Skip to content

modify "misconfiguration of security services" under defense evasion #22

@6mile

Description

@6mile

Under Defense Evasion one of the evasion techniques is "Misconfiguration of security measures". I believe this should be more like "disable security measures" or perhaps "disable or misconfigure security measures".
In my experience, it's much more common for attackers to totally disable a control like a GitHub Action, or endpoint detection than it is for them to do the more challenging thing which is to misconfigure it.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions