{
 "source": "MITRE ATT&CK Enterprise v19.1 — Detection Analytics",
 "note": "検知アナリティクス(ハンティング観点)。能動的サイバー防御の下地。logic は英語原文。© The MITRE Corporation.",
 "generated": "2026-06-11",
 "count": 2129,
 "analytics": [
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1595",
   "technique_ja": "アクティブスキャン",
   "technique_en": "Active Scanning",
   "analytic_id": "AN1962",
   "detection_strategy_id": "DET0830",
   "analytic_name": "Analytic 1962",
   "platforms": "PRE",
   "log_sources": "Network Traffic Flow (Network Traffic) | Network Traffic Content (Network Traffic)",
   "log_sources_ja": "ネットワークトラフィックフロー (Network Traffic) | ネットワークトラフィック内容 (Network Traffic)",
   "tuning": "",
   "detection_logic_en": "Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.\nMonitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s))."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1595.001",
   "technique_ja": "IPブロックのスキャン",
   "technique_en": "Scanning IP Blocks",
   "analytic_id": "AN1949",
   "detection_strategy_id": "DET0817",
   "analytic_name": "Analytic 1949",
   "platforms": "PRE",
   "log_sources": "Network Traffic Content (Network Traffic) | Network Traffic Flow (Network Traffic)",
   "log_sources_ja": "ネットワークトラフィック内容 (Network Traffic) | ネットワークトラフィックフロー (Network Traffic)",
   "tuning": "",
   "detection_logic_en": "Monitoring the content of network traffic can help detect patterns associated with active scanning activities. This can include identifying repeated connection attempts, unusual scanning behaviors, or probing activity targeting multiple IP addresses across a network.\nMonitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1595.002",
   "technique_ja": "脆弱性スキャン",
   "technique_en": "Vulnerability Scanning",
   "analytic_id": "AN1999",
   "detection_strategy_id": "DET0867",
   "analytic_name": "Analytic 1999",
   "platforms": "PRE",
   "log_sources": "Network Traffic Content (Network Traffic) | Network Traffic Flow (Network Traffic)",
   "log_sources_ja": "ネットワークトラフィック内容 (Network Traffic) | ネットワークトラフィックフロー (Network Traffic)",
   "tuning": "",
   "detection_logic_en": "Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).\nMonitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1595.003",
   "technique_ja": "ワードリストスキャン",
   "technique_en": "Wordlist Scanning",
   "analytic_id": "AN2000",
   "detection_strategy_id": "DET0868",
   "analytic_name": "Analytic 2000",
   "platforms": "PRE",
   "log_sources": "Network Traffic Content (Network Traffic)",
   "log_sources_ja": "ネットワークトラフィック内容 (Network Traffic)",
   "tuning": "",
   "detection_logic_en": "Monitor for suspicious network traffic that could be indicative of scanning, such as large quantities originating from a single source (especially if the source is known to be associated with an adversary/botnet)."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1592",
   "technique_ja": "標的ホスト情報の収集",
   "technique_en": "Gather Victim Host Information",
   "analytic_id": "AN1958",
   "detection_strategy_id": "DET0826",
   "analytic_name": "Analytic 1958",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "Internet scanners may be used to look for patterns associated with malicious content designed to collect host information from visitors.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: ATT ScanBox)\nMuch of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1592.001",
   "technique_ja": "ハードウェア",
   "technique_en": "Hardware",
   "analytic_id": "AN2019",
   "detection_strategy_id": "DET0887",
   "analytic_name": "Analytic 2019",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "Internet scanners may be used to look for patterns associated with malicious content designed to collect host hardware information from visitors.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: ATT ScanBox)\nMuch of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1592.002",
   "technique_ja": "ソフトウェア",
   "technique_en": "Software",
   "analytic_id": "AN2020",
   "detection_strategy_id": "DET0888",
   "analytic_name": "Analytic 2020",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "Internet scanners may be used to look for patterns associated with malicious content designed to collect host software information from visitors.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: ATT ScanBox)\nMuch of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1592.003",
   "technique_ja": "ファームウェア",
   "technique_en": "Firmware",
   "analytic_id": "AN1950",
   "detection_strategy_id": "DET0818",
   "analytic_name": "Analytic 1950",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1592.004",
   "technique_ja": "クライアント構成",
   "technique_en": "Client Configurations",
   "analytic_id": "AN1952",
   "detection_strategy_id": "DET0820",
   "analytic_name": "Analytic 1952",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "Internet scanners may be used to look for patterns associated with malicious content designed to collect client configuration information from visitors.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: ATT ScanBox)\nMuch of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1589",
   "technique_ja": "標的ID情報の収集",
   "technique_en": "Gather Victim Identity Information",
   "analytic_id": "AN1973",
   "detection_strategy_id": "DET0841",
   "analytic_name": "Analytic 1973",
   "platforms": "PRE",
   "log_sources": "Network Traffic Content (Network Traffic)",
   "log_sources_ja": "ネットワークトラフィック内容 (Network Traffic)",
   "tuning": "",
   "detection_logic_en": "Monitor for suspicious network traffic that could be indicative of probing for user information, such as large/iterative quantities of authentication requests originating from a single source (especially if the source is known to be associated with an adversary/botnet). Analyzing web metadata may also reveal artifacts that can be attributed to potentially malicious activity, such as referer or user-agent string HTTP/S fields."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1589.001",
   "technique_ja": "認証情報",
   "technique_en": "Credentials",
   "analytic_id": "AN1945",
   "detection_strategy_id": "DET0813",
   "analytic_name": "Analytic 1945",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1589.002",
   "technique_ja": "メールアドレス",
   "technique_en": "Email Addresses",
   "analytic_id": "AN1946",
   "detection_strategy_id": "DET0814",
   "analytic_name": "Analytic 1946",
   "platforms": "PRE",
   "log_sources": "Network Traffic Content (Network Traffic)",
   "log_sources_ja": "ネットワークトラフィック内容 (Network Traffic)",
   "tuning": "",
   "detection_logic_en": "Monitor for suspicious network traffic that could be indicative of probing for email addresses and/or usernames, such as large/iterative quantities of authentication requests originating from a single source (especially if the source is known to be associated with an adversary/botnet). Analyzing web metadata may also reveal artifacts that can be attributed to potentially malicious activity, such as referer or user-agent string HTTP/S fields."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1589.003",
   "technique_ja": "従業員名",
   "technique_en": "Employee Names",
   "analytic_id": "AN1989",
   "detection_strategy_id": "DET0857",
   "analytic_name": "Analytic 1989",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1590",
   "technique_ja": "標的ネットワーク情報の収集",
   "technique_en": "Gather Victim Network Information",
   "analytic_id": "AN2001",
   "detection_strategy_id": "DET0869",
   "analytic_name": "Analytic 2001",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1590.001",
   "technique_ja": "ドメインプロパティ",
   "technique_en": "Domain Properties",
   "analytic_id": "AN1979",
   "detection_strategy_id": "DET0847",
   "analytic_name": "Analytic 1979",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1590.002",
   "technique_ja": "DNS",
   "technique_en": "DNS",
   "analytic_id": "AN1975",
   "detection_strategy_id": "DET0843",
   "analytic_name": "Analytic 1975",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1590.003",
   "technique_ja": "ネットワーク信頼依存関係",
   "technique_en": "Network Trust Dependencies",
   "analytic_id": "AN1960",
   "detection_strategy_id": "DET0828",
   "analytic_name": "Analytic 1960",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1590.004",
   "technique_ja": "ネットワークトポロジー",
   "technique_en": "Network Topology",
   "analytic_id": "AN1951",
   "detection_strategy_id": "DET0819",
   "analytic_name": "Analytic 1951",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1590.005",
   "technique_ja": "IPアドレス",
   "technique_en": "IP Addresses",
   "analytic_id": "AN1947",
   "detection_strategy_id": "DET0815",
   "analytic_name": "Analytic 1947",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1590.006",
   "technique_ja": "ネットワークセキュリティアプライアンス",
   "technique_en": "Network Security Appliances",
   "analytic_id": "AN2021",
   "detection_strategy_id": "DET0889",
   "analytic_name": "Analytic 2021",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1591",
   "technique_ja": "標的組織情報の収集",
   "technique_en": "Gather Victim Org Information",
   "analytic_id": "AN2022",
   "detection_strategy_id": "DET0890",
   "analytic_name": "Analytic 2022",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1591.001",
   "technique_ja": "物理的所在地の特定",
   "technique_en": "Determine Physical Locations",
   "analytic_id": "AN1938",
   "detection_strategy_id": "DET0806",
   "analytic_name": "Analytic 1938",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1591.002",
   "technique_ja": "取引関係",
   "technique_en": "Business Relationships",
   "analytic_id": "AN1987",
   "detection_strategy_id": "DET0855",
   "analytic_name": "Analytic 1987",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1591.003",
   "technique_ja": "業務テンポの特定",
   "technique_en": "Identify Business Tempo",
   "analytic_id": "AN1981",
   "detection_strategy_id": "DET0849",
   "analytic_name": "Analytic 1981",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1591.004",
   "technique_ja": "役割の特定",
   "technique_en": "Identify Roles",
   "analytic_id": "AN1939",
   "detection_strategy_id": "DET0807",
   "analytic_name": "Analytic 1939",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1598",
   "technique_ja": "情報収集型フィッシング",
   "technique_en": "Phishing for Information",
   "analytic_id": "AN1955",
   "detection_strategy_id": "DET0823",
   "analytic_name": "Analytic 1955",
   "platforms": "PRE",
   "log_sources": "Network Traffic Content (Network Traffic) | Application Log Content (Application Log) | Network Traffic Flow (Network Traffic)",
   "log_sources_ja": "ネットワークトラフィック内容 (Network Traffic) | アプリケーションログ内容 (Application Log) | ネットワークトラフィックフロー (Network Traffic)",
   "tuning": "",
   "detection_logic_en": "Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).\nDepending on the specific method of phishing, the detections can vary. Monitor for suspicious email activity, such as numerous accounts receiving messages from a single unusual/unknown sender. Filtering based on DKIM+SPF or header analysis can help detect when the email sender is spoofed.(Citation: Microsoft Anti Spoofing)(Citation: ACSC Email Spoofing)\nWhen it comes to following links, monitor for references to uncategorized or known-bad sites. URL inspection within email (including expanding shortened links) can also help detect links leading to known malicious sites.\nMonitor social media traffic for suspicious activity, including messages requesting information as well as abnormal file or data transfers (especially those involving unknown, or otherwise suspicious accounts).\n\nMonitor call logs from corporate devices to identify patterns of potential voice phishing, such as calls to/from known malicious phone numbers.\nMonitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1598.001",
   "technique_ja": "スピアフィッシングサービス",
   "technique_en": "Spearphishing Service",
   "analytic_id": "AN1953",
   "detection_strategy_id": "DET0821",
   "analytic_name": "Analytic 1953",
   "platforms": "PRE",
   "log_sources": "Application Log Content (Application Log) | Network Traffic Flow (Network Traffic) | Network Traffic Content (Network Traffic)",
   "log_sources_ja": "アプリケーションログ内容 (Application Log) | ネットワークトラフィックフロー (Network Traffic) | ネットワークトラフィック内容 (Network Traffic)",
   "tuning": "",
   "detection_logic_en": "Monitor social media traffic for suspicious activity, including messages requesting information as well as abnormal file or data transfers (especially those involving unknown, or otherwise suspicious accounts).\nMuch of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.\nMonitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.\nMonitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s))."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1598.002",
   "technique_ja": "スピアフィッシング添付ファイル",
   "technique_en": "Spearphishing Attachment",
   "analytic_id": "AN1997",
   "detection_strategy_id": "DET0865",
   "analytic_name": "Analytic 1997",
   "platforms": "PRE",
   "log_sources": "Network Traffic Flow (Network Traffic) | Application Log Content (Application Log) | Network Traffic Content (Network Traffic)",
   "log_sources_ja": "ネットワークトラフィックフロー (Network Traffic) | アプリケーションログ内容 (Application Log) | ネットワークトラフィック内容 (Network Traffic)",
   "tuning": "",
   "detection_logic_en": "Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.\nMonitor for suspicious email activity, such as numerous accounts receiving messages from a single unusual/unknown sender. Filtering based on DKIM+SPF or header analysis can help detect when the email sender is spoofed.(Citation: Microsoft Anti Spoofing)(Citation: ACSC Email Spoofing)\nMonitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s))."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1598.003",
   "technique_ja": "スピアフィッシングリンク",
   "technique_en": "Spearphishing Link",
   "analytic_id": "AN2010",
   "detection_strategy_id": "DET0878",
   "analytic_name": "Analytic 2010",
   "platforms": "PRE",
   "log_sources": "Application Log Content (Application Log) | Network Traffic Flow (Network Traffic) | Network Traffic Content (Network Traffic)",
   "log_sources_ja": "アプリケーションログ内容 (Application Log) | ネットワークトラフィックフロー (Network Traffic) | ネットワークトラフィック内容 (Network Traffic)",
   "tuning": "",
   "detection_logic_en": "Monitor for suspicious email activity, such as numerous accounts receiving messages from a single unusual/unknown sender. Filtering based on DKIM+SPF or header analysis can help detect when the email sender is spoofed.(Citation: Microsoft Anti Spoofing)(Citation: ACSC Email Spoofing) Monitor for references to uncategorized or known-bad sites. URL inspection within email (including expanding shortened links and identifying obfuscated URLs) can also help detect links leading to known malicious sites.(Citation: Mandiant URL Obfuscation 2023)\n\nFurthermore, monitor browser logs for homographs in ASCII and in internationalized domain names abusing different character sets (e.g. Cyrillic vs Latin versions of trusted sites).\nMonitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.\nMonitor and analyze traffic patterns and packet inspection associated to protocol(s), leveraging SSL/TLS inspection for encrypted traffic, that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).\n\nFurthermore, monitor network traffic for homographs via the use of internationalized domain names abusing different character sets (e.g. Cyrillic vs Latin versions of trusted sites). Also monitor and analyze traffic patterns and packet inspection for indicators of cloned websites. For example, if adversaries use HTTrack to clone websites,  <code> Mirrored from (victim URL)</code> may be visible in the HTML section of packets. "
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1598.004",
   "technique_ja": "スピアフィッシング音声",
   "technique_en": "Spearphishing Voice",
   "analytic_id": "AN2018",
   "detection_strategy_id": "DET0886",
   "analytic_name": "Analytic 2018",
   "platforms": "PRE",
   "log_sources": "Application Log Content (Application Log)",
   "log_sources_ja": "アプリケーションログ内容 (Application Log)",
   "tuning": "",
   "detection_logic_en": "Monitor call logs from corporate devices to identify patterns of potential voice phishing, such as calls to/from known malicious phone numbers."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1682",
   "technique_ja": "公開AIサービスへの照会",
   "technique_en": "Query Public AI Services",
   "analytic_id": "AN2062",
   "detection_strategy_id": "DET0919",
   "analytic_name": "Analytic 2062",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this takes place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1597",
   "technique_ja": "非公開ソースの探索",
   "technique_en": "Search Closed Sources",
   "analytic_id": "AN1954",
   "detection_strategy_id": "DET0822",
   "analytic_name": "Analytic 1954",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1597.001",
   "technique_ja": "脅威インテリベンダー",
   "technique_en": "Threat Intel Vendors",
   "analytic_id": "AN1948",
   "detection_strategy_id": "DET0816",
   "analytic_name": "Analytic 1948",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1597.002",
   "technique_ja": "技術データの購入",
   "technique_en": "Purchase Technical Data",
   "analytic_id": "AN2012",
   "detection_strategy_id": "DET0880",
   "analytic_name": "Analytic 2012",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1596",
   "technique_ja": "公開技術データベースの探索",
   "technique_en": "Search Open Technical Databases",
   "analytic_id": "AN1992",
   "detection_strategy_id": "DET0860",
   "analytic_name": "Analytic 1992",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1596.001",
   "technique_ja": "DNS/パッシブDNS",
   "technique_en": "DNS/Passive DNS",
   "analytic_id": "AN2009",
   "detection_strategy_id": "DET0877",
   "analytic_name": "Analytic 2009",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1596.002",
   "technique_ja": "WHOIS",
   "technique_en": "WHOIS",
   "analytic_id": "AN1964",
   "detection_strategy_id": "DET0832",
   "analytic_name": "Analytic 1964",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1596.003",
   "technique_ja": "デジタル証明書",
   "technique_en": "Digital Certificates",
   "analytic_id": "AN1963",
   "detection_strategy_id": "DET0831",
   "analytic_name": "Analytic 1963",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1596.004",
   "technique_ja": "CDN",
   "technique_en": "CDNs",
   "analytic_id": "AN1941",
   "detection_strategy_id": "DET0809",
   "analytic_name": "Analytic 1941",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1596.005",
   "technique_ja": "スキャンデータベース",
   "technique_en": "Scan Databases",
   "analytic_id": "AN1990",
   "detection_strategy_id": "DET0858",
   "analytic_name": "Analytic 1990",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1593",
   "technique_ja": "公開ウェブサイト/ドメインの探索",
   "technique_en": "Search Open Websites/Domains",
   "analytic_id": "AN1988",
   "detection_strategy_id": "DET0856",
   "analytic_name": "Analytic 1988",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1593.001",
   "technique_ja": "ソーシャルメディア",
   "technique_en": "Social Media",
   "analytic_id": "AN1944",
   "detection_strategy_id": "DET0812",
   "analytic_name": "Analytic 1944",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1593.002",
   "technique_ja": "検索エンジン",
   "technique_en": "Search Engines",
   "analytic_id": "AN1943",
   "detection_strategy_id": "DET0811",
   "analytic_name": "Analytic 1943",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1593.003",
   "technique_ja": "コードリポジトリ",
   "technique_en": "Code Repositories",
   "analytic_id": "AN1937",
   "detection_strategy_id": "DET0805",
   "analytic_name": "Analytic 1937",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. \n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1681",
   "technique_ja": "脅威ベンダーデータの探索",
   "technique_en": "Search Threat Vendor Data",
   "analytic_id": "AN1998",
   "detection_strategy_id": "DET0866",
   "analytic_name": "Analytic 1998",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders."
