This page carries a per-technique evidence record across 84 MITRE ATT&CK techniques in a working detection library. It was published this morning with two columns; it is republished now with a different structure, because a public exchange changed what the right structure is. The change is described below rather than quietly applied.
The framing here is Reza Adineh's, author of TID-CMM. His position, posted publicly: an evidence reference is an audit record, not a detection artefact — it can exist even when no detection artefact was produced. For a completed check the record has to state five things: what ran, whether execution succeeded, what evidence was expected, where it looked and in which time window, and what was observed. And three states must stay distinguishable rather than collapse into one: checked and not observed, not tested, and execution inconclusive.
We could not fit our own numbers into those three states, and said so in public. Of the 84, sixty-odd are not checked and not observed, because no check ran at all — the bench holds no sensor carrying that class of evidence. Calling them not tested would be wrong in a specific and misleading way: not tested reads as something the assessor fixes by testing more. This is not that.
So we proposed a fourth state: not observable with this sensor set. It is a property of the measuring infrastructure rather than of the technique, and it is frequently the finding itself. Filling in "what ran, where, and in which window" would be truthful for the rows where something ran and fabrication for the rows where nothing did. Add a state; do not back-fill.
Everything here holds within the assessed configuration and tested conditions — and that qualifier binds the three observed rows exactly as hard as it binds the rest. A rule that fired on this bench is evidence about this bench. It is not a claim that the same technique is caught in an estate we have not measured.
An earlier version of this page reported 66 techniques as unobservable. That version is a report, not a configuration record, and it should not be treated as one. What follows is the closest thing to a dated configuration artefact we actually hold, with its source and its limits.
| Created (UTC) | Component | Image |
|---|---|---|
| 2026-06-24 16:28 | lab-victim | vcyber-lab-victim (Ubuntu 22.04, Wazuh agent) |
| 2026-09-05 04:41 | wazuh manager | wazuh/wazuh-manager:4.14.7 |
| 2026-09-05 04:43 | wazuh agent | wazuh/wazuh-agent:4.14.7 |
| 2026-09-09 02:54 | zeek-sensor agent added | wazuh/wazuh-agent:4.14.7 |
| 2026-09-09 03:55 | Zeek added (current container, -C) | zeek/zeek:latest |
Source. Container creation timestamps from the container runtime's own metadata. It is a machine record, not a reconstruction, and anyone with access to the host can reproduce it.
Limits, and they are real. Three of them. Creation time is not the same as the time a sensor began producing usable data — an earlier Zeek container existed roughly an hour before the one listed and was discarding packets on checksum offload, so it wrote connection records while every protocol analyser stayed silent. The record shows which components exist, not the configuration they ran with. And it can only speak for what runs in containers on this host; it cannot prove the absence of a sensor somewhere else.
The blind hour is unestablished, and this page now says so rather than asserting it.
The sentence above states that an earlier Zeek container wrote connection records while every
protocol analyser stayed silent. On 10 September 2026 we went to re-derive that from the bench and
could not. The container was discarded, and the log volume now holds nothing earlier than
conn.2026-09-09-03-56-05.log, which belongs to the replacement. The pin is still
checkable: container creation timestamps come from the runtime and anyone with host access can
read them. The scope is not: the artefact that would show the blindness no longer exists, so
neither we nor a reader can recompute it.
We are keeping the sentence and labelling it rather than deleting it, because deleting it would remove the reason seven rows moved while leaving the movement. What it is now is a stated recollection with a stated reason it cannot be checked, which is a weaker thing than a measurement and should be read as one. Any figure on this page carrying our name is recomputable from data we ship. That sentence is not a figure, and it is not recomputable, and both facts belong next to it.
What it does establish. That no network sensor existed on this bench before 2026-09-09 02:54 UTC. That is the claim the seven-row change rests on, and it is the only claim we make from this table.
Seven rows moved. Seven detections did not happen. The change is in what the sensor set can reach, not in what was demonstrated. Only three techniques have an evidence record on this page, and only those three were observed. The other four moved from not observable with this sensor set to not tested — a different kind of unknown, not a result.
The first version of this page reported 66 techniques as unknown. Since then we stood up a network sensor on the lab bridge — Zeek, feeding a Wazuh agent — and wrote detection rules against it. That moved seven techniques out of the unobservable column — into not tested, not into observed — and produced the first three evidence records on this page.
The sensor did not work on the first attempt, and the reason is worth stating: Zeek was discarding
packets on checksum offload, so conn.log filled normally while every protocol analyser
stayed silent. A sensor that is running, writing logs and reporting no errors can still be blind to
every protocol on the wire. It took the -C flag and a measurement of the data side to
tell the two apart.
Current sensor inventory: one Ubuntu host with a Wazuh agent (auth, process) and a Zeek instance on the lab bridge (conn, ssl, http). No Sysmon. No commercial EDR. No DNS — container queries resolve against the Docker internal resolver and never cross the bridge. No cloud, no Kubernetes, no OT.
