ATT&CK grew a 15th tactic: A practical DFIR field guide to the Stealth / Defense Impairment split

Imported from official source

Cybersecurity Classified by Officially

Artifacts and tooling for the new Enterprise MITRE ATT&CK matrix tactics, distilled from the field.

If you’ve opened the Enterprise ATT&CK matrix recently, you may have done a double-take. The familiar Defense Evasion column is gone. In its place sit two tactics: Stealth (TA0005) and Defense Impairment (TA0112). The Enterprise model now spans 15 tactics rather than 14.

It’s a taxonomy change that makes sense, but it could disrupt your detection engineering, playbooks, and the way you narrate an intrusion in a report. Any content mapped to the old Defense Evasion tactic now belongs to one of two phases with different intent and, crucially for responders, different forensic footprints.

The change makes sense in light of current trends. Adversaries have leaned harder into both tactics over the last few cycles: living-off-the-land to stay quiet, then aggressively disabling telemetry the moment they need room to operate. A framework that treats those as one tactic makes it easy to under-invest in one while over-reporting the other. The split forces an honest audit of both.

Below, I'll show how the new categories improve clarity and offer a phase-by-phase field guide, with artifacts and tooling that you can use to align with the new tactics this week.

Why splitting the Defense Evasion ATT&CK tactic actually helps

Defense Evasion bundled two very different adversary goals: staying hidden and actively breaking the things that would otherwise catch them. Separating them sharpens both detection and response:

  • Stealth (TA0005) is about blending in.
    Examples include: timestomping ($SI vs $FN mismatches), alternate data streams, packing and encoding, masquerading as legitimate binaries. The evidence is subtle and lives in the file system and on disk.
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://www.sophos.com/en-gb/blog/mitre-enterprise-attack-grew-15th-tactic-practical-dfir-field-guide

    Officially imported this from Sophos’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    Sophos — imported from official source
    Official source
    https://news.sophos.com/feed/ RSS
    Imported
    September 20, 2026 19:52
    Versions
    1 recorded
    Identity
    blt10fe9c7e5e3333fa

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.