  },
  {
   "tactic_id": "TA0043",
   "tactic_ja": "偵察",
   "technique_id": "T1594",
   "technique_ja": "標的所有ウェブサイトの探索",
   "technique_en": "Search Victim-Owned Websites",
   "analytic_id": "AN1942",
   "detection_strategy_id": "DET0810",
   "analytic_name": "Analytic 1942",
   "platforms": "PRE",
   "log_sources": "Application Log Content (Application Log)",
   "log_sources_ja": "アプリケーションログ内容 (Application Log)",
   "tuning": "",
   "detection_logic_en": "Monitor for suspicious network traffic that could be indicative of adversary reconnaissance, such as rapid successions of requests indicative of web crawling and/or large quantities of requests originating from a single source (especially if the source is known to be associated with an adversary). Analyzing web metadata may also reveal artifacts that can be attributed to potentially malicious activity, such as referer or user-agent string HTTP/S fields."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1583",
   "technique_ja": "インフラの取得",
   "technique_en": "Acquire Infrastructure",
   "analytic_id": "AN2027",
   "detection_strategy_id": "DET0895",
   "analytic_name": "Analytic 2027",
   "platforms": "PRE",
   "log_sources": "Response Metadata (Internet Scan) | Response Content (Internet Scan) | Active DNS (Domain Name) | Passive DNS (Domain Name) | Domain Registration (Domain Name)",
   "log_sources_ja": "応答メタデータ (Internet Scan) | 応答内容 (Internet Scan) | アクティブDNS (Domain Name) | パッシブDNS (Domain Name) | ドメイン登録 (Domain Name)",
   "tuning": "",
   "detection_logic_en": "Monitor for contextual data about an Internet-facing resource gathered from a scan, such as running services or ports that may buy, lease, or rent infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.\nOnce adversaries have provisioned infrastructure (ex: a server for use in command and control), internet scans may help proactively discover adversary acquired infrastructure. Consider looking for identifiable patterns such as services listening, certificates in use, SSL/TLS negotiation features, or other response artifacts associated with adversary C2 software.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: Mandiant SCANdalous Jul 2020)(Citation: Koczwara Beacon Hunting Sep 2021) Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.\nMonitor for queried domain name system (DNS) registry data that may buy, lease, or rent infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.\nMonitor for logged domain name system (DNS) data that may buy, lease, or rent infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.\nConsider use of services that may aid in tracking of newly acquired infrastructure, such as WHOIS databases for domain registration information. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1583.001",
   "technique_ja": "ドメイン",
   "technique_en": "Domains",
   "analytic_id": "AN2024",
   "detection_strategy_id": "DET0892",
   "analytic_name": "Analytic 2024",
   "platforms": "PRE",
   "log_sources": "Passive DNS (Domain Name) | Domain Registration (Domain Name) | Active DNS (Domain Name)",
   "log_sources_ja": "パッシブDNS (Domain Name) | ドメイン登録 (Domain Name) | アクティブDNS (Domain Name)",
   "tuning": "",
   "detection_logic_en": "Monitor logged domain name system (DNS) data for purchased domains that can be used during targeting. Reputation/category-based detection may be difficult until the categorization is updated. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access and Command and Control. \nDomain registration information is, by design, captured in public registration logs. Consider use of services that may aid in tracking of newly acquired domains, such as WHOIS databases and/or passive DNS. In some cases it may be possible to pivot on known pieces of domain registration information to uncover other infrastructure purchased by the adversary. Consider monitoring for domains created with a similar structure to your own, including under a different TLD. Though various tools and services exist to track, query, and monitor domain name registration information, tracking across multiple DNS infrastructures can require multiple tools/services or more advanced analytics.(Citation: ThreatConnect Infrastructure Dec 2020) Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access and Command and Control.\nMonitor queried domain name system (DNS) registry data for purchased domains that can be used during targeting. Reputation/category-based detection may be difficult until the categorization is updated. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access and Command and Control."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1583.002",
   "technique_ja": "DNSサーバ",
   "technique_en": "DNS Server",
   "analytic_id": "AN1994",
   "detection_strategy_id": "DET0862",
   "analytic_name": "Analytic 1994",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1583.003",
   "technique_ja": "仮想プライベートサーバ",
   "technique_en": "Virtual Private Server",
   "analytic_id": "AN1970",
   "detection_strategy_id": "DET0838",
   "analytic_name": "Analytic 1970",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan) | Response Metadata (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan) | 応答メタデータ (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "Once adversaries have provisioned a VPS (ex: for use as a command and control server), internet scans may reveal servers that adversaries have acquired. Consider looking for identifiable patterns such as services listening, certificates in use, SSL/TLS negotiation features, or other response artifacts associated with adversary C2 software.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: Mandiant SCANdalous Jul 2020)(Citation: Koczwara Beacon Hunting Sep 2021) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.\nMuch of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1583.004",
   "technique_ja": "サーバ",
   "technique_en": "Server",
   "analytic_id": "AN2003",
   "detection_strategy_id": "DET0871",
   "analytic_name": "Analytic 2003",
   "platforms": "PRE",
   "log_sources": "Response Metadata (Internet Scan) | Response Content (Internet Scan)",
   "log_sources_ja": "応答メタデータ (Internet Scan) | 応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.\nOnce adversaries have provisioned a server (ex: for use as a command and control server), internet scans may reveal servers that adversaries have acquired. Consider looking for identifiable patterns such as services listening, certificates in use, SSL/TLS negotiation features, or other response artifacts associated with adversary C2 software.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: Mandiant SCANdalous Jul 2020)(Citation: Koczwara Beacon Hunting Sep 2021)"
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1583.005",
   "technique_ja": "ボットネット",
   "technique_en": "Botnet",
   "analytic_id": "AN1969",
   "detection_strategy_id": "DET0837",
   "analytic_name": "Analytic 1969",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during [Phishing](https://attack.mitre.org/techniques/T1566), [Endpoint Denial of Service](https://attack.mitre.org/techniques/T1499), or [Network Denial of Service](https://attack.mitre.org/techniques/T1498)."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1583.006",
   "technique_ja": "Webサービス",
   "technique_en": "Web Services",
   "analytic_id": "AN2028",
   "detection_strategy_id": "DET0896",
   "analytic_name": "Analytic 2028",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "Once adversaries leverage the web service as infrastructure (ex: for command and control), it may be possible to look for unique characteristics associated with adversary software, if known.(Citation: ThreatConnect Infrastructure Dec 2020) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control ([Web Service](https://attack.mitre.org/techniques/T1102)) or [Exfiltration Over Web Service](https://attack.mitre.org/techniques/T1567)."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1583.007",
   "technique_ja": "サーバーレス",
   "technique_en": "Serverless",
   "analytic_id": "AN1961",
   "detection_strategy_id": "DET0829",
   "analytic_name": "Analytic 1961",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "Once adversaries leverage serverless functions as infrastructure (ex: for command and control), it may be possible to look for unique characteristics associated with adversary software, if known.(Citation: ThreatConnect Infrastructure Dec 2020) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle. "
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1583.008",
   "technique_ja": "マルバタイジング",
   "technique_en": "Malvertising",
   "analytic_id": "AN1968",
   "detection_strategy_id": "DET0836",
   "analytic_name": "Analytic 1968",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "If infrastructure or patterns in the malicious web content related to malvertising have been previously identified, internet scanning may uncover when an adversary has staged malicious web content. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on other phases of the adversary lifecycle, such as [Drive-by Compromise](https://attack.mitre.org/techniques/T1189) or [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203)."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1584",
   "technique_ja": "インフラの侵害",
   "technique_en": "Compromise Infrastructure",
   "analytic_id": "AN2017",
   "detection_strategy_id": "DET0885",
   "analytic_name": "Analytic 2017",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan) | Domain Registration (Domain Name) | Active DNS (Domain Name) | Passive DNS (Domain Name) | Response Metadata (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan) | ドメイン登録 (Domain Name) | アクティブDNS (Domain Name) | パッシブDNS (Domain Name) | 応答メタデータ (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "Once adversaries have provisioned compromised infrastructure (ex: a server for use in command and control), internet scans may help proactively discover compromised infrastructure. Consider looking for identifiable patterns such as services listening, certificates in use, SSL/TLS negotiation features, or other response artifacts associated with adversary C2 software.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: Mandiant SCANdalous Jul 2020)(Citation: Koczwara Beacon Hunting Sep 2021)\nConsider monitoring for anomalous changes to domain registrant information and/or domain resolution information that may indicate the compromise of a domain. Efforts may need to be tailored to specific domains of interest as benign registration and resolution changes are a common occurrence on the internet.\nMonitor for queried domain name system (DNS) registry data that may compromise third-party infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.\nMonitor for logged domain name system (DNS) data that may compromise third-party infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.\nMonitor for contextual data about an Internet-facing resource gathered from a scan, such as running services or ports that may compromise third-party infrastructure that can be used during targeting. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1584.001",
   "technique_ja": "ドメイン",
   "technique_en": "Domains",
   "analytic_id": "AN1995",
   "detection_strategy_id": "DET0863",
   "analytic_name": "Analytic 1995",
   "platforms": "PRE",
   "log_sources": "Passive DNS (Domain Name) | Domain Registration (Domain Name) | Active DNS (Domain Name)",
   "log_sources_ja": "パッシブDNS (Domain Name) | ドメイン登録 (Domain Name) | アクティブDNS (Domain Name)",
   "tuning": "",
   "detection_logic_en": "Monitor for logged domain name system (DNS) registry data that may hijack domains and/or subdomains that can be used during targeting.  In some cases, abnormal subdomain IP addresses (such as those originating in a different country from the root domain) may indicate a malicious subdomain.(Citation: Palo Alto Unit 42 Domain Shadowing 2022) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.\nConsider monitoring for anomalous changes to domain registrant information and/or domain resolution information that may indicate the compromise of a domain. Efforts may need to be tailored to specific domains of interest as benign registration and resolution changes are a common occurrence on the internet.\nMonitor for queried domain name system (DNS) registry data that may hijack domains and/or subdomains that can be used during targeting. In some cases, abnormal subdomain IP addresses (such as those originating in a different country from the root domain) may indicate a malicious subdomain.(Citation: Palo Alto Unit 42 Domain Shadowing 2022) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1584.002",
   "technique_ja": "DNSサーバ",
   "technique_en": "DNS Server",
   "analytic_id": "AN2023",
   "detection_strategy_id": "DET0891",
   "analytic_name": "Analytic 2023",
   "platforms": "PRE",
   "log_sources": "Active DNS (Domain Name) | Passive DNS (Domain Name)",
   "log_sources_ja": "アクティブDNS (Domain Name) | パッシブDNS (Domain Name)",
   "tuning": "",
   "detection_logic_en": "Monitor for queried domain name system (DNS) registry data that may compromise third-party DNS servers that can be used during targeting. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control.\nMonitor for logged domain name system (DNS) registry data that may compromise third-party DNS servers that can be used during targeting. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1584.003",
   "technique_ja": "仮想プライベートサーバ",
   "technique_en": "Virtual Private Server",
   "analytic_id": "AN1986",
   "detection_strategy_id": "DET0854",
   "analytic_name": "Analytic 1986",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan) | Response Metadata (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan) | 応答メタデータ (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "Once adversaries have provisioned software on a compromised VPS (ex: for use as a command and control server), internet scans may reveal VPSs that adversaries have compromised. Consider looking for identifiable patterns such as services listening, certificates in use, SSL/TLS negotiation features, or other response artifacts associated with adversary C2 software.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: Mandiant SCANdalous Jul 2020)(Citation: Koczwara Beacon Hunting Sep 2021)\n\nMuch of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1584.004",
   "technique_ja": "サーバ",
   "technique_en": "Server",
   "analytic_id": "AN2006",
   "detection_strategy_id": "DET0874",
   "analytic_name": "Analytic 2006",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan) | Response Metadata (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan) | 応答メタデータ (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "Once adversaries have provisioned software on a compromised server (ex: for use as a command and control server), internet scans may reveal servers that adversaries have compromised. Consider looking for identifiable patterns such as services listening, certificates in use, SSL/TLS negotiation features, or other response artifacts associated with adversary C2 software.(Citation: ThreatConnect Infrastructure Dec 2020)(Citation: Mandiant SCANdalous Jul 2020)(Citation: Koczwara Beacon Hunting Sep 2021)\nMuch of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1584.005",
   "technique_ja": "ボットネット",
   "technique_en": "Botnet",
   "analytic_id": "AN2015",
   "detection_strategy_id": "DET0883",
   "analytic_name": "Analytic 2015",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during [Phishing](https://attack.mitre.org/techniques/T1566), [Endpoint Denial of Service](https://attack.mitre.org/techniques/T1499), or [Network Denial of Service](https://attack.mitre.org/techniques/T1498)."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1584.006",
   "technique_ja": "Webサービス",
   "technique_en": "Web Services",
   "analytic_id": "AN2014",
   "detection_strategy_id": "DET0882",
   "analytic_name": "Analytic 2014",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "Once adversaries leverage the abused web service as infrastructure (ex: for command and control), it may be possible to look for unique characteristics associated with adversary software, if known.(Citation: ThreatConnect Infrastructure Dec 2020)\nMuch of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Command and Control [Web Service](https://attack.mitre.org/techniques/T1102) or [Exfiltration Over Web Service](https://attack.mitre.org/techniques/T1567) ."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1584.007",
   "technique_ja": "サーバーレス",
   "technique_en": "Serverless",
   "analytic_id": "AN1996",
   "detection_strategy_id": "DET0864",
   "analytic_name": "Analytic 1996",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "Once adversaries leverage serverless functions as infrastructure (ex: for command and control), it may be possible to look for unique characteristics associated with adversary software, if known.(Citation: ThreatConnect Infrastructure Dec 2020) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle. "
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1584.008",
   "technique_ja": "ネットワーク機器",
   "technique_en": "Network Devices",
   "analytic_id": "AN1991",
   "detection_strategy_id": "DET0859",
   "analytic_name": "Analytic 1991",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "Once adversaries leverage compromised network devices as infrastructure (ex: for command and control), it may be possible to look for unique characteristics associated with adversary software, if known.(Citation: ThreatConnect Infrastructure Dec 2020) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle. "
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1585",
   "technique_ja": "アカウントの確立",
   "technique_en": "Establish Accounts",
   "analytic_id": "AN2005",
   "detection_strategy_id": "DET0873",
   "analytic_name": "Analytic 2005",
   "platforms": "PRE",
   "log_sources": "Network Traffic Content (Network Traffic) | Social Media (Persona)",
   "log_sources_ja": "ネットワークトラフィック内容 (Network Traffic) | ソーシャルメディア (Persona)",
   "tuning": "",
   "detection_logic_en": "Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).\nConsider monitoring social media activity related to your organization. Suspicious activity may include personas claiming to work for your organization or recently created/modified accounts making numerous connection requests to accounts affiliated with your organization.\nMuch of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: [Phishing](https://attack.mitre.org/techniques/T1566))."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1585.001",
   "technique_ja": "ソーシャルメディアアカウント",
   "technique_en": "Social Media Accounts",
   "analytic_id": "AN1983",
   "detection_strategy_id": "DET0851",
   "analytic_name": "Analytic 1983",
   "platforms": "PRE",
   "log_sources": "Network Traffic Content (Network Traffic) | Social Media (Persona)",
   "log_sources_ja": "ネットワークトラフィック内容 (Network Traffic) | ソーシャルメディア (Persona)",
   "tuning": "",
   "detection_logic_en": "Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).\nConsider monitoring social media activity related to your organization. Suspicious activity may include personas claiming to work for your organization or recently created/modified accounts making numerous connection requests to accounts affiliated with your organization.\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: [Spearphishing via Service](https://attack.mitre.org/techniques/T1566/003))."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1585.002",
   "technique_ja": "メールアカウント",
   "technique_en": "Email Accounts",
   "analytic_id": "AN1967",
   "detection_strategy_id": "DET0835",
   "analytic_name": "Analytic 1967",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: [Phishing](https://attack.mitre.org/techniques/T1566))."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1585.003",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Accounts",
   "analytic_id": "AN1978",
   "detection_strategy_id": "DET0846",
   "analytic_name": "Analytic 1978",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during exfiltration (ex: [Transfer Data to Cloud Account](https://attack.mitre.org/techniques/T1537))."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1586",
   "technique_ja": "アカウントの侵害",
   "technique_en": "Compromise Accounts",
   "analytic_id": "AN2008",
   "detection_strategy_id": "DET0876",
   "analytic_name": "Analytic 2008",
   "platforms": "PRE",
   "log_sources": "Social Media (Persona) | Network Traffic Content (Network Traffic)",
   "log_sources_ja": "ソーシャルメディア (Persona) | ネットワークトラフィック内容 (Network Traffic)",
   "tuning": "",
   "detection_logic_en": "Consider monitoring social media activity related to your organization. Suspicious activity may include personas claiming to work for your organization or recently modified accounts making numerous connection requests to accounts affiliated with your organization.\nMuch of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: [Phishing](https://attack.mitre.org/techniques/T1566)).\nMonitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s))."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1586.001",
   "technique_ja": "ソーシャルメディアアカウント",
   "technique_en": "Social Media Accounts",
   "analytic_id": "AN2002",
   "detection_strategy_id": "DET0870",
   "analytic_name": "Analytic 2002",
   "platforms": "PRE",
   "log_sources": "Social Media (Persona) | Network Traffic Content (Network Traffic)",
   "log_sources_ja": "ソーシャルメディア (Persona) | ネットワークトラフィック内容 (Network Traffic)",
   "tuning": "",
