











This article is part of an ongoing series from Sophos frontline security operations specialists, sharing the expertise they use to strengthen our industry-leading Managed Detection and Response (MDR) service and defend customers against evolving AI Era threats.
If you’ve opened the Enterprise ATT&CK matrix recently, you may have done a double-take. The familiar Defense Evasion column is gone. In its place sit two tactics: Stealth (TA0005) and Defense Impairment (TA0112). The Enterprise model now spans 15 tactics rather than 14.
It’s a taxonomy change that makes sense, but it could disrupt your detection engineering, playbooks, and the way you narrate an intrusion in a report. Any content mapped to the old Defense Evasion tactic now belongs to one of two phases with different intent and, crucially for responders, different forensic footprints.
The change makes sense in light of current trends. Adversaries have leaned harder into both tactics over the last few cycles: living-off-the-land to stay quiet, then aggressively disabling telemetry the moment they need room to operate. A framework that treats those as one tactic makes it easy to under-invest in one while over-reporting the other. The split forces an honest audit of both.
Below, I'll show how the new categories improve clarity and offer a phase-by-phase field guide, with artifacts and tooling that you can use to align with the new tactics this week.
Defense Evasion bundled two very different adversary goals: staying hidden and actively breaking the things that would otherwise catch them. Separating them sharpens both detection and response:
When you’re being attacked at 2 a.m., “They hid” and “they blinded us” is an important distinction that leads to different collection priorities, different timelines, and different conversations with the customer.
The host is only half the picture. Modern intrusions increasingly hide inside identity and SaaS using stolen session tokens, OAuth consent grants, and sign-ins that look perfectly legitimate. In that environment, stealth looks like a valid token with broad access. Defense Impairment looks like someone disabling conditional access or muting an alerting policy. There’s usually no timestomping or event log clearing. For DFIR, the key questions will always be: what did they leave behind, and how do I pull it apart? But in modern environments, the artifacts move to sign-in logs, unified audit trails, and provider telemetry, and your tooling needs to shift accordingly.
Rather than asking you to re-learn the revised Enterprise matrix, I mapped it to how responders actually work. For each of the 15 tactics, the reference below answers two questions: what did they leave behind, and how do I pull it apart? The reference provides a condensed artifact-and-tooling view (tooling listed alphabetically). The full technique sheet extends this to 43 techniques with data sources and detection analytics.
Download the field guide spreadsheet here.
| Tactic / Phase | Forensic Artifacts & Evidence | DFIR Tooling & Approach (A–Z) |
|---|---|---|
| Reconnaissance | Perimeter/WAF & DNS logs, netflow, scan traffic | Suricata, Velociraptor, Zeek |
| Resource Development | Domain regs, TLS certs, staged tooling | MISP, passive DNS, VirusTotal |
| Initial Access | Security.evtx 4624/4625, M365 sign-in, web shells, .eml | EvtxECmd, KAPE, M365 BEC toolkit |
| Execution | Prefetch, Amcache, Shimcache, PS logs, 4688 | AmcacheParser, EvtxECmd, PECmd |
| Persistence | Run keys, Services, Tasks, WMI subs, 7045 | Autoruns, RECmd, RegRipper, SBECmd |
| Privilege Escalation | SAM/SYSTEM hives, LSASS, token abuse, BYOVD | driver analysis, RegRipper, Volatility 3 |
| Stealth | Timestomp $MFT, ADS, masquerading, USN gaps | MFTECmd, Sigma, USN parser, YARA |
| Defense Impairment | Log clear 1102, AV tamper, firewall mods | Defender log review, EvtxECmd, RECmd |
| Credential Access | LSASS, NTDS.dit, Wdigest, browser creds, 4648 | Hindsight, ProcDump, Volatility 3 |
| Discovery | Cmd history, enum logs, SRUM, UserAssist | EvtxECmd, KAPE triage, SrumECmd |
| Lateral Movement | RDP cache, 4624 T3/T10, PsExec/WinRM, jump-lists | CyLR, EvtxECmd, KAPE, Velociraptor |
| Collection | Staged archives, Recent, clipboard, shellbags | KAPE, RECmd, SBECmd |
| Command & Control | Beaconing, DNS-tunnel, HTTP implant, RMM traces | LOLRMM.io, RITA, Suricata, Zeek |
| Exfiltration | Large egress, cloud history, USB (setupapi) | browser forensics, DLP logs, Netflow |
| Impact | Mass ext changes, ransom notes, VSS delete | MFTECmd/USN, Volatility 3, VSS analysis |
Cross-cutting platforms operate across every phase: KAPE and Velociraptor for triage and collection, Plaso for super-timelines, and Sigma, YARA, and ATT&CK Navigator for detection and coverage mapping.
This mapping is built from real Sophos Incident Response engagements. Across those engagements, the same pattern keeps showing up: the artifact was there before the alert was.
That's what an artifact-first posture buys you. An alert tells you something happened. The artifacts tell you what happened, when, how far it spread, and whether you've scoped it. So treat the tactic split as a prompt to check your collection: can you evidence both the hiding and the blinding behaviors, given that attackers do both?
A field guide is only as good as the caseload behind it. The Sophos Incident Response practice runs thousands of engagements every year, across every sector and region. The team is drawn from national, military, and organizational CSIRTs, law enforcement, and intelligence backgrounds, backed by the threat intelligence of Sophos X-Ops. That real-world experience and volume is how we know that patterns like “artifact-first” hold up. It’s also why our median attacker dwell time in real cases now sits at just three days. The response speed and pattern-recognition compound.
The full 15-tactic matrix and the filterable technique sheet are attached. The teams that adapt their evidence strategy and not just their labels will be the ones who scope faster and eradicate cleaner.
The full 15-tactic matrix and the filterable technique sheet are available here for download. The teams that adapt their evidence strategy and not just their labels will be the ones who scope faster and eradicate cleaner.
_____
Sophos DFIR is a 24/7 service for Sophos and non-Sophos customers alike. Request emergency assistance at sophos.com/emergency-response. Onboarding starts within hours, and most customers are triaged within 48 hours.
The Sophos Security Services Retainer (SSR) converges proactive testing, readiness, and guaranteed DFIR into one model that includes defined response SLAs, pre-negotiated rates, and Service Units for pen-testing, tabletop exercises, and more. sophos.com/retainer
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。