Attack path: Password Guessing
Kill-chain expansion via actor co-occurrence analysis ·
16 techniques ·
8 detectable
·
8 detection gaps
Entry point: CVE-2023-23382
T1110.001
Reconnaissance
Persistence
Priv Escalation
Credential Access
T1110.001
Password Guessing
✓ sigma
999.0x lift
T1040
Network Sniffing
✓ sigma
7.7x lift
T1110.003
Password Spraying
× no rule
6.9x lift
T1110.004
Credential Stuffing
× no rule
6.4x lift
T1003.008
/etc/passwd and /etc/shadow
× no rule
5.9x lift
T1552.002
Credentials in Registry
✓ sigma
5.8x lift
T1528
Steal Application Access Token
✓ sigma
4.4x lift
Entry point (from CVE)
Detection rule available
Detection gap - potential blind spot
Lift = how strongly this technique co-occurs with the entry point across shared threat actors (1x = expected, 5x = highly distinctive)
Hunt package
All 16 techniques in this chain - Sigma rules, Atomic tests, and detection gaps in one view.