Changelog¶
Version History¶
- Refactored the Summiting website to align to overall CTID Detection Engineering work and make it easier to navigate
- Added in Telemetry Strategy & Readiness content that describes how to identify minimum telemetry requirements for a given ambiguous technique
- Added description of the Telemetry Confidence (TC) scoring methodology with examples, extensions to use cases and results from 10 use cases related to ambiguous behaviors, and shared our methodology for automating the process using AI/LLM augmentation
This release includes our "Ambiguous Techniques" research, which defines what makes a technique ambiguous, identifies examples of ambiguous techniques in MITRE ATT&CK, and contributes new best practices for building robust detections for ambiguous techniques.
This major update defines "robustness" in the context of detection engineering, how to quantify robustness and how to improve it in your existing detections. This release also adds new elements to the STP model for scoring network detections.
The initial release of Summiting the pyramid includes the model, methodology, definitions, and worked examples.