Detection Validation

Testing & Validation

Rules instrumented with simulation frameworks or regression datasets to validate your detection pipeline end-to-end.

47

Simulations

149

Datasets

42

Fully instrumented

154

Testable rules

47 results
atomic-red-teamT1027.001
ART

Pad Binary to Change Hash - Linux/macOS dd

ffe2346c-abd5-4b45-a713-bf5f1ebd573a

atomic-red-teamT1562.001
ART

AMSI Bypass - Create AMSIEnable Reg Key

728eca7b-0444-4f6f-ac36-437e3d751dc0

Interactive AT Job
highwindows· process_creation
atomic-red-teamT1053.002
ART

At.exe Scheduled task

4a6c0dc4-0f2a-4203-9298-a5a9bdc21ed8

Boot Configuration Tampering Via Bcdedit.EXE
highwindows· process_creation
atomic-red-teamT1490
ART

Windows - Disable Windows Recovery Console Repair

cf21060a-80b3-4238-a595-22525de4ab81

atomic-red-teamT1105
ART

Windows - BITSAdmin BITS Download

a1921cd3-9a2d-47d5-a891-f1d0f2a7a31b

atomic-red-teamT1105
ART

Windows - BITSAdmin BITS Download

a1921cd3-9a2d-47d5-a891-f1d0f2a7a31b

atomic-red-teamT1105
ART

Windows - BITSAdmin BITS Download

a1921cd3-9a2d-47d5-a891-f1d0f2a7a31b

atomic-red-teamT1003.005
ART

Cached Credential Dump via Cmdkey

56506854-89d6-46a3-9804-b7fde90791f9

Suspicious Curl.EXE Download
highwindows· process_creation
atomic-red-teamT1105
ART

Curl Download File

2b080b99-0deb-4d51-af0f-833d37c4ca6a

Findstr GPP Passwords
highwindows· process_creation
atomic-red-teamT1552.006
ART

GPP Passwords (findstr)

870fe8fb-5e23-4f5f-b89d-dd7fe26f3b5f

atomic-red-teamT1562.001
ART

Disable Hypervisor-Enforced Code Integrity (HVCI)

70bd71e6-eba4-4e00-92f7-617911dbe020

PUA - AdFind Suspicious Execution
highwindows· process_creation
atomic-red-teamT1018
ART

Adfind - Enumerate Active Directory Computer Objects

a889f5be-2d54-4050-bd05-884578748bb4

atomic-red-teamT1018
ART

Adfind - Enumerate Active Directory Domain Controller Objects

5838c31e-a0e2-4b9f-b60a-d79d2cb7995e