ATK Research · updated 9 September 2026

A check that never ran is not a check that found nothing.

This page carries a per-technique evidence record across 84 MITRE ATT&CK techniques in a working detection library. It was published this morning with two columns; it is republished now with a different structure, because a public exchange changed what the right structure is. The change is described below rather than quietly applied.

3
checked and observed
22
not tested
59
not observable with this sensor set
0
back-filled records

What an evidence reference is, and whose idea it is

The framing here is Reza Adineh's, author of TID-CMM. His position, posted publicly: an evidence reference is an audit record, not a detection artefact — it can exist even when no detection artefact was produced. For a completed check the record has to state five things: what ran, whether execution succeeded, what evidence was expected, where it looked and in which time window, and what was observed. And three states must stay distinguishable rather than collapse into one: checked and not observed, not tested, and execution inconclusive.

We could not fit our own numbers into those three states, and said so in public. Of the 84, sixty-odd are not checked and not observed, because no check ran at all — the bench holds no sensor carrying that class of evidence. Calling them not tested would be wrong in a specific and misleading way: not tested reads as something the assessor fixes by testing more. This is not that.

So we proposed a fourth state: not observable with this sensor set. It is a property of the measuring infrastructure rather than of the technique, and it is frequently the finding itself. Filling in "what ran, where, and in which window" would be truthful for the rows where something ran and fabrication for the rows where nothing did. Add a state; do not back-fill.

The boundary applies to the positive column too

Everything here holds within the assessed configuration and tested conditions — and that qualifier binds the three observed rows exactly as hard as it binds the rest. A rule that fired on this bench is evidence about this bench. It is not a claim that the same technique is caught in an estate we have not measured.

The before-state, as a dated record rather than a memory

An earlier version of this page reported 66 techniques as unobservable. That version is a report, not a configuration record, and it should not be treated as one. What follows is the closest thing to a dated configuration artefact we actually hold, with its source and its limits.

Created (UTC)ComponentImage
2026-06-24 16:28lab-victimvcyber-lab-victim (Ubuntu 22.04, Wazuh agent)
2026-09-05 04:41wazuh managerwazuh/wazuh-manager:4.14.7
2026-09-05 04:43wazuh agentwazuh/wazuh-agent:4.14.7
2026-09-09 02:54zeek-sensor agent addedwazuh/wazuh-agent:4.14.7
2026-09-09 03:55Zeek added (current container, -C)zeek/zeek:latest

Source. Container creation timestamps from the container runtime's own metadata. It is a machine record, not a reconstruction, and anyone with access to the host can reproduce it.

Limits, and they are real. Three of them. Creation time is not the same as the time a sensor began producing usable data — an earlier Zeek container existed roughly an hour before the one listed and was discarding packets on checksum offload, so it wrote connection records while every protocol analyser stayed silent. The record shows which components exist, not the configuration they ran with. And it can only speak for what runs in containers on this host; it cannot prove the absence of a sensor somewhere else.

The blind hour is unestablished, and this page now says so rather than asserting it. The sentence above states that an earlier Zeek container wrote connection records while every protocol analyser stayed silent. On 10 September 2026 we went to re-derive that from the bench and could not. The container was discarded, and the log volume now holds nothing earlier than conn.2026-09-09-03-56-05.log, which belongs to the replacement. The pin is still checkable: container creation timestamps come from the runtime and anyone with host access can read them. The scope is not: the artefact that would show the blindness no longer exists, so neither we nor a reader can recompute it.

We are keeping the sentence and labelling it rather than deleting it, because deleting it would remove the reason seven rows moved while leaving the movement. What it is now is a stated recollection with a stated reason it cannot be checked, which is a weaker thing than a measurement and should be read as one. Any figure on this page carrying our name is recomputable from data we ship. That sentence is not a figure, and it is not recomputable, and both facts belong next to it.

What it does establish. That no network sensor existed on this bench before 2026-09-09 02:54 UTC. That is the claim the seven-row change rests on, and it is the only claim we make from this table.

Seven rows moved. Seven detections did not happen. The change is in what the sensor set can reach, not in what was demonstrated. Only three techniques have an evidence record on this page, and only those three were observed. The other four moved from not observable with this sensor set to not tested — a different kind of unknown, not a result.

What changed since this morning, and why

The first version of this page reported 66 techniques as unknown. Since then we stood up a network sensor on the lab bridge — Zeek, feeding a Wazuh agent — and wrote detection rules against it. That moved seven techniques out of the unobservable column — into not tested, not into observed — and produced the first three evidence records on this page.

The sensor did not work on the first attempt, and the reason is worth stating: Zeek was discarding packets on checksum offload, so conn.log filled normally while every protocol analyser stayed silent. A sensor that is running, writing logs and reporting no errors can still be blind to every protocol on the wire. It took the -C flag and a measurement of the data side to tell the two apart.

Current sensor inventory: one Ubuntu host with a Wazuh agent (auth, process) and a Zeek instance on the lab bridge (conn, ssl, http). No Sysmon. No commercial EDR. No DNS — container queries resolve against the Docker internal resolver and never cross the bridge. No cloud, no Kubernetes, no OT.