   "detection_logic_en": "Consider monitoring social media activity related to your organization. Suspicious activity may include personas claiming to work for your organization or recently modified accounts making numerous connection requests to accounts affiliated with your organization.\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: [Spearphishing via Service](https://attack.mitre.org/techniques/T1566/003)).\nMonitor and analyze traffic patterns and packet inspection associated to protocol(s), leveraging SSL/TLS inspection for encrypted traffic, that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s))."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1586.002",
   "technique_ja": "メールアカウント",
   "technique_en": "Email Accounts",
   "analytic_id": "AN1993",
   "detection_strategy_id": "DET0861",
   "analytic_name": "Analytic 1993",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access (ex: [Phishing](https://attack.mitre.org/techniques/T1566))."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1586.003",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Accounts",
   "analytic_id": "AN2011",
   "detection_strategy_id": "DET0879",
   "analytic_name": "Analytic 2011",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during exfiltration (ex: [Transfer Data to Cloud Account](https://attack.mitre.org/techniques/T1537))."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1587",
   "technique_ja": "能力の開発",
   "technique_en": "Develop Capabilities",
   "analytic_id": "AN1985",
   "detection_strategy_id": "DET0853",
   "analytic_name": "Analytic 1985",
   "platforms": "PRE",
   "log_sources": "Malware Content (Malware Repository) | Malware Metadata (Malware Repository) | Response Content (Internet Scan)",
   "log_sources_ja": "マルウェア内容 (Malware Repository) | マルウェアメタデータ (Malware Repository) | 応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "Consider analyzing malware for features that may be associated with the adversary and/or their developers, such as compiler used, debugging artifacts, or code similarities. Malware repositories can also be used to identify additional samples associated with the adversary and identify development patterns over time. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control.\nMonitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control.\nConsider use of services that may aid in the tracking of capabilities, such as certificates, in use on sites across the Internet. In some cases it may be possible to pivot on known pieces of information to uncover other adversary infrastructure.(Citation: Splunk Kovar Certificates 2017) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1587.001",
   "technique_ja": "マルウェア",
   "technique_en": "Malware",
   "analytic_id": "AN2004",
   "detection_strategy_id": "DET0872",
   "analytic_name": "Analytic 2004",
   "platforms": "PRE",
   "log_sources": "Malware Content (Malware Repository) | Malware Metadata (Malware Repository)",
   "log_sources_ja": "マルウェア内容 (Malware Repository) | マルウェアメタデータ (Malware Repository)",
   "tuning": "",
   "detection_logic_en": "Consider analyzing malware for features that may be associated with the adversary and/or their developers, such as compiler used, debugging artifacts, or code similarities. Malware repositories can also be used to identify additional samples associated with the adversary and identify development patterns over time.\nMonitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1587.002",
   "technique_ja": "コード署名証明書",
   "technique_en": "Code Signing Certificates",
   "analytic_id": "AN1965",
   "detection_strategy_id": "DET0833",
   "analytic_name": "Analytic 1965",
   "platforms": "PRE",
   "log_sources": "Malware Metadata (Malware Repository)",
   "log_sources_ja": "マルウェアメタデータ (Malware Repository)",
   "tuning": "",
   "detection_logic_en": "Consider analyzing self-signed code signing certificates for features that may be associated with the adversary and/or their developers, such as the thumbprint, algorithm used, validity period, and common name. Malware repositories can also be used to identify additional samples associated with the adversary and identify patterns an adversary has used in crafting self-signed code signing certificates.\nMuch of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related follow-on behavior, such as [Code Signing](https://attack.mitre.org/techniques/T1553/002) or [Install Root Certificate](https://attack.mitre.org/techniques/T1553/004)."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1587.003",
   "technique_ja": "デジタル証明書",
   "technique_en": "Digital Certificates",
   "analytic_id": "AN1976",
   "detection_strategy_id": "DET0844",
   "analytic_name": "Analytic 1976",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "Consider use of services that may aid in the tracking of certificates in use on sites across the Internet. In some cases it may be possible to pivot on known pieces of certificate information to uncover other adversary infrastructure.(Citation: Splunk Kovar Certificates 2017)\nDetection efforts may be focused on related behaviors, such as [Web Protocols](https://attack.mitre.org/techniques/T1071/001) , [Asymmetric Cryptography](https://attack.mitre.org/techniques/T1573/002) , and/or [Install Root Certificate](https://attack.mitre.org/techniques/T1553/004) ."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1587.004",
   "technique_ja": "エクスプロイト",
   "technique_en": "Exploits",
   "analytic_id": "AN2026",
   "detection_strategy_id": "DET0894",
   "analytic_name": "Analytic 2026",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the use of exploits (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004))."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1588",
   "technique_ja": "能力の入手",
   "technique_en": "Obtain Capabilities",
   "analytic_id": "AN1982",
   "detection_strategy_id": "DET0850",
   "analytic_name": "Analytic 1982",
   "platforms": "PRE",
   "log_sources": "Certificate Registration (Certificate) | Malware Metadata (Malware Repository) | Response Content (Internet Scan) | Malware Content (Malware Repository)",
   "log_sources_ja": "証明書登録 (Certificate) | マルウェアメタデータ (Malware Repository) | 応答内容 (Internet Scan) | マルウェア内容 (Malware Repository)",
   "tuning": "",
   "detection_logic_en": "Consider use of services that may aid in the tracking of newly issued certificates and/or certificates in use on sites across the Internet. In some cases it may be possible to pivot on known pieces of certificate information to uncover other adversary infrastructure.(Citation: Splunk Kovar Certificates 2017) Some server-side components of adversary tools may have default values set for SSL/TLS certificates.(Citation: Recorded Future Beacon Certificates) Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control.\nMonitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control.\nMonitor for logged network traffic in response to a scan showing both protocol header and body values that may buy and/or steal capabilities that can be used during targeting. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Defense Evasion or Command and Control.\nConsider analyzing malware for features that may be associated with malware providers, such as compiler used, debugging artifacts, code similarities, or even group identifiers associated with specific Malware-as-a-Service (MaaS) offerings. Malware repositories can also be used to identify additional samples associated with the developers and the adversary utilizing their services. Identifying overlaps in malware use by different adversaries may indicate malware was obtained by the adversary rather than developed by them. In some cases, identifying overlapping characteristics in malware used by different adversaries may point to a shared quartermaster.(Citation: FireEyeSupplyChain) Malware repositories can also be used to identify features of tool use associated with an adversary, such as watermarks in [Cobalt Strike](https://attack.mitre.org/software/S0154) payloads.(Citation: Analyzing CS Dec 2020)"
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1588.001",
   "technique_ja": "マルウェア",
   "technique_en": "Malware",
   "analytic_id": "AN1977",
   "detection_strategy_id": "DET0845",
   "analytic_name": "Analytic 1977",
   "platforms": "PRE",
   "log_sources": "Malware Metadata (Malware Repository) | Malware Content (Malware Repository)",
   "log_sources_ja": "マルウェアメタデータ (Malware Repository) | マルウェア内容 (Malware Repository)",
   "tuning": "",
   "detection_logic_en": "Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle.\nConsider analyzing malware for features that may be associated with malware providers, such as compiler used, debugging artifacts, code similarities, or even group identifiers associated with specific MaaS offerings. Malware repositories can also be used to identify additional samples associated with the developers and the adversary utilizing their services. Identifying overlaps in malware use by different adversaries may indicate malware was obtained by the adversary rather than developed by them. In some cases, identifying overlapping characteristics in malware used by different adversaries may point to a shared quartermaster.(Citation: FireEyeSupplyChain)"
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1588.002",
   "technique_ja": "ツール",
   "technique_en": "Tool",
   "analytic_id": "AN1984",
   "detection_strategy_id": "DET0852",
   "analytic_name": "Analytic 1984",
   "platforms": "PRE",
   "log_sources": "Malware Metadata (Malware Repository)",
   "log_sources_ja": "マルウェアメタデータ (Malware Repository)",
   "tuning": "",
   "detection_logic_en": "Monitor for contextual data about a malicious payload, such as compilation times, file hashes, as well as watermarks or other identifiable configuration information. In some cases, malware repositories can also be used to identify features of tool use associated with an adversary, such as watermarks in [Cobalt Strike](https://attack.mitre.org/software/S0154) payloads.(Citation: Analyzing CS Dec 2020)\nMuch of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1588.003",
   "technique_ja": "コード署名証明書",
   "technique_en": "Code Signing Certificates",
   "analytic_id": "AN2007",
   "detection_strategy_id": "DET0875",
   "analytic_name": "Analytic 2007",
   "platforms": "PRE",
   "log_sources": "Malware Metadata (Malware Repository)",
   "log_sources_ja": "マルウェアメタデータ (Malware Repository)",
   "tuning": "",
   "detection_logic_en": "Consider analyzing code signing certificates for features that may be associated with the adversary and/or their developers, such as the thumbprint, algorithm used, validity period, common name, and certificate authority. Malware repositories can also be used to identify additional samples associated with the adversary and identify patterns an adversary has used in procuring code signing certificates.\nMuch of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related follow-on behavior, such as [Code Signing](https://attack.mitre.org/techniques/T1553/002) or [Install Root Certificate](https://attack.mitre.org/techniques/T1553/004)."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1588.004",
   "technique_ja": "デジタル証明書",
   "technique_en": "Digital Certificates",
   "analytic_id": "AN1980",
   "detection_strategy_id": "DET0848",
   "analytic_name": "Analytic 1980",
   "platforms": "PRE",
   "log_sources": "Certificate Registration (Certificate) | Response Content (Internet Scan)",
   "log_sources_ja": "証明書登録 (Certificate) | 応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "Consider use of services that may aid in the tracking of newly issued certificates and/or certificates in use on sites across the Internet. In some cases it may be possible to pivot on known pieces of certificate information to uncover other adversary infrastructure.(Citation: Splunk Kovar Certificates 2017) Some server-side components of adversary tools may have default values set for SSL/TLS certificates.(Citation: Recorded Future Beacon Certificates)\nMonitor for logged network traffic in response to a scan showing both protocol header and body values that may buy and/or steal SSL/TLS certificates that can be used during targeting. Detection efforts may be focused on related behaviors, such as [Web Protocols](https://attack.mitre.org/techniques/T1071/001), [Asymmetric Cryptography](https://attack.mitre.org/techniques/T1573/002), and/or [Install Root Certificate](https://attack.mitre.org/techniques/T1553/004)."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1588.005",
   "technique_ja": "エクスプロイト",
   "technique_en": "Exploits",
   "analytic_id": "AN1959",
   "detection_strategy_id": "DET0827",
   "analytic_name": "Analytic 1959",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "\nMuch of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the use of exploits (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004))."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1588.006",
   "technique_ja": "脆弱性",
   "technique_en": "Vulnerabilities",
   "analytic_id": "AN1940",
   "detection_strategy_id": "DET0808",
   "analytic_name": "Analytic 1940",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the potential use of exploits for vulnerabilities (i.e. [Exploit Public-Facing Application](https://attack.mitre.org/techniques/T1190), [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203), [Exploitation for Privilege Escalation](https://attack.mitre.org/techniques/T1068), [Exploitation for Stealth](https://attack.mitre.org/techniques/T1211), [Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212), [Exploitation of Remote Services](https://attack.mitre.org/techniques/T1210), and [Application or System Exploitation](https://attack.mitre.org/techniques/T1499/004))."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1588.007",
   "technique_ja": "人工知能",
   "technique_en": "Artificial Intelligence",
   "analytic_id": "AN1974",
   "detection_strategy_id": "DET0842",
   "analytic_name": "Analytic 1974",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on behaviors relating to the potential use of generative artificial intelligence (i.e. [Phishing](https://attack.mitre.org/techniques/T1566), [Phishing for Information](https://attack.mitre.org/techniques/T1598))."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1608",
   "technique_ja": "能力の配置（ステージング）",
   "technique_en": "Stage Capabilities",
   "analytic_id": "AN1971",
   "detection_strategy_id": "DET0839",
   "analytic_name": "Analytic 1971",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "If infrastructure or patterns in malware, tooling, certificates, or malicious web content have been previously identified, internet scanning may uncover when an adversary has staged their capabilities.\nMuch of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on related stages of the adversary lifecycle, such as initial access and post-compromise behaviors."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1608.001",
   "technique_ja": "マルウェアのアップロード",
   "technique_en": "Upload Malware",
   "analytic_id": "AN1956",
   "detection_strategy_id": "DET0824",
   "analytic_name": "Analytic 1956",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "If infrastructure or patterns in malware have been previously identified, internet scanning may uncover when an adversary has staged malware to make it accessible for targeting.\nMuch of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle, such as [User Execution](https://attack.mitre.org/techniques/T1204) or [Ingress Tool Transfer](https://attack.mitre.org/techniques/T1105) ."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1608.002",
   "technique_ja": "ツールのアップロード",
   "technique_en": "Upload Tool",
   "analytic_id": "AN1966",
   "detection_strategy_id": "DET0834",
   "analytic_name": "Analytic 1966",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "If infrastructure or patterns in tooling have been previously identified, internet scanning may uncover when an adversary has staged tools to make them accessible for targeting.\nMuch of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on post-compromise phases of the adversary lifecycle, such as [Ingress Tool Transfer](https://attack.mitre.org/techniques/T1105)."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1608.003",
   "technique_ja": "デジタル証明書のインストール",
   "technique_en": "Install Digital Certificate",
   "analytic_id": "AN1972",
   "detection_strategy_id": "DET0840",
   "analytic_name": "Analytic 1972",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "Consider use of services that may aid in the tracking of certificates in use on sites across the Internet. In some cases it may be possible to pivot on known pieces of certificate information to uncover other adversary infrastructure.(Citation: Splunk Kovar Certificates 2017)\nDetection efforts may be focused on related behaviors, such as [Web Protocols](https://attack.mitre.org/techniques/T1071/001) or [Asymmetric Cryptography](https://attack.mitre.org/techniques/T1573/002)."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1608.004",
   "technique_ja": "ドライブバイ標的の準備",
   "technique_en": "Drive-by Target",
   "analytic_id": "AN1957",
   "detection_strategy_id": "DET0825",
   "analytic_name": "Analytic 1957",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "If infrastructure or patterns in the malicious web content utilized to deliver a [Drive-by Compromise](https://attack.mitre.org/techniques/T1189) have been previously identified, internet scanning may uncover when an adversary has staged web content for use in a strategic web compromise.\nMuch of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on other phases of the adversary lifecycle, such as [Drive-by Compromise](https://attack.mitre.org/techniques/T1189) or [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203)."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1608.005",
   "technique_ja": "リンク標的の準備",
   "technique_en": "Link Target",
   "analytic_id": "AN2025",
   "detection_strategy_id": "DET0893",
   "analytic_name": "Analytic 2025",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "If infrastructure or patterns in malicious web content have been previously identified, internet scanning may uncover when an adversary has staged web content to make it accessible for targeting.\nMuch of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on other phases of the adversary lifecycle, such as during [Spearphishing Link](https://attack.mitre.org/techniques/T1598/003) , [Spearphishing Link](https://attack.mitre.org/techniques/T1566/002) , or [Malicious Link](https://attack.mitre.org/techniques/T1204/001) ."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1608.006",
   "technique_ja": "SEOポイズニング",
   "technique_en": "SEO Poisoning",
   "analytic_id": "AN2013",
   "detection_strategy_id": "DET0881",
   "analytic_name": "Analytic 2013",
   "platforms": "PRE",
   "log_sources": "Response Content (Internet Scan)",
   "log_sources_ja": "応答内容 (Internet Scan)",
   "tuning": "",
   "detection_logic_en": "If infrastructure or patterns in the malicious web content related to SEO poisoning or [Drive-by Target](https://attack.mitre.org/techniques/T1608/004) have been previously identified, internet scanning may uncover when an adversary has staged web content supporting a strategic web compromise. Much of this activity will take place outside the visibility of the target organization, making detection of this behavior difficult. Detection efforts may be focused on other phases of the adversary lifecycle, such as [Drive-by Compromise](https://attack.mitre.org/techniques/T1189) or [Exploitation for Client Execution](https://attack.mitre.org/techniques/T1203)."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1650",
   "technique_ja": "アクセスの取得",
   "technique_en": "Acquire Access",
   "analytic_id": "AN2016",
   "detection_strategy_id": "DET0884",
   "analytic_name": "Analytic 2016",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this takes place outside the visibility of the target organization, making detection difficult for defenders. \n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access. "
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1683",
   "technique_ja": "コンテンツの生成",
   "technique_en": "Generate Content",
   "analytic_id": "AN2059",
   "detection_strategy_id": "DET0916",
   "analytic_name": "Analytic 2059",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this takes place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1683.001",
   "technique_ja": "テキスト",
   "technique_en": "Written Content",
   "analytic_id": "AN2060",
   "detection_strategy_id": "DET0917",
   "analytic_name": "Analytic 2060",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this takes place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0042",
   "tactic_ja": "リソース開発",
   "technique_id": "T1683.002",
   "technique_ja": "画像・音声・動画",
   "technique_en": "Audio-Visual Content",
   "analytic_id": "AN2061",
   "detection_strategy_id": "DET0918",
   "analytic_name": "Analytic 2061",
   "platforms": "PRE",
   "log_sources": "",
   "log_sources_ja": "",
   "tuning": "",
   "detection_logic_en": "Much of this takes place outside the visibility of the target organization, making detection difficult for defenders.\n\nDetection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1543",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1543",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | User Account Authentication (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | ユーザーアカウント認証 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "LogonType | TimeWindow | GeoIPMismatch",
