Skip to content

Security1 publisher2 min readPublished

Enterprise ATT&CK splits Defense Evasion into Stealth and Defense Impairment

The Enterprise matrix now runs 15 tactics, and the two that replaced Defense Evasion leave different forensic evidence, so detection content mapped to the old tactic has to be reassigned technique by technique.

The Watch · Security desk

Illustration accompanying Enterprise ATT&CK splits Defense Evasion into Stealth and Defense Impairment

What happened

  • Enterprise ATT&CK no longer has a Defense Evasion column; in its place sit two tactics, Stealth with the identifier TA0005 and Defense Impairment with TA0112.
  • Defense Impairment gathers the loud work of clearing Windows event logs (1102), disabling Defender through registry tampering, modifying the firewall and stopping security services, evidence attackers then try to destroy.
  • Stealth covers blending in, and its evidence is subtle and sits on disk: $SI versus $FN timestamp mismatches, alternate data streams, packing and encoding, binaries masquerading as legitimate ones.
  • Sophos says the split looks different in identity and SaaS, where stealth is a valid token with broad access and impairment is disabling conditional access or muting an alerting policy, with no log clearing.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint A coverage layer built before the split keeps reporting the same evasion figure while the new 15th column sits empty, and nothing in the tooling forces the correction.
  • cost Someone has to do the reassignment technique by technique, and the sheet Sophos publishes alongside the guide runs to 43 techniques with their data sources and detection analytics.
  • decision Whether the answer at 2 a.m. is that they hid or that they blinded us now sets collection priorities and timeline order, and Sophos says it changes the conversation with the customer.
  • exposure Teams whose collection stops at the host cannot see the impairment half in cloud intrusions, where the evidence sits in sign-in logs, unified audit trails and provider telemetry.

One of the two identifiers is new. The Enterprise model went from 14 tactics to 15 [2], and of the pair now standing where Defense Evasion did, TA0112 is the later number [15]. The Sophos post does not say whether TA0005 carried over from Defense Evasion or was reissued for Stealth. That detail decides how the change reaches existing content: a rule or coverage layer that stores the tactic name has lost its target, while one that stores the ID may still resolve, to a tactic that now covers only the quiet half.

Sophos says anything mapped to the old Defense Evasion tactic now belongs to one of two phases with different intent and, for responders, different forensic footprints [4]. The post calls it a taxonomy change that "makes sense", but one that "could disrupt your detection engineering, playbooks, and the way you narrate an intrusion in a report" [3]. All three of those sit in the labelling layer above the detection logic.

The behavioural argument for the split is in the same post. Adversaries have leaned harder into both tactics over the last few cycles, living off the land to stay quiet and then disabling telemetry the moment they need room to operate [8]. Sophos argues that a framework treating those as one tactic makes it easy to under-invest in one while over-reporting the other [7].

The guide is drawn from Sophos incident response engagements, and the pattern the company reports from them is that "the artifact was there before the alert was" [11]. The tooling it lists as cross-cutting, working across every phase, is KAPE and Velociraptor for triage and collection, Plaso for super-timelines, and Sigma, YARA and ATT&CK Navigator for detection and coverage mapping [12].

What to watch

  • Whether MITRE publishes deprecation guidance or a crosswalk table for content still mapped to Defense Evasion, and which release carries it.
  • Whether public Sigma repositories and vendor content packs reissue tactic tags for TA0112, and how long that takes.
  • Whether cloud providers' audit trails get technique-level coverage under Defense Impairment for conditional access changes and alert policy edits.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories