Attack path: Exploitation of Remote Services
Kill-chain expansion via actor co-occurrence analysis ·
16 techniques ·
12 detectable
·
4 detection gaps
Entry point: CVE-2026-31062
T1210
Priv Escalation
Credential Access
Discovery
Lateral Movement
Impact
T1488
Disk Content Wipe
× no rule
7.3x lift
T1495
Firmware Corruption
✓ sigma
5.2x lift
T1496
Resource Hijacking
✓ sigma
5.0x lift
T1561
Disk Wipe
× no rule
4.6x lift
T1561.001
Disk Content Wipe
✓ sigma
4.2x lift
T1499.004
Application or System Exploita…
✓ sigma
4.2x lift
T1529
System Shutdown/Reboot
✓ sigma
4.2x lift
T1561.002
Disk Structure Wipe
✓ sigma
4.2x lift
Entry point (from CVE)
Detection rule available
Detection gap - potential blind spot
Lift = how strongly this technique co-occurs with the entry point across shared threat actors (1x = expected, 5x = highly distinctive)
Hunt package
All 16 techniques in this chain - Sigma rules, Atomic tests, and detection gaps in one view.