Learning path
Start here
The archive in the order to meet it rather than the order it was written. Every module ends with you having done something on a machine, not just read about it.
00 Foundations
The vocabulary everything else uses. Do this first even if you have been in the field a while, because the rest of the path assumes the terms.
- Explain what a tactic, a technique and a sub-technique are, and read a technique ID
- Say what ATT&CK is not: a score, a product requirement, or a threat model
- Use a technique page as a study plan rather than a reference
01 Persistence
One tactic, worked four ways, on your own machine. The order matters: each lab is more powerful and more visible than the one before, and the last one only makes sense once you have seen the other three.
- Find the same persistence through the event log, the filesystem, the registry and Autoruns
- Explain the difference between state and history, and why you need both
- Say why detections built on process ancestry survive where ones built on process name drown
- Use frequency analysis to find what is rare rather than trying to know what is bad
- Decide when a technique needs a detection and when it needs a hunt
02 Credential access
Not written yet. Northwind already turns on an LSASS dump, and this module will take that apart properly.
- Recognise credential dumping in process access telemetry
- Scope an incident correctly once credentials are known to be gone
Nothing published for this module yet. It is listed because the path is a plan, and a plan that hides its gaps is not much use to anyone building a term around it.