// mitre att&ck mapping

Coverage matrix

Every lab maps to a primary ATT&CK technique, the data sources it relies on, the tactic phase it interrupts, and an assessment of detection difficulty and signal value.

LabATT&CKTacticData SourcesDifficultySignal
Detecting PowerShell EncodedCommand Abuse
Phase 1
T1059.001ExecutionWindows Security, Sysmon, PowerShellEasyHigh
Detecting Invoke-Expression (IEX) Misuse
Phase 1
T1059.001ExecutionPowerShell, SysmonEasyHigh
Detecting DownloadString / Invoke-WebRequest Staging
Phase 1
T1059.001ExecutionPowerShell, SysmonEasyHigh
Detecting Hidden-Window PowerShell
Phase 1
T1059.001ExecutionSysmonEasyMedium
Detecting -ExecutionPolicy Bypass
Phase 1
T1059.001ExecutionSysmonEasyMedium
Detecting Office Applications Spawning PowerShell
Phase 1
T1059.001ExecutionSysmonEasyHigh
PowerShell + Outbound Network Correlation
Phase 2
T1059.001ExecutionSysmonModerateHigh
PowerShell + Persistence Indicator Correlation
Phase 2
T1059.001ExecutionSysmon, Windows SecurityModerateHigh
Suspicious Parent/Child Process Relationships
Phase 2
T1059.001ExecutionSysmonModerateMedium
Office → Script Interpreter Execution Chains
Phase 2
T1059.001ExecutionSysmonModerateHigh
Detecting AMSI Bypass Attempts
Phase 3
T1562.001Defense EvasionPowerShellAdvancedHigh
Detecting .NET Reflection Loading in PowerShell
Phase 3
T1620Defense EvasionPowerShellAdvancedHigh
Memory-Only PowerShell Execution
Phase 3
T1059.001ExecutionPowerShellAdvancedHigh
Obfuscation Scoring of PowerShell Script Blocks
Phase 3
T1027Defense EvasionPowerShellAdvancedMedium
Entropy Analysis on Decoded PowerShell Payloads
Phase 3
T1027Defense EvasionPowerShellAdvancedMedium
End-to-End ATT&CK Chain Correlation
Phase 3
TA0002+TA0005+TA0003MultiWazuhAdvancedHigh
Primary technique
T1059.001 — Command and Scripting Interpreter: PowerShell
Related techniques
T1027, T1562.001, T1620, T1547, T1053
Tactics interrupted
Execution, Defense Evasion, Persistence, Privilege Escalation