Attack path: System Service Discovery
Kill-chain expansion via actor co-occurrence analysis ·
16 techniques ·
14 detectable
·
2 detection gaps
Entry point: CVE-2016-6883
T1007
Resource Dev
Priv Escalation
Discovery
T1007
System Service Discovery
✓ sigma
999.0x lift
T1124
System Time Discovery
✓ sigma
79.3x lift
T1016.001
Internet Connection Discovery
× no rule
39.7x lift
T1069.001
Local Groups
✓ sigma
21.6x lift
T1049
System Network Connections Dis…
✓ sigma
4.7x lift
T1012
Query Registry
✓ sigma
4.2x lift
T1087.002
Domain Account
✓ sigma
3.2x lift
T1087.001
Local Account
✓ sigma
3.0x lift
Entry point (from CVE)
Detection rule available
Detection gap - potential blind spot
Lift = how strongly this technique co-occurs with the entry point across shared threat actors (1x = expected, 5x = highly distinctive)
Hunt package
All 16 techniques in this chain - Sigma rules, Atomic tests, and detection gaps in one view.