84 rows. Technique links go to attack.mitre.org. Sigma column shows the first two rule names the library attaches, where it attaches any.
| Technique | Data sources declared | Evidence state | Evidence record (completed checks only) |
|---|---|---|---|
| T0831 | historian, ics_protocol | not observable with this sensor set | — |
| T0836 | historian | not observable with this sensor set | — |
| T0843 | ot | not observable with this sensor set | — |
| T1003.001 | edr, sysmon | not observable with this sensor set | — |
| T1003.003 | sysmon | not observable with this sensor set | — |
| T1003.006 | auth | not tested | — |
| T1018 | process, sysmon | not tested | — |
| T1021.001 | auth | not tested | — |
| T1021.002 | auth, sysmon | not tested | — |
| T1027 | sysmon | not observable with this sensor set | — |
| T1041 | network | not tested | — |
| T1046 | auth, network | not tested | — |
| T1047 | sysmon | not observable with this sensor set | — |
| T1048.003 | dns | not observable with this sensor set | — |
| T1053.005 | sysmon | not observable with this sensor set | — |
| T1055.001 | sysmon | not observable with this sensor set | — |
| T1056.001 | edr | not observable with this sensor set | — |
| T1059.001 | sysmon | not observable with this sensor set | — |
| T1059.004 | edr | not observable with this sensor set | — |
| T1059.005 | sysmon | not observable with this sensor set | — |
| T1068 | sysmon | not observable with this sensor set | — |
| T1069.002 | sysmon | not observable with this sensor set | — |
| T1070.001 | sysmon | not observable with this sensor set | — |
| T1071.001 | network | not tested | — |
| T1071.004 | dns | not observable with this sensor set | — |
| T1074.001 | [0 KHAI], sysmon | not observable with this sensor set | — |
| T1078 | auth | not tested | — |
| T1078.004 | azuread, cloud_audit, cloudtrail | not observable with this sensor set | — |
| T1087.002 | sysmon | not observable with this sensor set | — |
| T1090 | sysmon | not observable with this sensor set | — |
| T1098 | cloudtrail | not observable with this sensor set | — |
| T1098.001 | azuread, cloud_audit | not observable with this sensor set | — |
| T1098.005 | cloud_audit | not observable with this sensor set | — |
| T1105 | network | checked and observed | ran: Wazuh rule 100204 on Zeek conn.log · completed: yes · expected: an inbound transfer of 1 MB or more in one session · where/when: same sensor and window · observed: 1 alert. resp_ip_bytes = 6,302,226 from 172.22.0.4:8080 |
| T1110.001 | active-response, auth | not tested | — |
| T1110.003 | auth | not tested | — |
| T1114.002 | cloud_audit, m365 | not observable with this sensor set | — |
| T1133 | auth | not tested | — |
| T1134.001 | sysmon | not observable with this sensor set | — |
| T1190 | network | checked and observed | ran: Wazuh rule 100202 on Zeek conn.log · completed: yes · expected: failed connection states against web ports · where/when: same sensor and window · observed: 1 alert on a rejected connection to a web port |
| T1204.002 | [0 KHAI], mail | not observable with this sensor set | — |
| T1207 | auth | not tested | — |
| T1213 | cloud_audit | not observable with this sensor set | — |
| T1219 | sysmon | not observable with this sensor set | — |
| T1482 | sysmon | not observable with this sensor set | — |
| T1484.001 | auth | not tested | — |
| T1485 | sysmon | not observable with this sensor set | — |
| T1486 | edr | not observable with this sensor set | — |
| T1489 | sysmon | not observable with this sensor set | — |
| T1490 | sysmon | not observable with this sensor set | — |
| T1491.001 | sysmon | not observable with this sensor set | — |
| T1496 | network | checked and observed | ran: Wazuh rule 100201 on Zeek conn.log · completed: yes · expected: a connection record to a known stratum mining port · where/when: Zeek sensor on the lab bridge br-28b08d506cb4, 2026-09-09 03:1x–03:2x UTC · observed: 3 alerts. 172.22.0.2:54700 → 172.22.0.4:3333, tcp, conn_state RSTRH |
| T1505.003 | edr, sysmon | not observable with this sensor set | — |
| T1528 | azuread, cloud_audit | not observable with this sensor set | — |
| T1529 | sysmon | not observable with this sensor set | — |
| T1530 | cloud_audit, cloudtrail | not observable with this sensor set | — |
| T1539 | cloud_audit | not observable with this sensor set | — |
| T1543.003 | sysmon | not observable with this sensor set | — |
| T1546.003 | sysmon | not observable with this sensor set | — |
| T1547.001 | sysmon | not observable with this sensor set | — |
| T1548.002 | sysmon | not observable with this sensor set | — |
| T1550.002 | auth | not tested | — |
| T1550.003 | auth | not tested | — |
| T1552.004 | process | not tested | — |
| T1558.001 | auth | not tested | — |
| T1558.003 | auth | not tested | — |
| T1558.004 | auth | not tested | — |
| T1560.001 | sysmon | not observable with this sensor set | — |
| T1561.002 | sysmon | not observable with this sensor set | — |
| T1562.001 | sysmon | not observable with this sensor set | — |
| T1564.008 | m365 | not observable with this sensor set | — |
| T1565.001 | sysmon | not observable with this sensor set | — |
| T1566.001 | not observable with this sensor set | — | |
| T1566.002 | m365, proxy | not observable with this sensor set | — |
| T1567.002 | cloudtrail, network | not tested | — |
| T1570 | sysmon | not observable with this sensor set | — |
| T1573.002 | network | not tested | — |
| T1574.009 | sysmon | not observable with this sensor set | — |
| T1606.002 | auth | not tested | — |
| T1610 | kubernetes | not observable with this sensor set | — |
| T1611 | falco | not observable with this sensor set | — |
| T1613 | kubernetes | not observable with this sensor set | — |
| T1621 | cloud_audit | not observable with this sensor set | — |
| T1648 | cloud_audit | not observable with this sensor set | — |
Published rather than available on request, so every number above is recomputable:
ATK New Technology · Hanoi, Vietnam · Dong Nguyen · dongnx@atkvn.com
Related, same terms: Detection Reality Index Vol.1 · Vol.2 (IBM QRadar) · Vol.3 · Crypto Reality Index Vol.1 · IETF PQ authentication position paper · atkvn.com