Center for Threat-Informed Defense

Version 18.0 19.0

Detection Strategies : Enterprise ATT&CK Changelog

Added Detection Strategies

New Analytics:

  • AN2036: Analytic 2036
  • AN2034: Analytic 2034
  • AN2033: Analytic 2033
  • AN2037: Analytic 2037
  • AN2035: Analytic 2035

New Analytics:

  • AN2038: Analytic 2038
  • AN2042: Analytic 2042
  • AN2040: Analytic 2040
  • AN2041: Analytic 2041
  • AN2039: Analytic 2039

New Analytics:

  • AN2043: Analytic 2043

New Analytics:

  • AN2059: Analytic 2059

New Analytics:

  • AN2060: Analytic 2060

New Analytics:

  • AN2061: Analytic 2061

New Analytics:

  • AN2062: Analytic 2062

New Analytics:

  • AN2063: Analytic 2063
  • AN2064: Analytic 2064
  • AN2065: Analytic 2065

Modified Detection Strategies

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
spec_version 2.1
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-04-24T20:25:52.122Z
name Detection Strategy for Disable or Modify Linux Audit System Detection Strategy for Disable or Modify Linux Audit System Log

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
spec_version 2.1
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-04-24T20:24:45.876Z
name Detect disabled Windows event logging Detect Disabled Windows Event Log

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
spec_version 2.1
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-04-24T20:25:34.812Z
name Detection Strategy for Disable or Modify Cloud Logs Detection Strategy for Disable or Modify Cloud Log

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
spec_version 2.1
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-04-24T20:26:54.885Z
name Unauthorized Network Firewall Rule Modification (T1562.013) Detection of Unauthorized Network Firewall Rule Modification

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
spec_version 2.1
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-04-24T20:26:14.331Z
name Detection for Spoofing Security Alerting across OS Platforms Detection for Spoofing Tool UI across OS Platforms

New Analytics:

  • AN2044: Analytic 2044
Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
spec_version 2.1
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-04-24T20:24:31.994Z
name Detection of Impair Defenses through Disabled or Modified Tools across OS Platforms. Detection of Defense Impairment through Disabled or Modified Tools across OS Platforms.
x_mitre_version 1.0 1.1
Iterable Item Added
FIELD OLD VALUE NEW VALUE
x_mitre_analytic_refs x-mitre-analytic--2b990a38-dedf-4a9a-9bd2-9a805c2f1b46

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
spec_version 2.1
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-04-24T20:25:01.924Z
name Detection Strategy for Impair Defenses via Impair Command History Logging across OS platforms. Detection Strategy for Defense Impairment via Prevent Command History Logging across OS platforms.

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
spec_version 2.1
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-04-24T20:26:25.154Z
name Detection fo Remote Service Session Hijacking for RDP. Detection of Remote Service Session Hijacking for RDP.

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
spec_version 2.1
revoked False
Values Changed
FIELD OLD VALUE NEW VALUE
modified 2025-10-21T15:10:28.402Z 2026-04-24T20:26:05.352Z
name Detection Strategy for Exploitation for Defense Evasion Detection Strategy for Exploitation for Stealth

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
spec_version 2.1
Values Changed
FIELD OLD VALUE NEW VALUE
external_references[0]['url'] https://attack.mitre.org/detection-strategies/DET0897 https://attack.mitre.org/detectionstrategies/DET0897
modified 2025-10-23T20:53:44.184Z 2025-11-12T22:03:39.105Z

Details
Dictionary Item Added
FIELD OLD VALUE NEW VALUE
spec_version 2.1
Values Changed
FIELD OLD VALUE NEW VALUE
external_references[0]['url'] https://attack.mitre.org/detection-strategies/DET0898 https://attack.mitre.org/detectionstrategies/DET0898
modified 2025-10-23T19:55:18.990Z 2025-11-12T22:03:39.105Z