MITRE ATT&CK Introduces 15th Tactic: Stealth and Defense Impairment
Article Content
- •MITRE ATT&CK now features 15 tactics, with Defense Evasion split into Stealth and Defense Impairment.
- •Stealth focuses on blending in, while Defense Impairment involves degrading defender capabilities.
- •Cybersecurity teams must update detection and response strategies to align with the new tactics.
The MITRE ATT&CK framework has introduced a significant update by splitting the Defense Evasion tactic into two distinct tactics: Stealth (TA0005) and Defense Impairment (TA0112). This change reflects evolving adversary behaviors, where attackers are increasingly using stealth techniques to remain undetected while simultaneously impairing defensive measures. The Stealth tactic focuses on methods to blend in, such as timestomping and masquerading, while Defense Impairment targets the degradation of defenses, like clearing logs and disabling security services. This split aims to enhance clarity in detection and response strategies for cybersecurity professionals. The new tactics necessitate a reassessment of detection engineering and incident response playbooks, especially in modern environments where attacks often exploit identity and cloud services. The update is effective immediately, urging organizations to adapt their tools and methodologies accordingly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…