   "detection_logic_en": "Detection of compromised or misused valid accounts via anomalous logon patterns, abnormal logon types, and inconsistent geographic or time-based activity across Windows endpoints."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1544",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1544",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | User Account Authentication (NSM:Connections)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ユーザーアカウント認証 (NSM:Connections)",
   "tuning": "UserContext | HostDensityThreshold | LoginMethod",
   "detection_logic_en": "Detection of valid account misuse through SSH logins, sudo/su abuse, and service account anomalies outside expected patterns."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1545",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1545",
   "platforms": "macOS",
   "log_sources": "Logon Session Metadata (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ログオンセッションメタデータ (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "LoginOrigin | ProcessTreeDepth",
   "detection_logic_en": "Detection of interactive and remote logins by service accounts or users at unusual times, with unexpected child process activity."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1546",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1546",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (saas:okta)",
   "log_sources_ja": "ユーザーアカウント認証 (saas:okta)",
   "tuning": "MFAFailureCount | RiskScoreThreshold | IPGeoVelocity",
   "detection_logic_en": "Detection of valid account abuse in IdP logs via geographic anomalies, impossible travel, risky sign-ins, and multiple MFA attempts or failures."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1547",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1547",
   "platforms": "Containers",
   "log_sources": "User Account Authentication (kubernetes:audit)",
   "log_sources_ja": "ユーザーアカウント認証 (kubernetes:audit)",
   "tuning": "ServiceAccountScope | ClusterIPWhitelist",
   "detection_logic_en": "Detection of containerized service accounts or compromised kubeconfigs being used for cluster access from unexpected nodes or IPs."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1283",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1283",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security)",
   "tuning": "UserContext | TimeWindow",
   "detection_logic_en": "Detection of default account usage such as Guest or Administrator performing interactive or remote logons on systems outside of installation or maintenance windows."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1284",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1284",
   "platforms": "Linux",
   "log_sources": "Logon Session Metadata (auditd:USER_LOGIN)",
   "log_sources_ja": "ログオンセッションメタデータ (auditd:USER_LOGIN)",
   "tuning": "SSHMethod | RemoteIPWhitelist",
   "detection_logic_en": "Monitoring for SSH logins from default accounts such as 'root', especially when login is via password and not key-based authentication."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1285",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1285",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (AWS:CloudTrail)",
   "log_sources_ja": "ユーザーアカウント認証 (AWS:CloudTrail)",
   "tuning": "AccountList | GeoLocation",
   "detection_logic_en": "Use of known default service accounts or root-level cloud accounts performing authentication or changes to IAM policy."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1286",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1286",
   "platforms": "ESXi",
   "log_sources": "User Account Authentication (esxi:auth)",
   "log_sources_ja": "ユーザーアカウント認証 (esxi:auth)",
   "tuning": "AccountName | IPRange",
   "detection_logic_en": "Abuse of system-generated or default privileged accounts such as 'root' or 'vpxuser' logging into ESXi hosts."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1287",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1287",
   "platforms": "Network Devices",
   "log_sources": "User Account Authentication (networkdevice:syslog)",
   "log_sources_ja": "ユーザーアカウント認証 (networkdevice:syslog)",
   "tuning": "Username | InterfaceType",
   "detection_logic_en": "Login activity from default admin credentials (e.g., 'admin', 'cisco') on routers, firewalls, and switches."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Accounts",
   "analytic_id": "AN0590",
   "detection_strategy_id": "DET0210",
   "analytic_name": "Analytic 0590",
   "platforms": "Windows",
   "log_sources": "Logon Session Metadata (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッションメタデータ (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext | LogonType",
   "detection_logic_en": "Detection of suspicious logon behavior using valid domain accounts across multiple hosts, off-hours, or simultaneous sessions from geographically distant locations."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Accounts",
   "analytic_id": "AN0591",
   "detection_strategy_id": "DET0210",
   "analytic_name": "Analytic 0591",
   "platforms": "Linux",
   "log_sources": "User Account Authentication (auditd:SYSCALL) | Logon Session Metadata (linux:syslog)",
   "log_sources_ja": "ユーザーアカウント認証 (auditd:SYSCALL) | ログオンセッションメタデータ (linux:syslog)",
   "tuning": "HostnameScope | AccountDomain",
   "detection_logic_en": "Use of domain accounts via sssd or winbind for logon activity outside of typical patterns, especially on sensitive systems or with lateral movement tools."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Accounts",
   "analytic_id": "AN0592",
   "detection_strategy_id": "DET0210",
   "analytic_name": "Analytic 0592",
   "platforms": "macOS",
   "log_sources": "User Account Authentication (macos:unifiedlog)",
   "log_sources_ja": "ユーザーアカウント認証 (macos:unifiedlog)",
   "tuning": "UserLocation | LogonMethod",
   "detection_logic_en": "Domain logins using network accounts or mobile accounts via Open Directory or Active Directory plugins, especially outside business hours or on atypical endpoints."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Accounts",
   "analytic_id": "AN0593",
   "detection_strategy_id": "DET0210",
   "analytic_name": "Analytic 0593",
   "platforms": "ESXi",
   "log_sources": "User Account Authentication (esxi:vpxd) | Logon Session Metadata (esxi:hostd)",
   "log_sources_ja": "ユーザーアカウント認証 (esxi:vpxd) | ログオンセッションメタデータ (esxi:hostd)",
   "tuning": "AccountType | LoginInterface",
   "detection_logic_en": "Login to vSphere or ESXi hosts using domain accounts, especially those associated with vpxuser or unexpected group memberships."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078.003",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Accounts",
   "analytic_id": "AN1137",
   "detection_strategy_id": "DET0407",
   "analytic_name": "Analytic 1137",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Logon Session Metadata (WinEventLog:Security)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | ログオンセッションメタデータ (WinEventLog:Security)",
   "tuning": "TimeWindow | UserContext",
   "detection_logic_en": "Detects anomalous usage of local accounts to log into a system, especially accounts not typically used interactively or outside business hours."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078.003",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Accounts",
   "analytic_id": "AN1138",
   "detection_strategy_id": "DET0407",
   "analytic_name": "Analytic 1138",
   "platforms": "Linux",
   "log_sources": "Logon Session Metadata (auditd:USER_LOGIN) | User Account Authentication (linux:auth)",
   "log_sources_ja": "ログオンセッションメタデータ (auditd:USER_LOGIN) | ユーザーアカウント認証 (linux:auth)",
   "tuning": "TimeWindow | HostRole",
   "detection_logic_en": "Detects interactive or service logins from local accounts outside expected operational context or at anomalous times."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078.003",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Accounts",
   "analytic_id": "AN1139",
   "detection_strategy_id": "DET0407",
   "analytic_name": "Analytic 1139",
   "platforms": "macOS",
   "log_sources": "Logon Session Metadata (macos:unifiedlog)",
   "log_sources_ja": "ログオンセッションメタデータ (macos:unifiedlog)",
   "tuning": "UserContext | TimeWindow",
   "detection_logic_en": "Detects abnormal or rare logins via local accounts through system or remote mechanisms such as SSH."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Accounts",
   "analytic_id": "AN1503",
   "detection_strategy_id": "DET0546",
   "analytic_name": "Analytic 1503",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (azure:signinlogs) | Logon Session Metadata (saas:okta)",
   "log_sources_ja": "ユーザーアカウント認証 (azure:signinlogs) | ログオンセッションメタデータ (saas:okta)",
   "tuning": "AnomalousLocationThreshold | ProtocolType",
   "detection_logic_en": "Detects anomalous authentication activity such as sign-ins from impossible geolocations or legacy protocols from high-privileged accounts."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Accounts",
   "analytic_id": "AN1504",
   "detection_strategy_id": "DET0546",
   "analytic_name": "Analytic 1504",
   "platforms": "IaaS",
   "log_sources": "User Account Authentication (AWS:CloudTrail) | Logon Session Creation (gcp:audit)",
   "log_sources_ja": "ユーザーアカウント認証 (AWS:CloudTrail) | ログオンセッション作成 (gcp:audit)",
   "tuning": "ServiceInteractionBaseline | RoleSwitchRateThreshold",
   "detection_logic_en": "Detects cloud account use for API calls that exceed normal scope, such as IAM changes or access to services never used before."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Accounts",
   "analytic_id": "AN1505",
   "detection_strategy_id": "DET0546",
   "analytic_name": "Analytic 1505",
   "platforms": "SaaS",
   "log_sources": "Logon Session Metadata (m365:unified) | User Account Authentication (gcp:audit)",
   "log_sources_ja": "ログオンセッションメタデータ (m365:unified) | ユーザーアカウント認証 (gcp:audit)",
   "tuning": "FileDownloadThreshold | SharingPolicyViolationThreshold",
   "detection_logic_en": "Detects unexpected access or usage of cloud productivity tools (e.g., downloading large numbers of files, creating external shares) by internal users."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1078.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Accounts",
   "analytic_id": "AN1506",
   "detection_strategy_id": "DET0546",
   "analytic_name": "Analytic 1506",
   "platforms": "Office Suite",
   "log_sources": "Logon Session Metadata (m365:signinlogs) | User Account Authentication (gcp:audit)",
   "log_sources_ja": "ログオンセッションメタデータ (m365:signinlogs) | ユーザーアカウント認証 (gcp:audit)",
   "tuning": "BusinessHours | OfficeProductivityToolBaseline",
   "detection_logic_en": "Detects login and usage patterns deviating from typical Microsoft 365 or Google Workspace user profiles."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1091",
   "technique_ja": "リムーバブルメディア経由の複製",
   "technique_en": "Replication Through Removable Media",
   "analytic_id": "AN0841",
   "detection_strategy_id": "DET0301",
   "analytic_name": "Analytic 0841",
   "platforms": "Windows",
   "log_sources": "Drive Creation (WinEventLog:System) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | File Access (WinEventLog:Microsoft-Windows-Windows Defender/Operational)",
   "log_sources_ja": "ドライブ作成 (WinEventLog:System) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Microsoft-Windows-Windows Defender/Operational)",
   "tuning": "DriveLetterMatch | FileExecutionWindow | ParentProcess | FileEntropy",
   "detection_logic_en": "Execution of files originating from removable media after drive mount, with correlation to file write activity, autorun usage, or lateral spread via staged tools."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1133",
   "technique_ja": "外部リモートサービス",
   "technique_en": "External Remote Services",
   "analytic_id": "AN1004",
   "detection_strategy_id": "DET0354",
   "analytic_name": "Analytic 1004",
   "platforms": "Windows",
   "log_sources": "User Account Authentication (WinEventLog:Security) | Application Log Content (WinEventLog:Application) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ユーザーアカウント認証 (WinEventLog:Security) | アプリケーションログ内容 (WinEventLog:Application) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "BusinessHours | KnownRemoteIPs | FailedLogonThreshold | GeoIPWhitelist | TimeWindow",
   "detection_logic_en": "Unusual or unauthorized external remote access attempts (e.g., RDP, VPN, Citrix) → repeated failed logins followed by a successful session from uncommon geolocations or outside business hours → subsequent internal lateral movement or data exfiltration activities."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1133",
   "technique_ja": "外部リモートサービス",
   "technique_en": "External Remote Services",
   "analytic_id": "AN1005",
   "detection_strategy_id": "DET0354",
   "analytic_name": "Analytic 1005",
   "platforms": "Linux",
   "log_sources": "Logon Session Metadata (auditd:SYSCALL) | Application Log Content (NSM:Connections) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "ログオンセッションメタデータ (auditd:SYSCALL) | アプリケーションログ内容 (NSM:Connections) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "KnownSSHClients | FailedLogonThreshold | TimeWindow",
   "detection_logic_en": "Repeated SSH, VPN, or RDP gateway authentication attempts from external IPs → subsequent successful logon → remote shell or lateral movement activity (e.g., scp/sftp)."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1133",
   "technique_ja": "外部リモートサービス",
   "technique_en": "External Remote Services",
   "analytic_id": "AN1006",
   "detection_strategy_id": "DET0354",
   "analytic_name": "Analytic 1006",
   "platforms": "macOS",
   "log_sources": "Logon Session Metadata (macos:unifiedlog) | Network Connection Creation (macos:unifiedlog) | Network Traffic Flow (PF:Logs)",
   "log_sources_ja": "ログオンセッションメタデータ (macos:unifiedlog) | ネットワーク接続確立 (macos:unifiedlog) | ネットワークトラフィックフロー (PF:Logs)",
   "tuning": "KnownVNCServers | TimeWindow",
   "detection_logic_en": "Unexpected inbound or outbound VNC/SSH/Screen Sharing connections from external sources → repeated failed logins followed by success → remote interactive sessions or abnormal file transfers."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1133",
   "technique_ja": "外部リモートサービス",
   "technique_en": "External Remote Services",
   "analytic_id": "AN1007",
   "detection_strategy_id": "DET0354",
   "analytic_name": "Analytic 1007",
   "platforms": "Containers",
   "log_sources": "Application Log Content (ApplicationLog:API) | Logon Session Metadata (kubernetes:audit) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (ApplicationLog:API) | ログオンセッションメタデータ (kubernetes:audit) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "AllowedCIDRs | TimeWindow",
   "detection_logic_en": "Connections to exposed container services (e.g., Docker API, Kubernetes API server) from unauthorized external IPs → abnormal container creation/start → lateral activity within cluster nodes."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1189",
   "technique_ja": "ドライブバイ侵害",
   "technique_en": "Drive-by Compromise",
   "analytic_id": "AN0498",
   "detection_strategy_id": "DET0176",
   "analytic_name": "Analytic 0498",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Process Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | Application Log Content (WinEventLog:Application) | Process Modification (etw:Microsoft-Windows-Kernel-Process) | File Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | アプリケーションログ内容 (WinEventLog:Application) | プロセス変更 (etw:Microsoft-Windows-Kernel-Process) | ファイル作成 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TimeWindow | KnownGoodDomainsList | PayloadEntropyThreshold | UserContext",
   "detection_logic_en": "Correlated evidence of anomalous browser/network behavior (suspicious external resource fetches and script injection patterns) followed by atypical child processes, ephemeral execution contexts, memory modification or process injection, and unexpected file drops. Defender sees network requests to previously unseen/suspicious domains or resources + browser process spawning unusual children or loading unsigned modules + file writes or registry changes shortly after those requests."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1189",
   "technique_ja": "ドライブバイ侵害",
   "technique_en": "Drive-by Compromise",
   "analytic_id": "AN0499",
   "detection_strategy_id": "DET0176",
   "analytic_name": "Analytic 0499",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Application Log Content (linux:syslog) | Network Traffic Content (NSM:Flow) | File Creation (linux:Sysmon) | Network Connection Creation (NSM:Connections)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | アプリケーションログ内容 (linux:syslog) | ネットワークトラフィック内容 (NSM:Flow) | ファイル作成 (linux:Sysmon) | ネットワーク接続確立 (NSM:Connections)",
   "tuning": "TempPathPatterns | UserShellWhitelist | DomainRarityThreshold",
   "detection_logic_en": "Correlated evidence of browser or webview fetches to uncommon domains or mutated JS resources (proxy/NGFW logs + Zeek/HTTP logs) followed by unexpected interpreters or script engines executing (python, ruby, sh) spawned from browser processes or user sessions, rapid on-disk staging in /tmp, and outbound connections that deviate from baseline. Defender sees: uncommon resource fetch → short-lived child process executions from user browser context → file writes in temp directories → anomalous outbound C2-like connections."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1189",
   "technique_ja": "ドライブバイ侵害",
   "technique_en": "Drive-by Compromise",
   "analytic_id": "AN0500",
   "detection_strategy_id": "DET0176",
   "analytic_name": "Analytic 0500",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | Process Creation (macos:unifiedlog) | File Creation (macos:unifiedlog) | Network Traffic Content (NSM:Flow) | Process Modification (macos:unifiedlog)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow) | プロセス変更 (macos:unifiedlog)",
   "tuning": "SleepyUserThreshold | ExtensionInstallPolicy",
   "detection_logic_en": "Correlated evidence where Safari/Chrome/WebKit-based processes issue network requests for uncommon or obfuscated JS resources followed by spawning of script interpreters, launchd or ad-hoc binaries, unusual child processes, or dynamic library loads into browser processes. Defender sees: proxy/HTTP logs with suspicious resource content + unifiedlogs/ASL showing browser/plugin crashes or extension loads + process events indicating child process creation and file writes to /var/folders or /tmp shortly after the fetch."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1189",
   "technique_ja": "ドライブバイ侵害",
   "technique_en": "Drive-by Compromise",
   "analytic_id": "AN0501",
   "detection_strategy_id": "DET0176",
   "analytic_name": "Analytic 0501",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (azure:signinlogs) | Application Log Content (m365:unified) | User Account Metadata (saas:auth) | Logon Session Creation (AWS:CloudTrail)",
   "log_sources_ja": "ユーザーアカウント認証 (azure:signinlogs) | アプリケーションログ内容 (m365:unified) | ユーザーアカウントメタデータ (saas:auth) | ログオンセッション作成 (AWS:CloudTrail)",
   "tuning": "IdpAlertWindow | HighRiskCountryList | DeviceTrustLevel",
   "detection_logic_en": "Post-compromise identity & session anomalies that follow a drive-by compromise: token reuse from new/unfamiliar IPs, anomalous sign-in patterns for previously inactive users, unexpected consent/grant events, or provisioning changes. Defender sees an endpoint/browser compromise (network + endpoint signals) followed by unusual IdP events: new refresh token issuance, consent/consent-grant events, odd MFA bypass patterns, or unusual OAuth client registrations."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1190",
   "technique_ja": "公開アプリケーションの悪用",
   "technique_en": "Exploit Public-Facing Application",
   "analytic_id": "AN0219",
   "detection_strategy_id": "DET0080",
   "analytic_name": "Analytic 0219",
   "platforms": "Windows",
   "log_sources": "Application Log Content (ApplicationLog:IIS) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "アプリケーションログ内容 (ApplicationLog:IIS) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "PublicVIPs | SuspiciousPatterns | ErrorRateThreshold | TimeWindow | AllowedChildList",
   "detection_logic_en": "Adversary sends crafted HTTP/S (or other service) input to an Internet-facing app (IIS/ASP.NET, API, device portal). Chain: (1) abnormal request patterns to public endpoint → (2) elevated 4xx/5xx or unusual methods/paths → (3) server process (w3wp.exe/other service) spawns shell/LOLbins or loads non-standard modules → (4) optional outbound callback from the host/container."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1190",
   "technique_ja": "公開アプリケーションの悪用",
   "technique_en": "Exploit Public-Facing Application",
   "analytic_id": "AN0220",
   "detection_strategy_id": "DET0080",
   "analytic_name": "Analytic 0220",
   "platforms": "Linux",
   "log_sources": "Application Log Content (ApplicationLog:WebServer) | Process Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (ApplicationLog:WebServer) | プロセス生成 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "WebProcList | ChildToolList | BurstThreshold | TimeWindow",
   "detection_logic_en": "Adversary exploits Apache/Nginx/app servers. Chain: (1) suspicious requests in access logs → (2) spike of 5xx or WAF blocks → (3) web server or interpreter (apache2/nginx/php-fpm/node/python) spawns /bin/sh, curl, wget, socat, or writes webshell → (4) outbound callback."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1190",
