Skip to main content

Detection ATT&CK coverage

Generated by tools/scripts/detection/attack_coverage.py (ADR 040). Do not edit by hand; run the generator to refresh.

  • Rules: 21
  • Techniques covered: 25
ATT&CK techniqueRules
T1003.008/etc/shadow read by non-root or unusual process
T1021.004SSH process with batch-mode flags (lateral movement)
T1027Inline base64 decode piped to shell
T1036.005Masquerading system process executing from a temp path
T1048Data exfiltration via curl upload to external host
T1053.003Cron persistence via /etc/cron.d or user crontab write
T1059.001PowerShell encoded command on Linux
T1059.004Inline base64 decode piped to shell; Reverse shell via bash /dev/tcp; Suspicious curl-piped-to-shell execution
T1070.003Shell history tampering and anti-forensics
T1071.004DNS query with long subdomain (probable exfiltration)
T1083Path traversal / local file inclusion in HTTP request
T1098Local account creation or privileged group manipulation
T1105Suspicious curl-piped-to-shell execution
T1136.001Local account creation or privileged group manipulation
T1190Log4Shell JNDI probe in HTTP request; Path traversal / local file inclusion in HTTP request; SQL injection pattern in HTTP request
T1204.002Suspicious curl-piped-to-shell execution
T1486Mass file rename to ransomware extension
T1547.006systemd unit drop-in for persistence
T1548.003Sudoers privilege escalation via sudoers file write
T1562.001Disable Linux security tooling
T1562.003Shell history tampering and anti-forensics
T1567.002Data exfiltration via curl upload to external host
T1571Reverse shell via bash /dev/tcp
T1574.006Dynamic linker hijack via LD_PRELOAD
T1611Container escape via nsenter into host namespaces