🪟Windows detections
Clankerusecase tracks 1872 detection use cases covering the Windows attack surface across 309 MITRE ATT&CK techniques.
Detections targeting Windows endpoints — Sysmon / Security event log / Defender DeviceProcessEvents.
1872Use cases
309Techniques
60Articles
6Kill-chain phases
Top techniques on Windows (25)
T1204.002Malicious File504T1195.002Compromise Software Supply Chain281T1071.001Web Protocols226T1190Exploit Public-Facing Application169T1105Ingress Tool Transfer166T1059.007JavaScript135T1059.004Unix Shell131T1552.001Credentials In Files93T1041Exfiltration Over C2 Channel77T1059.006Python72T1036.005Match Legitimate Resource Name or Location67T1059.001PowerShell62T1567Exfiltration Over Web Service56T1505.003Web Shell53T1059Command and Scripting Interpreter52T1195.001Compromise Software Dependencies and Development Tools51T1059.003Windows Command Shell46T1053.005Scheduled Task41T1546Event Triggered Execution39T1027Obfuscated Files or Information33T1547.001Registry Run Keys / Startup Folder33T1068Exploitation for Privilege Escalation26T1203Exploitation for Client Execution25T1543.003Windows Service24T1546.016Installer Packages23