logo

How Detection Engineers Can Turn Procedures into Actionable Coverage

ID: 83eefd0c-29ca-562e-b206-d6615ec150d6

STIX ID: report--83eefd0c-29ca-562e-b206-d6615ec150d6

Feed Name: Tidal Cyber Blog

Date Published: 2025-11-11

Date Updated: 2026-03-26

Author: Tidal Cyber

...
...

This piece advocates a Threat-Led Defense approach that makes MITRE ATT&CK actionable by mapping adversary procedures to real detections, tools, and configurations, enabling coverage maps, prioritized detection engineering, and continuous validation of effectiveness; it illustrates with credential dumping examples (e.g., lsass.exe via comsvcs.dll, rundll32 MiniDump, procdump) and positions Tidal Cyber as a platform to implement this procedure-level, outcome-driven methodology.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.