hogfly Profile picture
Apr 11, 2019 11 tweets 2 min read
Has hunting now become synonymous with detection engineering? It was always a part of the process, but with everyone glomming on to ATT&CK, has the adversary been buried under a distilled set of behaviors that you build detection for? I firmly believe that for the purposes of detection, almost all actors can be distilled to a set of behaviors, but how much is being overlooked?