   "technique_ja": "公開アプリケーションの悪用",
   "technique_en": "Exploit Public-Facing Application",
   "analytic_id": "AN0221",
   "detection_strategy_id": "DET0080",
   "analytic_name": "Analytic 0221",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | Process Creation (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ServiceList | TimeWindow",
   "detection_logic_en": "Adversary targets macOS-hosted public services (e.g., nginx, node). Chain: suspicious inbound request → service crash/5xx → service spawns shell or writes file → new outbound connection."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1190",
   "technique_ja": "公開アプリケーションの悪用",
   "technique_en": "Exploit Public-Facing Application",
   "analytic_id": "AN0222",
   "detection_strategy_id": "DET0080",
   "analytic_name": "Analytic 0222",
   "platforms": "Containers",
   "log_sources": "Application Log Content (ApplicationLog:Ingress) | Process Creation (docker:events) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (ApplicationLog:Ingress) | プロセス生成 (docker:events) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "IngressNamespaces | MetadataEndpoints | TimeWindow",
   "detection_logic_en": "Adversary exploits containerized app via ingress or service. Chain: (1) suspicious request in ingress/app logs → (2) container process spawns a shell/exec/sidecar (kubectl exec/docker exec) → (3) egress to Internet or metadata service (169.254.169.254)."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1190",
   "technique_ja": "公開アプリケーションの悪用",
   "technique_en": "Exploit Public-Facing Application",
   "analytic_id": "AN0223",
   "detection_strategy_id": "DET0080",
   "analytic_name": "Analytic 0223",
   "platforms": "IaaS",
   "log_sources": "Network Traffic Content (ALB:HTTPLogs) | Network Traffic Flow (AWS:VPCFlowLogs)",
   "log_sources_ja": "ネットワークトラフィック内容 (ALB:HTTPLogs) | ネットワークトラフィックフロー (AWS:VPCFlowLogs)",
   "tuning": "LBProjects | ErrorBurst",
   "detection_logic_en": "Adversary targets cloud-hosted public endpoints. Chain: (1) ALB/ELB/Cloud LB logs show exploit-like inputs or error spikes → (2) workload spawns shell or reaches metadata API → (3) egress to new external hosts."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1190",
   "technique_ja": "公開アプリケーションの悪用",
   "technique_en": "Exploit Public-Facing Application",
   "analytic_id": "AN0224",
   "detection_strategy_id": "DET0080",
   "analytic_name": "Analytic 0224",
   "platforms": "ESXi",
   "log_sources": "Application Log Content (esxi:hostd) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (esxi:hostd) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "MgmtCIDR | TimeWindow",
   "detection_logic_en": "Adversary exploits exposed OpenSLP on ESXi or vCenter public endpoints. Chain: inbound request pattern to mgmt service → hostd/vpxd error/crash/restart → unexpected process behavior or datastore access → outbound callback."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1190",
   "technique_ja": "公開アプリケーションの悪用",
   "technique_en": "Exploit Public-Facing Application",
   "analytic_id": "AN0225",
   "detection_strategy_id": "DET0080",
   "analytic_name": "Analytic 0225",
   "platforms": "Network Devices",
   "log_sources": "Application Log Content (networkdevice:controlplane) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (networkdevice:controlplane) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "MgmtPorts | TrustedAdmins",
   "detection_logic_en": "Adversary exploits public admin services on routers/firewalls/switches. Chain: anomalous HTTP/SNMP/SmartInstall inputs → device syslog errors/restarts → config changes/CLI spawn → egress to attacker C2."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1195",
   "technique_ja": "サプライチェーン侵害",
   "technique_en": "Supply Chain Compromise",
   "analytic_id": "AN1480",
   "detection_strategy_id": "DET0537",
   "analytic_name": "Analytic 1480",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Microsoft-Windows-CodeIntegrity/Operational) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Microsoft-Windows-CodeIntegrity/Operational) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "TimeWindow | TrustedPublishers | TrustedUpdateHosts | RiskScoreThreshold",
   "detection_logic_en": "1) New or updated software is delivered/installed from atypical sources or with signature/hash mismatches; 2) installer/updater writes binaries to unexpected paths or replaces existing signed files; 3) first run causes unsigned/abnormally signed modules to load or child processes to execute, optionally followed by network egress to new destinations."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1195",
   "technique_ja": "サプライチェーン侵害",
   "technique_en": "Supply Chain Compromise",
   "analytic_id": "AN1481",
   "detection_strategy_id": "DET0537",
   "analytic_name": "Analytic 1481",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Process Modification (auditd:SYSCALL) | File Metadata (journald:package) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | プロセス変更 (auditd:SYSCALL) | ファイルメタデータ (journald:package) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "ApprovedRepos | PathScope | MinBinarySize | TimeWindow",
   "detection_logic_en": "1) Package manager or curl/wget installs/upgrades from non-approved repos or unsigned packages; 2) new ELF written into PATH directories or replacement of existing binaries/libraries; 3) first run leads to unexpected child processes or outbound connections."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1195",
   "technique_ja": "サプライチェーン侵害",
   "technique_en": "Supply Chain Compromise",
   "analytic_id": "AN1482",
   "detection_strategy_id": "DET0537",
   "analytic_name": "Analytic 1482",
   "platforms": "macOS",
   "log_sources": "File Metadata (macos:unifiedlog) | Process Creation (macos:osquery) | File Modification (macos:endpointsecurity) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "ファイルメタデータ (macos:unifiedlog) | プロセス生成 (macos:osquery) | ファイル変更 (macos:endpointsecurity) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "AllowedTeamIDs | TrustedDMGs | TimeWindow | RiskScoreThreshold",
   "detection_logic_en": "1) pkg/notarization installs from atypical sources or with Gatekeeper/AMFI warnings; 2) new Mach-O written into /Applications or ~/Library paths or substitution of signed components; 3) first run from installer spawns unsigned children or exfil."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1195.001",
   "technique_ja": "ソフトウェア依存関係・開発ツールの侵害",
   "technique_en": "Compromise Software Dependencies and Development Tools",
   "analytic_id": "AN0021",
   "detection_strategy_id": "DET0009",
   "analytic_name": "Analytic 0021",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | File Metadata (WinEventLog:Microsoft-Windows-CodeIntegrity/Operational) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Microsoft-Windows-CodeIntegrity/Operational) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "TimeWindow | ApprovedRegistries | DevHosts | TrustedPublishers",
   "detection_logic_en": "Adversary manipulates dependencies/dev tools used by developers or CI: a package manager (npm/yarn/pnpm, pip/pipenv, nuget/dotnet, chocolatey/winget, maven/gradle) or a compiler/IDE downloads or restores content; files are written under project paths and execution paths (node_modules, packages, .nuget, .gradle, .m2, %AppData%\\npm, %UserProfile%\\.cargo\\bin, temp build dirs). First run of newly written components triggers scripts (preinstall/postinstall), shell/PowerShell spawning, or loader DLLs, followed by network egress to non-approved registries/CDNs."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1195.001",
   "technique_ja": "ソフトウェア依存関係・開発ツールの侵害",
   "technique_en": "Compromise Software Dependencies and Development Tools",
   "analytic_id": "AN0022",
   "detection_strategy_id": "DET0009",
   "analytic_name": "Analytic 0022",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Process Modification (auditd:SYSCALL) | File Metadata (journald:package) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | プロセス変更 (auditd:SYSCALL) | ファイルメタデータ (journald:package) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "ApprovedRepos | PathScope | TimeWindow",
   "detection_logic_en": "Developer or CI invokes package managers/compilers (apt/yum + build-essential, npm/yarn/pnpm, pip/pip3, gem, cargo, go, maven/gradle). These write executable or script files into PATH or project dirs and immediately execute embedded lifecycle hooks (preinstall/postinstall, setup.py, npm scripts) that spawn shells or curl/wget, followed by egress to unfamiliar registries or domains."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1195.001",
   "technique_ja": "ソフトウェア依存関係・開発ツールの侵害",
   "technique_en": "Compromise Software Dependencies and Development Tools",
   "analytic_id": "AN0023",
   "detection_strategy_id": "DET0009",
   "analytic_name": "Analytic 0023",
   "platforms": "macOS",
   "log_sources": "File Metadata (macos:unifiedlog) | Process Creation (macos:endpointsecurity) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "ファイルメタデータ (macos:unifiedlog) | プロセス生成 (macos:endpointsecurity) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "AllowedTeamIDs | BrewTapsAllowList | TimeWindow",
   "detection_logic_en": "Developer tools (Homebrew, pip, npm/yarn, Xcode builds) install or update dependencies; new Mach-O or scripts appear under /usr/local, /opt/homebrew, ~/Library/Application Support, project dirs (node_modules/.bin, venv/bin). First run spawns sh/zsh/osascript/curl and new outbound flows; Gatekeeper/AMFI may flag unsigned components."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1195.002",
   "technique_ja": "ソフトウェアサプライチェーンの侵害",
   "technique_en": "Compromise Software Supply Chain",
   "analytic_id": "AN0862",
   "detection_strategy_id": "DET0309",
   "analytic_name": "Analytic 0862",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Driver Load (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Microsoft-Windows-CodeIntegrity/Operational) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ドライバ読み込み (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Microsoft-Windows-CodeIntegrity/Operational) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "TimeWindow | ApprovedUpdateHosts | ApprovedSigners | ProgramPaths",
   "detection_logic_en": "Adversary ships a tampered application or update: an updater/installer (msiexec/setup/update.exe/vendor service) writes or replaces binaries; on first run it spawns scripts/shells or unsigned DLLs and beacons to non-approved update CDNs/hosts. Detection correlates: (1) process creation of installer/updater → (2) file metadata changes in program paths → (3) first-run children and module/signature anomalies → (4) outbound connections to unexpected hosts within a short window."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1195.002",
   "technique_ja": "ソフトウェアサプライチェーンの侵害",
   "technique_en": "Compromise Software Supply Chain",
   "analytic_id": "AN0863",
   "detection_strategy_id": "DET0309",
   "analytic_name": "Analytic 0863",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Metadata (journald:package) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルメタデータ (journald:package) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "PathScope | ApprovedRepos | TimeWindow",
   "detection_logic_en": "A compromised package/update (deb/rpm/tarball/AppImage/vendor updater) is installed, writing/overwriting files in /usr/local/bin, /usr/bin, /opt, or ~/.local; first run executes unexpected shells/curl/wget and connects to unapproved hosts. Correlate package/updater execution → file writes/replace → first-run child processes → egress."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1195.002",
   "technique_ja": "ソフトウェアサプライチェーンの侵害",
   "technique_en": "Compromise Software Supply Chain",
   "analytic_id": "AN0864",
   "detection_strategy_id": "DET0309",
   "analytic_name": "Analytic 0864",
   "platforms": "macOS",
   "log_sources": "File Metadata (macos:unifiedlog) | Process Creation (macos:endpointsecurity) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "ファイルメタデータ (macos:unifiedlog) | プロセス生成 (macos:endpointsecurity) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "AllowedTeamIDs | BrewTapsAllowList | TimeWindow",
   "detection_logic_en": "A tampered app/pkg/notarized update is installed via installer, softwareupdated, Homebrew, or vendor updater; new Mach-O or bundle contents appear in /Applications, /Library, /usr/local or /opt/homebrew; first run spawns sh/zsh/osascript/curl and makes egress to unfamiliar domains; AMFI/Gatekeeper may log signature/notarization problems."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1195.003",
   "technique_ja": "ハードウェアサプライチェーンの侵害",
   "technique_en": "Compromise Hardware Supply Chain",
   "analytic_id": "AN1035",
   "detection_strategy_id": "DET0368",
   "analytic_name": "Analytic 1035",
   "platforms": "Windows",
   "log_sources": "Host Status (WinEventLog:Security) | File Metadata (WinEventLog:Microsoft-Windows-CodeIntegrity/Operational) | Driver Load (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "ホスト状態 (WinEventLog:Security) | ファイルメタデータ (WinEventLog:Microsoft-Windows-CodeIntegrity/Operational) | ドライバ読み込み (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "BaselineFirmwareVersion | BaselineDriverList | IntegrityCheckInterval",
   "detection_logic_en": "Detects tampered hardware or firmware via anomalous host status telemetry. Behavioral chain: (1) Pre-OS or firmware components exhibit unexpected version changes, signature failures, or modified boot paths; (2) System management/firmware tools log hardware inventory drift; (3) Sensor health telemetry or boot attestation events fail baseline checks; (4) Follow-on process execution from altered firmware or unknown drivers after boot."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1195.003",
   "technique_ja": "ハードウェアサプライチェーンの侵害",
   "technique_en": "Compromise Hardware Supply Chain",
   "analytic_id": "AN1036",
   "detection_strategy_id": "DET0368",
   "analytic_name": "Analytic 1036",
   "platforms": "Linux",
   "log_sources": "Host Status (auditd:SYSCALL) | File Metadata (fwupd:logs)",
   "log_sources_ja": "ホスト状態 (auditd:SYSCALL) | ファイルメタデータ (fwupd:logs)",
   "tuning": "ApprovedFirmwareHashes | AllowedDeviceIDs",
   "detection_logic_en": "Monitors for hardware or firmware tampering by correlating system boot logs, hardware inventory changes, and secure boot/firmware verification failures. Behavioral chain: (1) UEFI/BIOS version drift; (2) secure boot disabled or signature verification errors; (3) unexpected modules or hardware devices enumerated at boot; (4) new device firmware images loaded from non-approved sources."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1195.003",
   "technique_ja": "ハードウェアサプライチェーンの侵害",
   "technique_en": "Compromise Hardware Supply Chain",
   "analytic_id": "AN1037",
   "detection_strategy_id": "DET0368",
   "analytic_name": "Analytic 1037",
   "platforms": "macOS",
   "log_sources": "Host Status (macos:unifiedlog) | File Metadata (macos:endpointsecurity)",
   "log_sources_ja": "ホスト状態 (macos:unifiedlog) | ファイルメタデータ (macos:endpointsecurity)",
   "tuning": "AllowedTeamIDs | FirmwareVersionBaseline",
   "detection_logic_en": "Detects tampered Mac hardware/firmware by analyzing unified logs, EndpointSecurity events, and Apple Mobile File Integrity (AMFI) checks. Behavioral chain: (1) Boot process reports firmware signature mismatch; (2) Secure Boot policy altered; (3) new EFI drivers or hardware devices appear in inventory; (4) system extension loads from unapproved developer IDs post-boot."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1199",
   "technique_ja": "信頼関係の悪用",
   "technique_en": "Trusted Relationship",
   "analytic_id": "AN1344",
   "detection_strategy_id": "DET0488",
   "analytic_name": "Analytic 1344",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Logon Session Metadata (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | Application Log Content (WinEventLog:Security)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | ログオンセッションメタデータ (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | アプリケーションログ内容 (WinEventLog:Security)",
   "tuning": "ThirdPartyCIDRs | ExpectedAdminHosts | TimeWindow | HighValueResources",
   "detection_logic_en": "Behavioral chain: (1) a login from a third-party account or untrusted source network establishes an interactive/remote session; (2) the session acquires elevated privileges or accesses sensitive resources atypical for that account; (3) subsequent lateral movement or data access occurs from the same session/device. Correlate Windows logon events, token elevation/privileged use, and resource access with third-party context."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1199",
   "technique_ja": "信頼関係の悪用",
   "technique_en": "Trusted Relationship",
   "analytic_id": "AN1345",
   "detection_strategy_id": "DET0488",
   "analytic_name": "Analytic 1345",
   "platforms": "Linux",
   "log_sources": "Logon Session Metadata (auditd:SYSCALL) | Logon Session Creation (linux:syslog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ログオンセッションメタデータ (auditd:SYSCALL) | ログオンセッション作成 (linux:syslog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ThirdPartyUsers | AllowedJumpHosts | MFAExpected",
   "detection_logic_en": "Behavioral chain: (1) sshd or federated SSO logins from third-party networks or identities; (2) rapid sudo/su privilege elevation; (3) access to sensitive paths or east-west SSH. Correlate auth logs, process execution, and network flows."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1199",
   "technique_ja": "信頼関係の悪用",
   "technique_en": "Trusted Relationship",
   "analytic_id": "AN1346",
   "detection_strategy_id": "DET0488",
   "analytic_name": "Analytic 1346",
   "platforms": "macOS",
   "log_sources": "Logon Session Creation (macos:unifiedlog) | Logon Session Metadata (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ログオンセッション作成 (macos:unifiedlog) | ログオンセッションメタデータ (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ManagedDeviceList",
   "detection_logic_en": "Behavioral chain: (1) third-party interactive login or mobileconfig-based device enrollment; (2) privilege use or admin group change; (3) lateral movement mounts/ssh. Correlate unified logs and network telemetry."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1199",
   "technique_ja": "信頼関係の悪用",
   "technique_en": "Trusted Relationship",
   "analytic_id": "AN1347",
   "detection_strategy_id": "DET0488",
   "analytic_name": "Analytic 1347",
   "platforms": "Identity Provider",
   "log_sources": "Logon Session Creation (azure:signinlogs) | Logon Session Metadata (azure:audit) | Application Log Content (m365:unified)",
   "log_sources_ja": "ログオンセッション作成 (azure:signinlogs) | ログオンセッションメタデータ (azure:audit) | アプリケーションログ内容 (m365:unified)",
   "tuning": "TrustedPartnerTenantIDs | RequiredMFA | RoleScopeAllowList",
   "detection_logic_en": "Behavioral chain: (1) delegated admin or external identity establishes session (e.g., partner/reseller DAP, B2B guest, SAML/OAuth trust); (2) role elevation or app consent/permission grant; (3) downstream privileged actions in the tenant. Correlate IdP sign-in, admin/role assignment, and consent/admin-on-behalf events."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1199",
   "technique_ja": "信頼関係の悪用",
   "technique_en": "Trusted Relationship",
   "analytic_id": "AN1348",
   "detection_strategy_id": "DET0488",
   "analytic_name": "Analytic 1348",
   "platforms": "IaaS",
   "log_sources": "Logon Session Creation (AWS:CloudTrail) | Application Log Content (AWS:CloudTrail) | Logon Session Metadata (gcp:audit)",
   "log_sources_ja": "ログオンセッション作成 (AWS:CloudTrail) | アプリケーションログ内容 (AWS:CloudTrail) | ログオンセッションメタデータ (gcp:audit)",
   "tuning": "ExternalAccountAllowList | SensitiveAPIs | GeoVelocityThreshold",
   "detection_logic_en": "Behavioral chain: (1) cross-account or third-party principal assumes a role into the tenant/subscription/project; (2) privileged API calls are made in short succession; (3) access originates from unfamiliar networks or geos. Correlate assume-role/federation events with sensitive API usage."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1199",
   "technique_ja": "信頼関係の悪用",
   "technique_en": "Trusted Relationship",
   "analytic_id": "AN1349",
   "detection_strategy_id": "DET0488",
   "analytic_name": "Analytic 1349",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (saas:googleworkspace) | Logon Session Metadata (saas:salesforce)",
   "log_sources_ja": "アプリケーションログ内容 (saas:googleworkspace) | ログオンセッションメタデータ (saas:salesforce)",
   "tuning": "ApprovedApps | ExportVolumeThreshold",
   "detection_logic_en": "Behavioral chain: (1) third-party app or admin connects via OAuth/marketplace install; (2) high-privilege scopes granted; (3) anomalous actions (mass read/exports, admin changes)."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1199",
   "technique_ja": "信頼関係の悪用",
   "technique_en": "Trusted Relationship",
   "analytic_id": "AN1350",
   "detection_strategy_id": "DET0488",
   "analytic_name": "Analytic 1350",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified) | Logon Session Creation (azure:signinlogs)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | ログオンセッション作成 (azure:signinlogs)",
   "tuning": "MailboxDelegateAllowList",
   "detection_logic_en": "Behavioral chain: (1) delegated administration offers/relationships created or modified by partner tenants; (2) mailbox delegation/impersonation enabled; (3) follow-on access from partner IPs."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1200",
   "technique_ja": "ハードウェアの追加",
   "technique_en": "Hardware Additions",
   "analytic_id": "AN0185",
   "detection_strategy_id": "DET0069",
   "analytic_name": "Analytic 0185",
   "platforms": "Windows",
   "log_sources": "Application Log Content (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Driver Load (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Drive Creation (WinEventLog:System) | Network Traffic Flow (wineventlog:dhcp)",
   "log_sources_ja": "アプリケーションログ内容 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ドライバ読み込み (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ドライブ作成 (WinEventLog:System) | ネットワークトラフィックフロー (wineventlog:dhcp)",
   "tuning": "TrustedDeviceVIDPID | ExpectedBusTypes | TimeWindow | TrustedMACs",
   "detection_logic_en": "Chain: (1) a new external device is recognized by Windows (USB/Thunderbolt/PCIe) or a new block device appears; (2) within a short window, the same user/session spawns processes or the OS mounts a new volume; (3) optional follow-on activity such as HID keystroke injection, DMA driver load, or new network interface MAC on DHCP. Correlate Security EID 6416 / Kernel-PnP with sysmon and DHCP/network metadata."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1200",
   "technique_ja": "ハードウェアの追加",
   "technique_en": "Hardware Additions",
   "analytic_id": "AN0186",
   "detection_strategy_id": "DET0069",
   "analytic_name": "Analytic 0186",
   "platforms": "Linux",
   "log_sources": "Drive Creation (auditd:SYSCALL) | Application Log Content (linux:syslog) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "ドライブ作成 (auditd:SYSCALL) | アプリケーションログ内容 (linux:syslog) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "BlocklistDeviceStrings | ServerClassesNoUSB | DHCPVlanScopes",
   "detection_logic_en": "Chain: (1) udev / kernel logs show hot-plug (USB/Thunderbolt/PCIe); (2) block device created by udisks/diskarbitration; (3) optional: new network interface or DHCP lease observed. Correlate /var/log/messages|syslog, auditd SYSCALL open/creat on /dev, and DHCP/Zeek."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1200",
   "technique_ja": "ハードウェアの追加",
   "technique_en": "Hardware Additions",
   "analytic_id": "AN0187",
   "detection_strategy_id": "DET0069",
   "analytic_name": "Analytic 0187",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | Drive Creation (macos:unifiedlog) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | ドライブ作成 (macos:unifiedlog) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "ManagedUSBPolicy | KnownAppleAccessories",
   "detection_logic_en": "Chain: (1) unified logs report IOUSBHost/IOThunderbolt device arrival; (2) diskarbitrationd attaches a new volume; (3) optional: config profile manipulation or new network interface MAC obtains a lease. Correlate unifiedlogs (subsystems: IOUSBHost, IOKit, diskarbitrationd), FSEvents, and DHCP/Zeek."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566",
   "technique_ja": "フィッシング",
   "technique_en": "Phishing",
   "analytic_id": "AN0188",
   "detection_strategy_id": "DET0070",
   "analytic_name": "Analytic 0188",
   "platforms": "Windows",
   "log_sources": "Application Log Content (m365:unified) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "SuspiciousFileTypes | AllowedSenders",
   "detection_logic_en": "Unusual inbound email activity where attachments or embedded URLs are delivered to users followed by execution of new processes or suspicious document behavior. Detection involves correlating email metadata, file creation, and network activity after a phishing message is received."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566",
   "technique_ja": "フィッシング",
   "technique_en": "Phishing",
   "analytic_id": "AN0189",
   "detection_strategy_id": "DET0070",
   "analytic_name": "Analytic 0189",
   "platforms": "Linux",
   "log_sources": "Application Log Content (Application:Mail) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "アプリケーションログ内容 (Application:Mail) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "MonitoredMailPaths | AttachmentHashBaseline",
   "detection_logic_en": "Monitor for malicious payload delivery through phishing where attachments or URLs in email clients (e.g., Thunderbird, mutt) result in unusual file creation or outbound network connections. Focus on correlation between mail logs, file writes, and execution activity."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566",
   "technique_ja": "フィッシング",
   "technique_en": "Phishing",
   "analytic_id": "AN0190",
   "detection_strategy_id": "DET0070",
   "analytic_name": "Analytic 0190",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "SuspiciousDomains | ExecutionDelayWindow",
   "detection_logic_en": "Detection of phishing through anomalous Mail app activity, such as attachments saved to disk and immediately executed, or Safari/Preview launching URLs and files linked from email messages. Correlate UnifiedLogs events with subsequent process execution."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566",
   "technique_ja": "フィッシング",
   "technique_en": "Phishing",
   "analytic_id": "AN0191",
   "detection_strategy_id": "DET0070",
   "analytic_name": "Analytic 0191",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "ParentProcessList | MacroExecutionThreshold",
   "detection_logic_en": "Phishing via Office documents containing embedded macros or links that spawn processes. Detection relies on correlating Office application logs with suspicious child process execution and outbound network connections."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566",
   "technique_ja": "フィッシング",
   "technique_en": "Phishing",
   "analytic_id": "AN0192",
   "detection_strategy_id": "DET0070",
   "analytic_name": "Analytic 0192",
   "platforms": "Identity Provider",
   "log_sources": "Logon Session Creation (azure:signinlogs)",
   "log_sources_ja": "ログオンセッション作成 (azure:signinlogs)",
   "tuning": "GeoAnomalyThreshold | MFABypassIndicators",
   "detection_logic_en": "Phishing attempts targeting IdPs often manifest as anomalous login attempts from suspicious email invitations or fake SSO prompts. Detection correlates login flows, MFA bypass attempts, and anomalous geographic patterns following phishing email delivery."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566",
   "technique_ja": "フィッシング",
   "technique_en": "Phishing",
   "analytic_id": "AN0193",
   "detection_strategy_id": "DET0070",
   "analytic_name": "Analytic 0193",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (saas:collaboration)",
   "log_sources_ja": "アプリケーションログ内容 (saas:collaboration)",
   "tuning": "MonitoredSaaSApps | LinkInspectionPolicy",
   "detection_logic_en": "Phishing delivered via SaaS services (chat, collaboration platforms) where messages contain malicious URLs or attachments. Detect anomalous link clicks, suspicious file uploads, or token misuse after SaaS-based phishing attempts."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566.001",
   "technique_ja": "スピアフィッシング添付ファイル",
   "technique_en": "Spearphishing Attachment",
   "analytic_id": "AN0655",
   "detection_strategy_id": "DET0236",
   "analytic_name": "Analytic 0655",
   "platforms": "Windows",
   "log_sources": "Application Log Content (m365:unified) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "AttachmentExtensions | SuspiciousParentChildPairs | TimeWindow",
   "detection_logic_en": "Detection of spearphishing attachments by correlating suspicious email delivery with subsequent file creation and abnormal process execution (e.g., Office spawning PowerShell or CMD). Behavior chain includes inbound email metadata → attachment stored on disk → process execution → outbound network activity."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566.001",
   "technique_ja": "スピアフィッシング添付ファイル",
   "technique_en": "Spearphishing Attachment",
   "analytic_id": "AN0656",
   "detection_strategy_id": "DET0236",
   "analytic_name": "Analytic 0656",
   "platforms": "Linux",
   "log_sources": "Application Log Content (Application:Mail) | Process Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (Application:Mail) | プロセス生成 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "AttachmentStoragePaths | ScriptInterpreters",
   "detection_logic_en": "Phishing attachments executed on Linux systems are detected by linking email logs to file creation in mail directories and subsequent suspicious process execution. Look for unexpected binaries or scripts spawned from user mail directories and anomalous outbound network activity."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566.001",
   "technique_ja": "スピアフィッシング添付ファイル",
   "technique_en": "Spearphishing Attachment",
   "analytic_id": "AN0657",
   "detection_strategy_id": "DET0236",
   "analytic_name": "Analytic 0657",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | Process Creation (macos:unifiedlog) | File Creation (macos:unifiedlog)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:unifiedlog)",
   "tuning": "ExecutionDelayThreshold | SuspiciousParentApps",
   "detection_logic_en": "Phishing attachment detection on macOS through correlation of Mail app logs, file creation in user directories, and abnormal process execution (e.g., Preview.app or Mail.app spawning Terminal or scripting binaries). Network traffic after attachment interaction is also monitored."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566.002",
   "technique_ja": "スピアフィッシングリンク",
   "technique_en": "Spearphishing Link",
   "analytic_id": "AN0298",
   "detection_strategy_id": "DET0107",
   "analytic_name": "Analytic 0298",
   "platforms": "Windows",
   "log_sources": "Application Log Content (m365:unified) | Process Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | プロセス生成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "SuspiciousTLDs | URLShortenerDomains | ClickToExecutionWindow",
   "detection_logic_en": "Correlation of inbound emails with embedded links followed by user-driven browser navigation to suspicious or obfuscated domains. Detection chain includes malicious URL in email → user click recorded in Office logs → browser process spawning unusual child processes (e.g., PowerShell, cmd) or download activity."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566.002",
   "technique_ja": "スピアフィッシングリンク",
   "technique_en": "Spearphishing Link",
   "analytic_id": "AN0299",
   "detection_strategy_id": "DET0107",
   "analytic_name": "Analytic 0299",
   "platforms": "Linux",
   "log_sources": "Application Log Content (Application:Mail) | Process Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (Application:Mail) | プロセス生成 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "MonitoredBrowsers | PhishingIndicators",
   "detection_logic_en": "Detection of spearphishing links through mail logs and browser activity. Behavior includes email with suspicious URLs → user click recorded in mail/web proxy logs → shell or interpreter launched from browser process."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566.002",
   "technique_ja": "スピアフィッシングリンク",
   "technique_en": "Spearphishing Link",
   "analytic_id": "AN0300",
   "detection_strategy_id": "DET0107",
   "analytic_name": "Analytic 0300",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | Process Creation (macos:unifiedlog) | Network Traffic Content (macos:unifiedlog)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog) | ネットワークトラフィック内容 (macos:unifiedlog)",
   "tuning": "CertificateAnomalies | ExecutionDelayThreshold",
   "detection_logic_en": "Correlation of Mail.app logs with Safari/Chrome activity. Suspicious behavior includes email links → Safari/Chrome accessing newly registered or lookalike domains → osascript or Terminal spawned unexpectedly."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566.002",
   "technique_ja": "スピアフィッシングリンク",
   "technique_en": "Spearphishing Link",
   "analytic_id": "AN0301",
   "detection_strategy_id": "DET0107",
   "analytic_name": "Analytic 0301",
   "platforms": "Identity Provider",
   "log_sources": "Application Log Content (azure:signinlogs)",
   "log_sources_ja": "アプリケーションログ内容 (azure:signinlogs)",
   "tuning": "AllowedApps | AnomalousConsentPatterns",
   "detection_logic_en": "Detection of OAuth consent phishing or malicious login attempts initiated through spearphishing links. Behavior chain includes inbound email with OAuth URL → consent page visited → unusual token grants logged in IdP logs."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566.003",
   "technique_ja": "サービス経由のスピアフィッシング",
   "technique_en": "Spearphishing via Service",
   "analytic_id": "AN0320",
   "detection_strategy_id": "DET0115",
   "analytic_name": "Analytic 0320",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "MonitoredServices | SuspiciousProcessPatterns | TimeWindow",
   "detection_logic_en": "Inbound spearphishing attempts delivered via third-party services (e.g., Gmail, LinkedIn messages) leading to malicious file downloads or browser-initiated script execution. Defender view includes correlation of external service logins, unexpected file write operations, and suspicious descendant processes spawned from productivity or browser applications."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566.003",
   "technique_ja": "サービス経由のスピアフィッシング",
   "technique_en": "Spearphishing via Service",
   "analytic_id": "AN0321",
   "detection_strategy_id": "DET0115",
   "analytic_name": "Analytic 0321",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Application Log Content (linux:syslog) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | アプリケーションログ内容 (linux:syslog) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "BrowserProcesses | PhishingIndicators",
   "detection_logic_en": "Use of non-enterprise email or messaging services in Thunderbird, Evolution, or browsers leading to suspicious file downloads and subsequent execution. Defender view includes browser-initiated downloads of unexpected content and shell or interpreter processes launched post-download."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566.003",
   "technique_ja": "サービス経由のスピアフィッシング",
   "technique_en": "Spearphishing via Service",
   "analytic_id": "AN0322",
   "detection_strategy_id": "DET0115",
   "analytic_name": "Analytic 0322",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | Process Creation (macos:unifiedlog) | Network Traffic Content (macos:unifiedlog)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog) | ネットワークトラフィック内容 (macos:unifiedlog)",
   "tuning": "CertificateChecks | ExecutionDelay",
   "detection_logic_en": "Phishing attempts via iCloud Mail, Gmail, or social media apps accessed on macOS systems. Defender view includes Mail.app or Safari downloads of files followed by osascript, Terminal, or abnormal child process execution."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566.004",
   "technique_ja": "スピアフィッシング音声",
   "technique_en": "Spearphishing Voice",
   "analytic_id": "AN0683",
   "detection_strategy_id": "DET0245",
   "analytic_name": "Analytic 0683",
   "platforms": "Windows",
   "log_sources": "Application Log Content (ApplicationLog:CallRecords)",
   "log_sources_ja": "アプリケーションログ内容 (ApplicationLog:CallRecords)",
   "tuning": "PhoneNumberBlocklist | TimeWindow",
   "detection_logic_en": "Monitor call log records from corporate devices for unusual or unauthorized numbers, especially repeated calls to/from known malicious phone numbers. Correlate with subsequent system events (e.g., browser navigation, remote management tool execution)."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566.004",
   "technique_ja": "スピアフィッシング音声",
   "technique_en": "Spearphishing Voice",
   "analytic_id": "AN0684",
   "detection_strategy_id": "DET0245",
   "analytic_name": "Analytic 0684",
   "platforms": "Linux",
   "log_sources": "Application Log Content (networkdevice:syslog)",
   "log_sources_ja": "アプリケーションログ内容 (networkdevice:syslog)",
   "tuning": "CallDestinationPatterns | UserContext",
   "detection_logic_en": "Audit VoIP/SIP logs for suspicious outbound calls or call setup messages to unusual endpoints. Correlate with user activity such as browser execution or package installation following the call."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566.004",
   "technique_ja": "スピアフィッシング音声",
   "technique_en": "Spearphishing Voice",
   "analytic_id": "AN0685",
   "detection_strategy_id": "DET0245",
   "analytic_name": "Analytic 0685",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog)",
   "tuning": "CallerIDPatterns | PayloadCorrelation",
   "detection_logic_en": "Monitor Facetime, iMessage, or SIP client logs for anomalous voice call attempts. Link to subsequent user execution events (downloads, RMM installs) triggered post-call."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1566.004",
   "technique_ja": "スピアフィッシング音声",
   "technique_en": "Spearphishing Voice",
   "analytic_id": "AN0686",
   "detection_strategy_id": "DET0245",
   "analytic_name": "Analytic 0686",
   "platforms": "Identity Provider",
   "log_sources": "Application Log Content (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified)",
   "tuning": "MFARequestThreshold | ConsentGrantPatterns",
   "detection_logic_en": "Correlate MFA push fatigue or unusual consent grant attempts with call activity where adversaries may have socially engineered the user over voice."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1659",
   "technique_ja": "コンテンツインジェクション",
   "technique_en": "Content Injection",
   "analytic_id": "AN0992",
   "detection_strategy_id": "DET0349",
   "analytic_name": "Analytic 0992",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "MonitoredExtensions | SuspiciousParentProcesses | RedirectList",
   "detection_logic_en": "Detect suspicious file creations and process executions triggered by browser activity (e.g., injected payloads written to %AppData% or Temp directories, then executed). Correlate network anomalies with subsequent local process creation or script execution."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1659",
   "technique_ja": "コンテンツインジェクション",
   "technique_en": "Content Injection",
   "analytic_id": "AN0993",
   "detection_strategy_id": "DET0349",
   "analytic_name": "Analytic 0993",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | File Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ファイル作成 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TempDirectories",
   "detection_logic_en": "Detect curl/wget commands saving executable/script payloads to /tmp or /var/tmp followed by execution. Monitor packet captures or IDS/IPS alerts for injected responses or mismatched content types."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1659",
   "technique_ja": "コンテンツインジェクション",
   "technique_en": "Content Injection",
   "analytic_id": "AN0994",
   "detection_strategy_id": "DET0349",
   "analytic_name": "Analytic 0994",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "MonitoredDirectories",
   "detection_logic_en": "Monitor unified logs for processes spawned from Safari or other browsers that immediately load scripts or executables. Detect file drops in ~/Library/Caches or ~/Downloads that execute shortly after being written."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1669",
   "technique_ja": "Wi-Fiネットワーク",
   "technique_en": "Wi-Fi Networks",
   "analytic_id": "AN1476",
   "detection_strategy_id": "DET0536",
   "analytic_name": "Analytic 1476",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Microsoft-Windows-WLAN-AutoConfig) | User Account Authentication (WinEventLog:Security)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Microsoft-Windows-WLAN-AutoConfig) | ユーザーアカウント認証 (WinEventLog:Security)",
   "tuning": "KnownSSIDList | GeoLocationContext",
   "detection_logic_en": "Detects anomalous wireless connections such as unexpected SSID associations, failed or repeated authentication attempts, and connections outside of known geofenced networks. Defenders should monitor wireless connection logs and event codes for network discovery, authentication, and association events."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1669",
   "technique_ja": "Wi-Fiネットワーク",
   "technique_en": "Wi-Fi Networks",
   "analytic_id": "AN1477",
   "detection_strategy_id": "DET0536",
   "analytic_name": "Analytic 1477",
   "platforms": "Linux",
   "log_sources": "Network Connection Creation (linux:syslog) | Network Traffic Flow (auditd:SYSCALL)",
   "log_sources_ja": "ネットワーク接続確立 (linux:syslog) | ネットワークトラフィックフロー (auditd:SYSCALL)",
   "tuning": "AllowedSSIDRegex | RetryThreshold",
   "detection_logic_en": "Detects unauthorized wireless associations by monitoring wpa_supplicant logs, NetworkManager events, and system calls related to interface state changes. Anomalies include repeated association failures, new SSIDs outside baselined values, and rogue AP connections."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1669",
   "technique_ja": "Wi-Fiネットワーク",
   "technique_en": "Wi-Fi Networks",
   "analytic_id": "AN1478",
   "detection_strategy_id": "DET0536",
   "analytic_name": "Analytic 1478",
   "platforms": "macOS",
   "log_sources": "Network Connection Creation (macos:unifiedlog) | Network Traffic Flow (macos:osquery)",
   "log_sources_ja": "ネットワーク接続確立 (macos:unifiedlog) | ネットワークトラフィックフロー (macos:osquery)",
   "tuning": "BaselineSSIDHistory",
   "detection_logic_en": "Detects unauthorized Wi-Fi associations and SSID scanning activity using unified logs and airport command telemetry. Anomalies include rapid SSID switching, connections to unapproved SSIDs, or repeated authentication failures."
  },
  {
   "tactic_id": "TA0001",
   "tactic_ja": "初期アクセス",
   "technique_id": "T1669",
   "technique_ja": "Wi-Fiネットワーク",
   "technique_en": "Wi-Fi Networks",
   "analytic_id": "AN1479",
   "detection_strategy_id": "DET0536",
   "analytic_name": "Analytic 1479",
   "platforms": "Network Devices",
   "log_sources": "Firewall Rule Modification (NSM:Firewall) | Network Traffic Content (WIDS:AssociationLogs)",
   "log_sources_ja": "ファイアウォールルール変更 (NSM:Firewall) | ネットワークトラフィック内容 (WIDS:AssociationLogs)",
   "tuning": "AuthorizedAPList",
   "detection_logic_en": "Detects rogue or suspicious wireless access attempts by monitoring firewall, WIDS/WIPS, and controller logs. Focus is on firewall rule changes, rogue AP detection, and anomalous MAC addresses connecting to access points."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1047",
   "technique_ja": "Windows Management Instrumentation",
   "technique_en": "Windows Management Instrumentation",
   "analytic_id": "AN1031",
   "detection_strategy_id": "DET0364",
   "analytic_name": "Analytic 1031",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | WMI Creation (WinEventLog:WMI)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | WMI作成 (WinEventLog:WMI)",
   "tuning": "WMIQueryScope | TimeWindow | UserContext | RemoteDestinationThreshold | SuspiciousCommandPatterns",
   "detection_logic_en": "Detects adversarial abuse of WMI to execute local or remote commands via WMIC, PowerShell, or COM API through a multi-event chain: process creation, command execution, and corresponding network connection if remote."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1053",
   "technique_ja": "スケジュールされたタスク/ジョブ",
   "technique_en": "Scheduled Task/Job",
   "analytic_id": "AN0258",
   "detection_strategy_id": "DET0094",
   "analytic_name": "Analytic 0258",
   "platforms": "Windows",
   "log_sources": "Scheduled Job Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | File Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "スケジュールジョブ作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Sysmon)",
   "tuning": "TaskAuthor | CommandLineRegex | ExecutionWindow",
   "detection_logic_en": "Detects creation or modification of scheduled tasks using schtasks.exe, at.exe, or COM objects followed by execution of outlier processes tied to the scheduled job."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1053",
   "technique_ja": "スケジュールされたタスク/ジョブ",
   "technique_en": "Scheduled Task/Job",
   "analytic_id": "AN0259",
   "detection_strategy_id": "DET0094",
   "analytic_name": "Analytic 0259",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Scheduled Job Creation (linux:osquery)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | スケジュールジョブ作成 (linux:osquery)",
   "tuning": "CronSchedulePattern | ServiceUser | BinaryEntropy",
   "detection_logic_en": "Detects creation or modification of cron jobs via crontab, /etc/cron.* directories, or systemd timer units with execution by unusual users or non-standard intervals."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1053",
   "technique_ja": "スケジュールされたタスク/ジョブ",
   "technique_en": "Scheduled Task/Job",
   "analytic_id": "AN0260",
   "detection_strategy_id": "DET0094",
   "analytic_name": "Analytic 0260",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (fs:fsusage) | Scheduled Job Creation (macos:osquery)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (fs:fsusage) | スケジュールジョブ作成 (macos:osquery)",
   "tuning": "PlistLabel | LaunchPath | JobRunInterval",
   "detection_logic_en": "Detects creation or alteration of LaunchAgents or LaunchDaemons with corresponding plist modification followed by execution of associated binaries."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1053",
   "technique_ja": "スケジュールされたタスク/ジョブ",
   "technique_en": "Scheduled Task/Job",
   "analytic_id": "AN0261",
   "detection_strategy_id": "DET0094",
   "analytic_name": "Analytic 0261",
   "platforms": "Containers",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Modification (containerd:runtime)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル変更 (containerd:runtime)",
   "tuning": "ContainerLabel | ScriptFrequency | ImageSource",
   "detection_logic_en": "Detects unusual use of `cron` or `sleep` loops inside containers executing unfamiliar scripts or binaries repeatedly."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1053",
   "technique_ja": "スケジュールされたタスク/ジョブ",
   "technique_en": "Scheduled Task/Job",
   "analytic_id": "AN0262",
   "detection_strategy_id": "DET0094",
   "analytic_name": "Analytic 0262",
   "platforms": "ESXi",
   "log_sources": "Scheduled Job Creation (esxi:vmkernel) | Command Execution (esxi:hostd) | File Modification (esxi:cron)",
   "log_sources_ja": "スケジュールジョブ作成 (esxi:vmkernel) | コマンド実行 (esxi:hostd) | ファイル変更 (esxi:cron)",
   "tuning": "StartupScriptName | ExecutionContext | PersistenceInterval",
   "detection_logic_en": "Detects modification of ESXi cron jobs, local.sh scripts, or scheduled API calls to persist custom binaries or shell scripts."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1053.002",
   "technique_ja": "At",
   "technique_en": "At",
   "analytic_id": "AN0943",
   "detection_strategy_id": "DET0333",
   "analytic_name": "Analytic 0943",
   "platforms": "Windows",
   "log_sources": "Scheduled Job Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "スケジュールジョブ作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TaskUser | ExecutionTimeWindow | CommandLinePattern",
   "detection_logic_en": "Detects creation of scheduled tasks via `at.exe` or WMI `Win32_ScheduledJob` class, followed by execution of anomalous processes by svchost.exe or taskeng.exe."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1053.002",
   "technique_ja": "At",
   "technique_en": "At",
   "analytic_id": "AN0944",
   "detection_strategy_id": "DET0333",
   "analytic_name": "Analytic 0944",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Modification (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL)",
   "tuning": "AtJobPath | ScheduleLatency | JobScriptEntropy",
   "detection_logic_en": "Detects usage of `at` command to schedule jobs, followed by job execution and modification of job files under /var/spool/cron/atjobs."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1053.002",
   "technique_ja": "At",
   "technique_en": "At",
   "analytic_id": "AN0945",
   "detection_strategy_id": "DET0333",
   "analytic_name": "Analytic 0945",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Modification (fs:fsusage) | Process Creation (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル変更 (fs:fsusage) | プロセス生成 (macos:osquery)",
   "tuning": "AtPermissions | ExecutionCommand | RunUser",
   "detection_logic_en": "Detects user or root invocation of `at` command to schedule a job, followed by job execution using LaunchServices and activity in /usr/lib/cron/at."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1053.003",
   "technique_ja": "Cron",
   "technique_en": "Cron",
   "analytic_id": "AN0805",
   "detection_strategy_id": "DET0290",
   "analytic_name": "Analytic 0805",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "CronFilePath | RunUser | ExecutionFrequency",
   "detection_logic_en": "Detects creation or modification of crontab entries by non-root users or from abnormal parent processes, followed by the execution of uncommon binaries at scheduled intervals."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1053.003",
   "technique_ja": "Cron",
   "technique_en": "Cron",
   "analytic_id": "AN0806",
   "detection_strategy_id": "DET0290",
   "analytic_name": "Analytic 0806",
   "platforms": "macOS",
   "log_sources": "Scheduled Job Creation (macos:unifiedlog) | File Modification (fs:fsusage)",
   "log_sources_ja": "スケジュールジョブ作成 (macos:unifiedlog) | ファイル変更 (fs:fsusage)",
   "tuning": "ScriptPath | CronScheduleSyntax | InteractiveUserContext",
   "detection_logic_en": "Detects crontab job additions or modifications via `crontab` utility or direct edits, especially those created by interactive users executing hidden or renamed scripts."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1053.003",
   "technique_ja": "Cron",
   "technique_en": "Cron",
   "analytic_id": "AN0807",
   "detection_strategy_id": "DET0290",
   "analytic_name": "Analytic 0807",
   "platforms": "ESXi",
   "log_sources": "File Modification (esxi:hostd) | Scheduled Job Creation (esxi:cron) | Process Creation (esxi:vmkernel)",
   "log_sources_ja": "ファイル変更 (esxi:hostd) | スケジュールジョブ作成 (esxi:cron) | プロセス生成 (esxi:vmkernel)",
   "tuning": "CrontabFileMonitored | ShellCommandPayload | JobInterval",
   "detection_logic_en": "Detects direct modification of crontab entries in /var/spool/cron/crontabs/root or /etc/rc.local.d/local.sh followed by execution of scripts linked to lateral movement or malware persistence."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1053.005",
   "technique_ja": "スケジュールされたタスク",
   "technique_en": "Scheduled Task",
   "analytic_id": "AN1221",
   "detection_strategy_id": "DET0441",
   "analytic_name": "Analytic 1221",
   "platforms": "Windows",
   "log_sources": "Scheduled Job Creation (WinEventLog:Security) | Scheduled Job Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "スケジュールジョブ作成 (WinEventLog:Security) | スケジュールジョブ変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext | TaskNamePattern | CommandLineEntropyThreshold",
   "detection_logic_en": "Detects the creation, modification, or deletion of scheduled tasks through Task Scheduler, WMI, PowerShell, or API-based methods followed by execution from svchost.exe or taskeng.exe. Includes detection of hidden or anomalous scheduled tasks, especially those created under SYSTEM or suspicious user contexts."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1053.006",
   "technique_ja": "systemdタイマー",
   "technique_en": "Systemd Timers",
   "analytic_id": "AN0645",
   "detection_strategy_id": "DET0231",
   "analytic_name": "Analytic 0645",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Scheduled Job Creation (linux:osquery)",
   "log_sources_ja": "ファイル作成 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | スケジュールジョブ作成 (linux:osquery)",
   "tuning": "TimerIntervalThreshold | ParentProcessID | UserContext | TimerCreationPath",
   "detection_logic_en": "Detects adversarial abuse of systemd timers by correlating file creation/modification of .timer and .service units in system directories with the execution of abnormal child processes launched by 'systemd' (PID 1), especially as root."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1053.007",
   "technique_ja": "コンテナオーケストレーションジョブ",
   "technique_en": "Container Orchestration Job",
   "analytic_id": "AN0582",
   "detection_strategy_id": "DET0206",
   "analytic_name": "Analytic 0582",
   "platforms": "Containers",
   "log_sources": "Scheduled Job Creation (kubernetes:apiserver) | Container Creation (kubernetes:events) | Network Traffic Content (container:proxy)",
   "log_sources_ja": "スケジュールジョブ作成 (kubernetes:apiserver) | コンテナ作成 (kubernetes:events) | ネットワークトラフィック内容 (container:proxy)",
   "tuning": "NamespaceScope | ImageRepository | ScheduleWindow | ExecutionCommand",
   "detection_logic_en": "Detects abuse of container orchestration platforms (e.g., Kubernetes) where adversaries create CronJobs to maintain persistence or execute malicious Jobs across the cluster."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059",
   "technique_ja": "コマンド＆スクリプトインタプリタ",
   "technique_en": "Command and Scripting Interpreter",
   "analytic_id": "AN1428",
   "detection_strategy_id": "DET0516",
   "analytic_name": "Analytic 1428",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "CommandLinePattern | ParentProcessName | TimeWindow",
   "detection_logic_en": "Detects the execution of scripting or command interpreters (e.g., powershell.exe, cmd.exe, wscript.exe) outside expected administrative time windows or from abnormal user contexts, often followed by encoded/obfuscated arguments or secondary execution events."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059",
   "technique_ja": "コマンド＆スクリプトインタプリタ",
   "technique_en": "Command and Scripting Interpreter",
   "analytic_id": "AN1429",
   "detection_strategy_id": "DET0516",
   "analytic_name": "Analytic 1429",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL)",
   "tuning": "InterpreterName | UserContext | ExecutionChainLength",
   "detection_logic_en": "Detects use of shell interpreters (e.g., bash, sh, python, perl) initiated by users or processes not normally executing them, especially when chaining suspicious utilities like netcat, curl, or ssh."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059",
   "technique_ja": "コマンド＆スクリプトインタプリタ",
   "technique_en": "Command and Scripting Interpreter",
   "analytic_id": "AN1430",
   "detection_strategy_id": "DET0516",
   "analytic_name": "Analytic 1430",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog)",
   "tuning": "LaunchAgentName | ScriptName | TerminalAppUsage",
   "detection_logic_en": "Detects launch of command-line interpreters via Terminal, Automator, or hidden `osascript`, especially when parent process lineage deviates from user-initiated applications."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059",
   "technique_ja": "コマンド＆スクリプトインタプリタ",
   "technique_en": "Command and Scripting Interpreter",
   "analytic_id": "AN1431",
   "detection_strategy_id": "DET0516",
   "analytic_name": "Analytic 1431",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:vobd)",
   "log_sources_ja": "コマンド実行 (esxi:vobd)",
   "tuning": "ShellEnabledFlag | SSHContext",
   "detection_logic_en": "Detects use of 'esxcli system' or direct interpreter commands (e.g., busybox shell) invoked from SSH or host terminal unexpectedly."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059",
   "technique_ja": "コマンド＆スクリプトインタプリタ",
   "technique_en": "Command and Scripting Interpreter",
   "analytic_id": "AN1432",
   "detection_strategy_id": "DET0516",
   "analytic_name": "Analytic 1432",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:cli) | User Account Authentication (networkdevice:syslog)",
   "log_sources_ja": "コマンド実行 (networkdevice:cli) | ユーザーアカウント認証 (networkdevice:syslog)",
   "tuning": "UserRole | DeviceType",
   "detection_logic_en": "Identifies CLI interpreter access (e.g., Cisco IOS, Juniper JUNOS) via `enable` mode or scripting-capable sessions used by uncommon accounts or from unknown IPs."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.001",
   "technique_ja": "PowerShell",
   "technique_en": "PowerShell",
   "analytic_id": "AN1252",
   "detection_strategy_id": "DET0455",
   "analytic_name": "Analytic 1252",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | Process Metadata (WinEventLog:PowerShell) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | プロセスメタデータ (WinEventLog:PowerShell) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "CommandLinePattern | ParentProcessName | TimeWindow | LoadedModuleList | ScriptBlockLengthThreshold",
   "detection_logic_en": "Detects behavioral chains where PowerShell is launched with encoded commands, unusual parent processes, or suspicious modules loaded, potentially followed by network connections or child process spawning. Supports detection of both direct (powershell.exe) and indirect (.NET automation) invocations."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.002",
   "technique_ja": "AppleScript",
   "technique_en": "AppleScript",
   "analytic_id": "AN1164",
   "detection_strategy_id": "DET0414",
   "analytic_name": "Analytic 1164",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog)",
   "tuning": "ScriptInvocationParent | TimeWindow | AppleEventActionType | TargetApplicationSet | ExecutionPathRegex",
   "detection_logic_en": "Detects AppleScript execution via 'osascript', NSAppleScript/OSAScript APIs, and abnormal application control events across user sessions. Focuses on causal chains such as osascript spawning child processes, script-induced keystrokes, or API-backed dialog spoofing."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.003",
   "technique_ja": "Windowsコマンドシェル",
   "technique_en": "Windows Command Shell",
   "analytic_id": "AN0578",
   "detection_strategy_id": "DET0202",
   "analytic_name": "Analytic 0578",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Module Load (WinEventLog:Sysmon) | Script Execution (EDR:scriptblock)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon) | スクリプト実行 (EDR:scriptblock)",
   "tuning": "ParentProcessName | TimeWindow | CommandLinePattern | ScriptStoragePath | UserContext",
   "detection_logic_en": "Detects interactive or scripted abuse of cmd.exe, batch files, or shell invocation chains. Focuses on parent-child relationships (e.g., cmd.exe launched from unusual parents), anomalous command-line parameters, and chaining with discovery, credential access, or lateral movement behaviors."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.004",
   "technique_ja": "Unixシェル",
   "technique_en": "Unix Shell",
   "analytic_id": "AN1081",
   "detection_strategy_id": "DET0384",
   "analytic_name": "Analytic 1081",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Flow (linux:osquery) | Logon Session Creation (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィックフロー (linux:osquery) | ログオンセッション作成 (linux:syslog)",
   "tuning": "ExecutableName | UserContext | ParentProcess | TimeWindow | CommandLinePattern",
   "detection_logic_en": "Detects bash, sh, zsh, or BusyBox shell execution initiated via remote sessions, unauthorized users, or embedded within secondary script interpreters. Focus is on chained behavior: shell > suspicious commands > network discovery or persistence indicators."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.004",
   "technique_ja": "Unixシェル",
   "technique_en": "Unix Shell",
   "analytic_id": "AN1082",
   "detection_strategy_id": "DET0384",
   "analytic_name": "Analytic 1082",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Command Execution (macos:osquery) | Script Execution (macos:syslog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | コマンド実行 (macos:osquery) | スクリプト実行 (macos:syslog)",
   "tuning": "ScriptLocation | ParentProcess | UserRole",
   "detection_logic_en": "Identifies use of sh/bash/zsh in suspicious context, such as user scripts launched from non-standard apps (e.g., Preview.app), embedded in LaunchDaemons, or executed outside Terminal.app. Looks for misuse in Automator, LaunchAgents, or NSAppleScript-executed shell."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.004",
   "technique_ja": "Unixシェル",
   "technique_en": "Unix Shell",
   "analytic_id": "AN1083",
   "detection_strategy_id": "DET0384",
   "analytic_name": "Analytic 1083",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:vmkernel) | Logon Session Creation (esxi:auth)",
   "log_sources_ja": "コマンド実行 (esxi:vmkernel) | ログオンセッション作成 (esxi:auth)",
   "tuning": "UserContext | CommandPattern | ShellPath",
   "detection_logic_en": "Detects BusyBox or Ash shell execution from unauthorized logins or remote connections. Focus is on rare shell invocations from DCUI, SSH sessions, or remote management paths. Also watches for payload droppers or persistence artifacts using shell."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.004",
   "technique_ja": "Unixシェル",
   "technique_en": "Unix Shell",
   "analytic_id": "AN1084",
   "detection_strategy_id": "DET0384",
   "analytic_name": "Analytic 1084",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:syslog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (networkdevice:syslog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "Interface | CommandString",
   "detection_logic_en": "Detects Unix shell usage on network appliances (e.g., routers, firewalls, embedded Linux) through rare console commands, CLI interfaces, or script injection via exposed APIs or SSH."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.005",
   "technique_ja": "Visual Basic",
   "technique_en": "Visual Basic",
   "analytic_id": "AN0209",
   "detection_strategy_id": "DET0076",
   "analytic_name": "Analytic 0209",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "ParentProcess | UserContext | TimeWindow | PayloadEntropyThreshold | ModuleName",
   "detection_logic_en": "Detects execution of VB-based scripts or macros (VBS/VBA/VBScript) through cscript.exe/wscript.exe, Office-based process chains, or HTA usage. Focuses on chained behavior: Office or HTML container spawns script host > script host spawns PowerShell, network connections, or process injection."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.005",
   "technique_ja": "Visual Basic",
   "technique_en": "Visual Basic",
   "analytic_id": "AN0210",
   "detection_strategy_id": "DET0076",
   "analytic_name": "Analytic 0210",
   "platforms": "macOS",
   "log_sources": "Script Execution (macos:unifiedlog) | Process Creation (macos:osquery) | Command Execution (macos:syslog)",
   "log_sources_ja": "スクリプト実行 (macos:unifiedlog) | プロセス生成 (macos:osquery) | コマンド実行 (macos:syslog)",
   "tuning": "ScriptLocation | EmulationContext | UserContext",
   "detection_logic_en": "Detects embedded or emulated VBScript/VBA execution via Wine-based apps, Office for Mac abusing cross-platform .NET features, or macros dropped and invoked via AppleScript or third-party automation tools."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.005",
   "technique_ja": "Visual Basic",
   "technique_en": "Visual Basic",
   "analytic_id": "AN0211",
   "detection_strategy_id": "DET0076",
   "analytic_name": "Analytic 0211",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Script Execution (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | スクリプト実行 (linux:syslog)",
