Blue Team | Determining Malice Through Context and Analytics

Blue Team | Determining Malice Through Context and Analytics

🎙 Antonia Feffer 👥 70K 📅 February 17, 2026 ⏱ 33 min 👁 140 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

ambiguous techniquescontextanalyticsdetectionfalse positives

Summary

Antonia Feffer, a senior cybersecurity engineer at MITRE, presents the Ambiguous Techniques (AT) project, which aims to improve detection of techniques whose observables are not sufficient to determine malicious intent. The talk builds on prior work on invariant behaviors and introduces a methodology for analyzing ambiguous techniques using three levels of context: peripheral, chain, and technique. The methodology is formalized in a flowchart that guides analysts in determining the necessary context for a given technique. The project validated the approach by developing analytics for techniques like domain account discovery and file/directory discovery, using co-occurring technique analysis and chain-level correlation. Real-world testing in a large enterprise environment showed significant reduction in false positives, from millions of alerts to a manageable number. The talk emphasizes the importance of context in distinguishing malicious from benign activity and provides actionable guidance for detection engineering.

140 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable insights into a practical problem in cybersecurity: distinguishing malicious from benign activity for ambiguous techniques. The argumentation is solid, based on a structured methodology developed through research and validated with real-world data. The speaker clearly explains the concepts and provides concrete examples, such as the domain account discovery analytic that reduced alerts from millions to a fraction of a percent. The approach is pragmatic and actionable, offering a framework that defenders can apply to their own detection engineering processes. The talk also highlights the importance of considering co-occurring techniques and chain-level context, which is often overlooked in traditional detection approaches.

Scientific Rigor, Source Quality, Title Accuracy

The talk is scientifically rigorous, drawing on the MITRE ATT&CK framework and the adversary emulation library. The speaker references prior work on invariant behaviors and the pyramid of pain, but does not provide specific citations or URLs during the talk. The description mentions links at the end, but they are not included in the provided data. The title accurately reflects the content, focusing on determining malice through context and analytics. The talk is well-structured and the methodology is clearly explained, with a logical flow from problem definition to solution validation.

209 words

Title / Content Match

The title accurately reflects the content, focusing on using context and analytics to determine malicious intent.

Quality & Reliability

8/10

Presentation by a senior cybersecurity engineer from MITRE, based on a structured methodology and validated with industry partner data. The talk is technical and detailed, with clear reasoning and practical examples.

Key Moments

Cited Sources

Concurring Sources

Contribution & Novelties

The talk presents a novel methodology for handling ambiguous techniques in cybersecurity, which is a significant challenge for defenders. The approach of using chain-level context and co-occurring techniques to reduce false positives is innovative and practical. The talk also provides a flowchart that can be directly applied by detection engineers. The validation with an industry partner demonstrates the effectiveness of the methodology.

Pour aller plus loin :

  • MITRE ATT&CK — The framework used for classifying techniques.
  • Pyramid of Pain — Concept referenced for evaluating detection robustness.
  • Sigma Rules — The format used for the chain analytics.

96 words

Radar Profile

The radar profile shows high scores across all dimensions, indicating a well-rounded and reliable presentation. The talk is technically deep, provides substantial information, and is based on credible sources.

Reliability 8/10