🪟Windows detections
Clankerusecase tracks 1825 detection use cases covering the Windows attack surface across 298 MITRE ATT&CK techniques.
Detections targeting Windows endpoints — Sysmon / Security event log / Defender DeviceProcessEvents.
1825Use cases
298Techniques
60Articles
6Kill-chain phases
Top techniques on Windows (25)
T1204.002Malicious File505T1195.002Compromise Software Supply Chain280T1071.001Web Protocols213T1190Exploit Public-Facing Application169T1105Ingress Tool Transfer153T1059.004Unix Shell143T1059.007JavaScript143T1552.001Credentials In Files96T1041Exfiltration Over C2 Channel81T1059.006Python65T1195.001Compromise Software Dependencies and Development Tools59T1567Exfiltration Over Web Service58T1036.005Match Legitimate Resource Name or Location55T1059.001PowerShell54T1059Command and Scripting Interpreter48T1505.003Web Shell47T1059.003Windows Command Shell45T1546Event Triggered Execution38T1053.005Scheduled Task31T1543.003Windows Service31T1027Obfuscated Files or Information30T1547.001Registry Run Keys / Startup Folder28T1552.005Cloud Instance Metadata API27T1546.016Installer Packages25T1068Exploitation for Privilege Escalation23