Version 18.0 19.0
Detection Strategies : Enterprise ATT&CK Changelog
Added Detection Strategies
New Analytics:
- AN2036: Analytic 2036
- AN2034: Analytic 2034
- AN2033: Analytic 2033
- AN2037: Analytic 2037
- AN2035: Analytic 2035
New Analytics:
- AN2038: Analytic 2038
- AN2042: Analytic 2042
- AN2040: Analytic 2040
- AN2041: Analytic 2041
- AN2039: Analytic 2039
New Analytics:
- AN2043: Analytic 2043
New Analytics:
- AN2059: Analytic 2059
New Analytics:
- AN2060: Analytic 2060
New Analytics:
- AN2061: Analytic 2061
New Analytics:
- AN2062: Analytic 2062
New Analytics:
- AN2063: Analytic 2063
- AN2064: Analytic 2064
- AN2065: Analytic 2065
Modified Detection Strategies
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| spec_version | 2.1 | |
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-04-24T20:25:52.122Z |
| name | Detection Strategy for Disable or Modify Linux Audit System | Detection Strategy for Disable or Modify Linux Audit System Log |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| spec_version | 2.1 | |
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-04-24T20:24:45.876Z |
| name | Detect disabled Windows event logging | Detect Disabled Windows Event Log |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| spec_version | 2.1 | |
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-04-24T20:25:34.812Z |
| name | Detection Strategy for Disable or Modify Cloud Logs | Detection Strategy for Disable or Modify Cloud Log |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| spec_version | 2.1 | |
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-04-24T20:26:54.885Z |
| name | Unauthorized Network Firewall Rule Modification (T1562.013) | Detection of Unauthorized Network Firewall Rule Modification |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| spec_version | 2.1 | |
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-04-24T20:26:14.331Z |
| name | Detection for Spoofing Security Alerting across OS Platforms | Detection for Spoofing Tool UI across OS Platforms |
New Analytics:
- AN2044: Analytic 2044
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| spec_version | 2.1 | |
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-04-24T20:24:31.994Z |
| name | Detection of Impair Defenses through Disabled or Modified Tools across OS Platforms. | Detection of Defense Impairment through Disabled or Modified Tools across OS Platforms. |
| x_mitre_version | 1.0 | 1.1 |
Iterable Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| x_mitre_analytic_refs | x-mitre-analytic--2b990a38-dedf-4a9a-9bd2-9a805c2f1b46 |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| spec_version | 2.1 | |
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-04-24T20:25:01.924Z |
| name | Detection Strategy for Impair Defenses via Impair Command History Logging across OS platforms. | Detection Strategy for Defense Impairment via Prevent Command History Logging across OS platforms. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| spec_version | 2.1 | |
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-04-24T20:26:25.154Z |
| name | Detection fo Remote Service Session Hijacking for RDP. | Detection of Remote Service Session Hijacking for RDP. |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| spec_version | 2.1 | |
| revoked | False |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| modified | 2025-10-21T15:10:28.402Z | 2026-04-24T20:26:05.352Z |
| name | Detection Strategy for Exploitation for Defense Evasion | Detection Strategy for Exploitation for Stealth |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| spec_version | 2.1 |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| external_references[0]['url'] | https://attack.mitre.org/detection-strategies/DET0897 | https://attack.mitre.org/detectionstrategies/DET0897 |
| modified | 2025-10-23T20:53:44.184Z | 2025-11-12T22:03:39.105Z |
Details
Dictionary Item Added
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| spec_version | 2.1 |
Values Changed
| FIELD | OLD VALUE | NEW VALUE |
|---|---|---|
| external_references[0]['url'] | https://attack.mitre.org/detection-strategies/DET0898 | https://attack.mitre.org/detectionstrategies/DET0898 |
| modified | 2025-10-23T19:55:18.990Z | 2025-11-12T22:03:39.105Z |