logo

Misbehaving Modalities: Detecting Tools, Not Techniques

ID: 35894cc4-9cea-5d21-b2a3-fa8375ae15e9

STIX ID: report--35894cc4-9cea-5d21-b2a3-fa8375ae15e9

Feed Name: Elastic Security Labs

Date Published: 2025-05-15

Date Updated: 2026-04-27

...
...

**Executive Summary:** This article introduces and explains the "Execution Modality" concept for reasoning about how malicious behaviors are executed (not just what they do), advocates detecting closer to the operating system source-of-truth (e.g., kernel ETW and call stacks), describes Elastic's modality-based PowerShell detections and example rules, and evaluates detection robustness using the Summiting the Pyramid analytic score.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.