Attack path: Screen Capture
Kill-chain expansion via actor co-occurrence analysis ·
16 techniques ·
11 detectable
·
5 detection gaps
Entry point: CVE-2023-41966
T1113
Resource Dev
Persistence
Priv Escalation
Credential Access
Collection
Entry point (from CVE)
Detection rule available
Detection gap - potential blind spot
Lift = how strongly this technique co-occurs with the entry point across shared threat actors (1x = expected, 5x = highly distinctive)
Hunt package
All 16 techniques in this chain - Sigma rules, Atomic tests, and detection gaps in one view.