRE ATT&CK v18 shifts detection engineering toward analytics



   
ReplyQuote
Share: