Home/ CVE-2018-16438/ Attack path

Attack path: Exploitation for Client Execution

Kill-chain expansion via actor co-occurrence analysis  ·  16 techniques  ·  4 detectable  ·  12 detection gaps
Entry point: CVE-2018-16438 T1203
Entry point (from CVE) Detection rule available Detection gap - potential blind spot Lift = how strongly this technique co-occurs with the entry point across shared threat actors (1x = expected, 5x = highly distinctive)
Hunt package
All 16 techniques in this chain - Sigma rules, Atomic tests, and detection gaps in one view.
Sigma rules Full technique
threatengine.sh