The full list

84 rows. Technique links go to attack.mitre.org. Sigma column shows the first two rule names the library attaches, where it attaches any.

TechniqueData sources declaredEvidence stateEvidence record (completed checks only)
T0831historian, ics_protocolnot observable with this sensor set—
T0836historiannot observable with this sensor set—
T0843otnot observable with this sensor set—
T1003.001edr, sysmonnot observable with this sensor set—
T1003.003sysmonnot observable with this sensor set—
T1003.006authnot tested—
T1018process, sysmonnot tested—
T1021.001authnot tested—
T1021.002auth, sysmonnot tested—
T1027sysmonnot observable with this sensor set—
T1041networknot tested—
T1046auth, networknot tested—
T1047sysmonnot observable with this sensor set—
T1048.003dnsnot observable with this sensor set—
T1053.005sysmonnot observable with this sensor set—
T1055.001sysmonnot observable with this sensor set—
T1056.001edrnot observable with this sensor set—
T1059.001sysmonnot observable with this sensor set—
T1059.004edrnot observable with this sensor set—
T1059.005sysmonnot observable with this sensor set—
T1068sysmonnot observable with this sensor set—
T1069.002sysmonnot observable with this sensor set—
T1070.001sysmonnot observable with this sensor set—
T1071.001networknot tested—
T1071.004dnsnot observable with this sensor set—
T1074.001[0 KHAI], sysmonnot observable with this sensor set—
T1078authnot tested—
T1078.004azuread, cloud_audit, cloudtrailnot observable with this sensor set—
T1087.002sysmonnot observable with this sensor set—
T1090sysmonnot observable with this sensor set—
T1098cloudtrailnot observable with this sensor set—
T1098.001azuread, cloud_auditnot observable with this sensor set—
T1098.005cloud_auditnot observable with this sensor set—
T1105networkchecked and observedran: Wazuh rule 100204 on Zeek conn.log · completed: yes · expected: an inbound transfer of 1 MB or more in one session · where/when: same sensor and window · observed: 1 alert. resp_ip_bytes = 6,302,226 from 172.22.0.4:8080
T1110.001active-response, authnot tested—
T1110.003authnot tested—
T1114.002cloud_audit, m365not observable with this sensor set—
T1133authnot tested—
T1134.001sysmonnot observable with this sensor set—
T1190networkchecked and observedran: Wazuh rule 100202 on Zeek conn.log · completed: yes · expected: failed connection states against web ports · where/when: same sensor and window · observed: 1 alert on a rejected connection to a web port
T1204.002[0 KHAI], mailnot observable with this sensor set—
T1207authnot tested—
T1213cloud_auditnot observable with this sensor set—
T1219sysmonnot observable with this sensor set—
T1482sysmonnot observable with this sensor set—
T1484.001authnot tested—
T1485sysmonnot observable with this sensor set—
T1486edrnot observable with this sensor set—
T1489sysmonnot observable with this sensor set—
T1490sysmonnot observable with this sensor set—
T1491.001sysmonnot observable with this sensor set—
T1496networkchecked and observedran: Wazuh rule 100201 on Zeek conn.log · completed: yes · expected: a connection record to a known stratum mining port · where/when: Zeek sensor on the lab bridge br-28b08d506cb4, 2026-09-09 03:1x–03:2x UTC · observed: 3 alerts. 172.22.0.2:54700 → 172.22.0.4:3333, tcp, conn_state RSTRH
T1505.003edr, sysmonnot observable with this sensor set—
T1528azuread, cloud_auditnot observable with this sensor set—
T1529sysmonnot observable with this sensor set—
T1530cloud_audit, cloudtrailnot observable with this sensor set—
T1539cloud_auditnot observable with this sensor set—
T1543.003sysmonnot observable with this sensor set—
T1546.003sysmonnot observable with this sensor set—
T1547.001sysmonnot observable with this sensor set—
T1548.002sysmonnot observable with this sensor set—
T1550.002authnot tested—
T1550.003authnot tested—
T1552.004processnot tested—
T1558.001authnot tested—
T1558.003authnot tested—
T1558.004authnot tested—
T1560.001sysmonnot observable with this sensor set—
T1561.002sysmonnot observable with this sensor set—
T1562.001sysmonnot observable with this sensor set—
T1564.008m365not observable with this sensor set—
T1565.001sysmonnot observable with this sensor set—
T1566.001mailnot observable with this sensor set—
T1566.002m365, proxynot observable with this sensor set—
T1567.002cloudtrail, networknot tested—
T1570sysmonnot observable with this sensor set—
T1573.002networknot tested—
T1574.009sysmonnot observable with this sensor set—
T1606.002authnot tested—
T1610kubernetesnot observable with this sensor set—
T1611falconot observable with this sensor set—
T1613kubernetesnot observable with this sensor set—
T1621cloud_auditnot observable with this sensor set—
T1648cloud_auditnot observable with this sensor set—

Raw data

Published rather than available on request, so every number above is recomputable:

ATK New Technology · Hanoi, Vietnam · Dong Nguyen · dongnx@atkvn.com

Related, same terms: Detection Reality Index Vol.1 · Vol.2 (IBM QRadar) · Vol.3 · Crypto Reality Index Vol.1 · IETF PQ authentication position paper · atkvn.com