Level 4: Low-Variance Behaviors / Core Sometimes¶
Description: Observables associated with low-variance behaviors that are core to some implementations of a technique or sub-technique and are unavoidable without using a substantially different implementation.
Level 4 observables represent behaviors that recur across multiple ways of performing a technique. They are not necessarily required by every implementation, but when an adversary chooses an implementation that relies on the behavior, the observable is difficult to avoid without changing the implementation strategy. Identifying these low-variance behaviors can provide robust detection opportunities across multiple implementations of a technique.
Why are these observables placed at Level 4?¶
An adversary may be able to evade a Level 4 observable by choosing a different implementation of the technique. However, doing so requires more than reconfiguring a tool or changing an incidental value. The adversary must instead change the implementation strategy used to accomplish the behavior. Level 4 therefore represents observables that are core to some implementations of a technique or sub-technique, while Level 5 observables represent behaviors that are invariant across all known implementations.
Observables¶
The examples below illustrate low-variance behaviors that are core to some implementations.
Technique / Sub-Technique |
Observable |
Low-Variance Behavior |
|---|---|---|
Modify Authentication Process (T1556) |
|
|
OS Credential Dumping: LSASS Memory (T1003.001) |
|
Access to |
Scheduled Task/Job: At (T1053.002) - Remote |
Event 5145: |
Remote use of the Windows At Service through the |
Modify Registry (T1112) - Remote |
Event 5145: |
Remote Registry access through the |