ATT&CK grew a 15th tactic: A practical DFIR field guide to the Stealth / Defense Impairment split
Cybersecurity Classified by Officially
Artifacts and tooling for the new Enterprise MITRE ATT&CK matrix tactics, distilled from the field.
If you’ve opened the Enterprise ATT&CK matrix recently, you may have done a double-take. The familiar Defense Evasion column is gone. In its place sit two tactics: Stealth (TA0005) and Defense Impairment (TA0112). The Enterprise model now spans 15 tactics rather than 14.
It’s a taxonomy change that makes sense, but it could disrupt your detection engineering, playbooks, and the way you narrate an intrusion in a report. Any content mapped to the old Defense Evasion tactic now belongs to one of two phases with different intent and, crucially for responders, different forensic footprints.
The change makes sense in light of current trends. Adversaries have leaned harder into both tactics over the last few cycles: living-off-the-land to stay quiet, then aggressively disabling telemetry the moment they need room to operate. A framework that treats those as one tactic makes it easy to under-invest in one while over-reporting the other. The split forces an honest audit of both.
Below, I'll show how the new categories improve clarity and offer a phase-by-phase field guide, with artifacts and tooling that you can use to align with the new tactics this week.
Why splitting the Defense Evasion ATT&CK tactic actually helps
Defense Evasion bundled two very different adversary goals: staying hidden and actively breaking the things that would otherwise catch them. Separating them sharpens both detection and response:
Examples include: timestomping ($SI vs $FN mismatches), alternate data streams, packing and encoding, masquerading as legitimate binaries. The evidence is subtle and lives in the file system and on disk.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.sophos.com/en-gb/blog/mitre-enterprise-attack-grew-15th-tactic-practical-dfir-field-guide
Officially imported this from Sophos’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Sophos — imported from official source
- Official source
- https://news.sophos.com/feed/ RSS
- Imported
- September 20, 2026 19:52
- Versions
- 1 recorded
- Identity
blt10fe9c7e5e3333fa