Tag: MITRE ATT&CK

Living-off-the-Land Kill Chain Detection — Markov chain + ensemble scoring on VPC Flow Logs — HACKFORLAB cover image
0 23
Posted in Cyber Threat

Living-off-the-Land Kill Chain Detection with Markov Chains

Detect blended LOTL attack chains by modelling network state transitions as Markov chains across MITRE ATT&CK phases on AWS VPC Flow Logs.