   "tuning": "InterpreterPath | FileExtension | ExecContext",
   "detection_logic_en": "Detects abuse of Mono/.NET Core environments to execute VB-like scripts, often in environments with Office emulation or WINE. Focus is on rare invocations of scripting hosts like mono.exe or .NET shells, often seen in spam filtering or forensic labs with Office support."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.006",
   "technique_ja": "Python",
   "technique_en": "Python",
   "analytic_id": "AN0172",
   "detection_strategy_id": "DET0063",
   "analytic_name": "Analytic 0172",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Traffic Content (EDR:hunting)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (EDR:hunting)",
   "tuning": "ParentProcess | ScriptPath | TimeWindow | UserContext | ChildProcess",
   "detection_logic_en": "Detects Python execution via python.exe or py.exe with anomalous parent lineage (e.g., Office macros, LOLBAS), execution from unusual directories, or chained network/PowerShell/system-level activity."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.006",
   "technique_ja": "Python",
   "technique_en": "Python",
   "analytic_id": "AN0173",
   "detection_strategy_id": "DET0063",
   "analytic_name": "Analytic 0173",
   "platforms": "macOS",
   "log_sources": "Script Execution (macos:unifiedlog) | Process Creation (macos:osquery) | Command Execution (macos:syslog)",
   "log_sources_ja": "スクリプト実行 (macos:unifiedlog) | プロセス生成 (macos:osquery) | コマンド実行 (macos:syslog)",
   "tuning": "ExecutionPath | ScriptName | SpawnChain",
   "detection_logic_en": "Detects native Python or framework-based execution from Terminal, embedded apps, or launchd jobs. Flags network calls, persistence writes, or system enumeration after Python launch."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.006",
   "technique_ja": "Python",
   "technique_en": "Python",
   "analytic_id": "AN0174",
   "detection_strategy_id": "DET0063",
   "analytic_name": "Analytic 0174",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Script Execution (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | スクリプト実行 (linux:syslog)",
   "tuning": "ScriptDir | ScheduledContext | NetworkActivity",
   "detection_logic_en": "Detects Python execution from non-standard user contexts or cron jobs that invoke outbound traffic, access sensitive files, or perform process injection (e.g., ptrace or /proc memory maps)."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.006",
   "technique_ja": "Python",
   "technique_en": "Python",
   "analytic_id": "AN0175",
   "detection_strategy_id": "DET0063",
   "analytic_name": "Analytic 0175",
   "platforms": "ESXi",
   "log_sources": "Process Creation (esxi:vobd) | Command Execution (esxi:hostd)",
   "log_sources_ja": "プロセス生成 (esxi:vobd) | コマンド実行 (esxi:hostd)",
   "tuning": "ExecutionSource | HostUser | InstallPath",
   "detection_logic_en": "Detects Python script or interpreter execution on ESXi hosts via embedded BusyBox shells, nested installations, or dropped files via SSH or datastore mount. Flags unusual scripting or post-compromise enumeration behavior."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.007",
   "technique_ja": "JavaScript",
   "technique_en": "JavaScript",
   "analytic_id": "AN0733",
   "detection_strategy_id": "DET0264",
   "analytic_name": "Analytic 0733",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Script Execution (m365:defender) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | スクリプト実行 (m365:defender) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "ParentProcess | ScriptPath | TimeWindow | UserContext | EntropyScore",
   "detection_logic_en": "Detects JavaScript execution through WSH (wscript.exe, cscript.exe) or HTA (mshta.exe), particularly when spawned from Office macros, web browsers, or abnormal user paths. Correlates script execution with outbound network activity or system modification."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.007",
   "technique_ja": "JavaScript",
   "technique_en": "JavaScript",
   "analytic_id": "AN0734",
   "detection_strategy_id": "DET0264",
   "analytic_name": "Analytic 0734",
   "platforms": "macOS",
   "log_sources": "Script Execution (macos:unifiedlog) | Process Creation (macos:osquery) | Command Execution (macos:syslog)",
   "log_sources_ja": "スクリプト実行 (macos:unifiedlog) | プロセス生成 (macos:osquery) | コマンド実行 (macos:syslog)",
   "tuning": "ScriptLocation | ParentProcess | APIInvocation",
   "detection_logic_en": "Detects JavaScript for Automation (JXA) via osascript or compiled scripts using OSAKit APIs. Flags execution involving system modification, inter-process scripting, or browser abuse."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.007",
   "technique_ja": "JavaScript",
   "technique_en": "JavaScript",
   "analytic_id": "AN0735",
   "detection_strategy_id": "DET0264",
   "analytic_name": "Analytic 0735",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Script Execution (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | スクリプト実行 (linux:syslog)",
   "tuning": "ScriptPath | BinaryName | UserExecutionContext | NetworkFollowUp",
   "detection_logic_en": "Detects Node.js or JavaScript interpreter execution from web shells, cron jobs, or local users. Correlates execution with reverse shell behavior, file modifications, or abnormal outbound connections."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.008",
   "technique_ja": "ネットワークデバイスCLI",
   "technique_en": "Network Device CLI",
   "analytic_id": "AN0399",
   "detection_strategy_id": "DET0142",
   "analytic_name": "Analytic 0399",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:syslog) | Network Traffic Content (NSM:Flow) | User Account Authentication (networkdevice:syslog)",
   "log_sources_ja": "コマンド実行 (networkdevice:syslog) | ネットワークトラフィック内容 (NSM:Flow) | ユーザーアカウント認証 (networkdevice:syslog)",
   "tuning": "TimeWindow | UserContext | CommandPattern | SourceIP | SessionDuration",
   "detection_logic_en": "Detects unauthorized or anomalous use of command-line interfaces (CLI) on network devices. Focuses on remote access sessions (e.g., SSH/Telnet), privilege escalation within CLI sessions, execution of high-risk commands (e.g., config replace, terminal monitor, no logging), and configuration changes outside of approved windows."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.009",
   "technique_ja": "クラウドAPI",
   "technique_en": "Cloud API",
   "analytic_id": "AN0215",
   "detection_strategy_id": "DET0078",
   "analytic_name": "Analytic 0215",
   "platforms": "IaaS",
   "log_sources": "Command Execution (AWS:CloudTrail) | Cloud Service Modification (azure:activity) | User Account Authentication (Okta:SystemLog)",
   "log_sources_ja": "コマンド実行 (AWS:CloudTrail) | クラウドサービス変更 (azure:activity) | ユーザーアカウント認証 (Okta:SystemLog)",
   "tuning": "TimeWindow | UserAgent | CredentialType | APISequence | ConsoleContext",
   "detection_logic_en": "Detects adversarial use of cloud APIs for command execution, resource control, or reconnaissance. Focuses on CLI/SDK/scripting language abuse via stolen credentials or in-browser Cloud Shells. Monitors for anomalous API calls chained with authentication context shifts (e.g., stolen token -> privileged action) and cross-service impacts."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.010",
   "technique_ja": "AutoHotKey & AutoIT",
   "technique_en": "AutoHotKey & AutoIT",
   "analytic_id": "AN0942",
   "detection_strategy_id": "DET0332",
   "analytic_name": "Analytic 0942",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | ParentProcessName | ScriptExtension | ChildProcessCount",
   "detection_logic_en": "Detects execution of AutoHotKey or AutoIT interpreters or compiled scripts used for unauthorized automation, command execution, or payload delivery, correlated with anomalous process lineage, command-line arguments, or script creation events."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.011",
   "technique_ja": "Lua",
   "technique_en": "Lua",
   "analytic_id": "AN0278",
   "detection_strategy_id": "DET0101",
   "analytic_name": "Analytic 0278",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "ParentProcessName | TimeWindow",
   "detection_logic_en": "Detects execution of Lua interpreters or scripts (.lua), especially when correlated with suspicious parent processes or file drop events, indicating malicious use of embedded scripting."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.011",
   "technique_ja": "Lua",
   "technique_en": "Lua",
   "analytic_id": "AN0279",
   "detection_strategy_id": "DET0101",
   "analytic_name": "Analytic 0279",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Metadata (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルメタデータ (auditd:SYSCALL)",
   "tuning": "ExecutablePath | UserContext",
   "detection_logic_en": "Detects invocation of lua or luajit interpreters by users or services outside of expected packages, chained with script drop or memory artifacts."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.011",
   "technique_ja": "Lua",
   "technique_en": "Lua",
   "analytic_id": "AN0280",
   "detection_strategy_id": "DET0101",
   "analytic_name": "Analytic 0280",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog)",
   "tuning": "ParentProcessName | SignatureStatus",
   "detection_logic_en": "Detects Lua script execution via native or 3rd party interpreters, chained with unsigned binaries or unexpected parent lineage."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.011",
   "technique_ja": "Lua",
   "technique_en": "Lua",
   "analytic_id": "AN0281",
   "detection_strategy_id": "DET0101",
   "analytic_name": "Analytic 0281",
   "platforms": "Network Devices",
   "log_sources": "Script Execution (networkdevice:runtime)",
   "log_sources_ja": "スクリプト実行 (networkdevice:runtime)",
   "tuning": "FirmwareBuildHash | ScriptInjectionPath",
   "detection_logic_en": "Detects embedded Lua interpreter execution or script injection on devices supporting Lua scripting (e.g., routers, firewalls), often seen in modified firmware or abused APIs."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.012",
   "technique_ja": "ハイパーバイザCLI",
   "technique_en": "Hypervisor CLI",
   "analytic_id": "AN1537",
   "detection_strategy_id": "DET0558",
   "analytic_name": "Analytic 1537",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:vmkernel) | User Account Authentication (esxi:auth)",
   "log_sources_ja": "コマンド実行 (esxi:vmkernel) | ユーザーアカウント認証 (esxi:auth)",
   "tuning": "TimeWindow | UserContext | CommandPattern",
   "detection_logic_en": "Detects suspicious use of ESXi native CLI tools like esxcli and vim-cmd by unauthorized users or outside expected maintenance windows. Focus is on actions such as stopping VMs, reconfiguring network/firewall settings, and enabling SSH or logging."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1059.013",
   "technique_ja": "コンテナCLI/API",
   "technique_en": "Container CLI/API",
   "analytic_id": "AN0233",
   "detection_strategy_id": "DET0083",
   "analytic_name": "Analytic 0233",
   "platforms": "Containers",
   "log_sources": "Process Creation (auditd:SYSCALL) | Container Start (docker:events) | Container Creation (kubernetes:apiserver) | Pod Creation (AWS:CloudTrail) | Command Execution (kubernetes:audit)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | コンテナ起動 (docker:events) | コンテナ作成 (kubernetes:apiserver) | Pod作成 (AWS:CloudTrail) | コマンド実行 (kubernetes:audit)",
   "tuning": "AuthorizedUserAgents | NewImageThreshold | TimeWindow | InteractiveSessionExpectation",
   "detection_logic_en": "Execution of container orchestration commands (e.g., `docker exec`, `kubectl exec`) or API-driven interactions with running containers from unauthorized hosts or non-standard user contexts. Defender sees programmatic or interactive command execution within containers outside expected CI/CD tools or automation frameworks, often followed by file writes, privilege escalation, or lateral discovery."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1072",
   "technique_ja": "ソフトウェア展開ツール",
   "technique_en": "Software Deployment Tools",
   "analytic_id": "AN0623",
   "detection_strategy_id": "DET0223",
   "analytic_name": "Analytic 0623",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Application Log Content (WinEventLog:Application)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | アプリケーションログ内容 (WinEventLog:Application)",
   "tuning": "ParentImageList | UserContext | TimeWindow",
   "detection_logic_en": "Detects SCCM, Intune, or remote push execution spawning scripts or binaries from SYSTEM context or unusual consoles (e.g., cmtrace.exe launching PowerShell or cmd.exe)."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1072",
   "technique_ja": "ソフトウェア展開ツール",
   "technique_en": "Software Deployment Tools",
   "analytic_id": "AN0624",
   "detection_strategy_id": "DET0223",
   "analytic_name": "Analytic 0624",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL)",
   "tuning": "DeployingHostAllowList | ScriptExecutionBaseline",
   "detection_logic_en": "Detects remote scripts or binaries deployed via Puppet, Chef, Ansible, or shell scripts from orchestration servers executing outside maintenance windows or in unmanaged nodes."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1072",
   "technique_ja": "ソフトウェア展開ツール",
   "technique_en": "Software Deployment Tools",
   "analytic_id": "AN0625",
   "detection_strategy_id": "DET0223",
   "analytic_name": "Analytic 0625",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Application Log Content (macos:jamf)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | アプリケーションログ内容 (macos:jamf)",
   "tuning": "SigningAuthorityList | RemoteCommandInterval",
   "detection_logic_en": "Detects script or binary execution initiated via JAMF, Munki, or custom MDM agents outside of baseline, or JAMF launching new Terminal or osascript processes from remote command payloads."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1072",
   "technique_ja": "ソフトウェア展開ツール",
   "technique_en": "Software Deployment Tools",
   "analytic_id": "AN0626",
   "detection_strategy_id": "DET0223",
   "analytic_name": "Analytic 0626",
   "platforms": "SaaS",
   "log_sources": "Command Execution (AWS:CloudTrail)",
   "log_sources_ja": "コマンド実行 (AWS:CloudTrail)",
   "tuning": "IAMRoleAllowList | ExecutionTargetList",
   "detection_logic_en": "Detects cloud-native software deployment or management (e.g., SSM Run Command, Intune) initiating script execution on endpoints outside expected org IDs, admin groups, or maintenance windows."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1072",
   "technique_ja": "ソフトウェア展開ツール",
   "technique_en": "Software Deployment Tools",
   "analytic_id": "AN0627",
   "detection_strategy_id": "DET0223",
   "analytic_name": "Analytic 0627",
   "platforms": "Network Devices",
   "log_sources": "Application Log Content (networkdevice:syslog) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (networkdevice:syslog) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "PushSourceAllowList | AuthUserPattern",
   "detection_logic_en": "Detects central router or switch config management tools (e.g., FortiManager, Cisco Prime) triggering device reboots or config pushes using abnormal accounts or IPs."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1106",
   "technique_ja": "ネイティブAPI",
   "technique_en": "Native API",
   "analytic_id": "AN1465",
   "detection_strategy_id": "DET0529",
   "analytic_name": "Analytic 1465",
   "platforms": "Windows",
   "log_sources": "Module Load (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "モジュール読み込み (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "DllName | Image | TargetProcess",
   "detection_logic_en": "Unusual or suspicious processes loading critical native API DLLs (e.g., ntdll.dll, kernel32.dll) followed by direct syscall behavior, memory manipulation, or hollowing."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1106",
   "technique_ja": "ネイティブAPI",
   "technique_en": "Native API",
   "analytic_id": "AN1466",
   "detection_strategy_id": "DET0529",
   "analytic_name": "Analytic 1466",
   "platforms": "Linux",
   "log_sources": "Process Access (auditd:SYSCALL) | Module Load (auditd:SYSCALL)",
   "log_sources_ja": "プロセスアクセス (auditd:SYSCALL) | モジュール読み込み (auditd:SYSCALL)",
   "tuning": "SyscallType | ProcessName | MAPS Path",
   "detection_logic_en": "Userland processes invoking syscall-heavy libraries (libc, glibc) followed by fork, mmap, or ptrace behavior commonly associated with code injection or memory manipulation."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1106",
   "technique_ja": "ネイティブAPI",
   "technique_en": "Native API",
   "analytic_id": "AN1467",
   "detection_strategy_id": "DET0529",
   "analytic_name": "Analytic 1467",
   "platforms": "macOS",
   "log_sources": "Module Load (macos:unifiedlog) | Process Creation (macos:endpointsecurity)",
   "log_sources_ja": "モジュール読み込み (macos:unifiedlog) | プロセス生成 (macos:endpointsecurity)",
   "tuning": "API Framework Name | Execution Context",
   "detection_logic_en": "Execution of processes that link to CoreServices or Foundation APIs followed by creation of memory regions, code execution, or abnormal library injection."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1127",
   "technique_ja": "信頼された開発ツールによるプロキシ実行",
   "technique_en": "Trusted Developer Utilities Proxy Execution",
   "analytic_id": "AN0488",
   "detection_strategy_id": "DET0172",
   "analytic_name": "Analytic 0488",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Process Metadata (WinEventLog:AppLocker)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | プロセスメタデータ (WinEventLog:AppLocker)",
   "tuning": "TimeWindow | AllowedUtilitiesList | DeveloperHosts | SuspiciousChildList | RarePathRegex | UnsignedOrInvalidSignatureOnly | ParentProcessAllowList | NetworkReputationThreshold",
   "detection_logic_en": "A trusted/signed developer utility (parent) is executed in a non-developer context and (a) spawns suspicious children (e.g., powershell.exe, cmd.exe, rundll32.exe, regsvr32.exe, wscript.exe), (b) loads unsigned/user-writable DLLs, (c) writes and then runs a new PE from user-writable paths, and/or (d) immediately makes outbound network connections."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1127.001",
   "technique_ja": "MSBuild",
   "technique_en": "MSBuild",
   "analytic_id": "AN1535",
   "detection_strategy_id": "DET0556",
   "analytic_name": "Analytic 1535",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Process Modification (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Process Metadata (WinEventLog:Microsoft-Windows-CodeIntegrity/Operational) | Script Execution (EDR:AMSI)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス変更 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | プロセスメタデータ (WinEventLog:Microsoft-Windows-CodeIntegrity/Operational) | スクリプト実行 (EDR:AMSI)",
   "tuning": "TimeWindow | DeveloperHosts | SuspiciousChildList | RarePathRegex | UnsignedOrInvalidSignatureOnly | NetworkReputationThreshold | BehaviorRiskScoreThreshold",
   "detection_logic_en": "MSBuild.exe is invoked outside expected developer/build contexts or with anomalous arguments (e.g., non-canonical paths, remote shares, Base64/obfuscated property values). Within a short window, it (a) spawns high-risk LOLBins/script interpreters, (b) writes new PE/DLL/script artifacts into user-writable paths and executes them, (c) loads unsigned/user-writable modules, (d) performs memory injection/thread creation into other processes, and/or (e) initiates outbound network connections."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1127.002",
   "technique_ja": "ClickOnce",
   "technique_en": "ClickOnce",
   "analytic_id": "AN0550",
   "detection_strategy_id": "DET0191",
   "analytic_name": "Analytic 0550",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Module Load (WinEventLog:Sysmon) | Process Metadata (WinEventLog:Microsoft-Windows-Security-Mitigations/KernelMode)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon) | プロセスメタデータ (WinEventLog:Microsoft-Windows-Security-Mitigations/KernelMode)",
   "tuning": "TimeWindow | KnownClickOnceApps | SuspiciousChildList",
   "detection_logic_en": "Abuse of ClickOnce applications where rundll32.exe invokes dfshim.dll with ShOpenVerbApplication or dfsvc.exe spawns unexpected child processes or loads unsigned modules."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1127.003",
   "technique_ja": "JamPlus",
   "technique_en": "JamPlus",
   "analytic_id": "AN1610",
   "detection_strategy_id": "DET0585",
   "analytic_name": "Analytic 1610",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Process Metadata (WinEventLog:Microsoft-Windows-CodeIntegrity/Operational)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | プロセスメタデータ (WinEventLog:Microsoft-Windows-CodeIntegrity/Operational)",
   "tuning": "TimeWindow | AllowedBuildHosts | SuspiciousChildList | RarePathRegex",
   "detection_logic_en": "Abuse of JamPlus.exe to launch malicious payloads via crafted .jam files, resulting in abnormal process creation, command execution, or artifact generation outside of standard development workflows."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1129",
   "technique_ja": "共有モジュール",
   "technique_en": "Shared Modules",
   "analytic_id": "AN0052",
   "detection_strategy_id": "DET0018",
   "analytic_name": "Analytic 0052",
   "platforms": "Windows",
   "log_sources": "Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | Process Metadata (WinEventLog:Microsoft-Windows-CodeIntegrity/Operational)",
   "log_sources_ja": "モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | プロセスメタデータ (WinEventLog:Microsoft-Windows-CodeIntegrity/Operational)",
   "tuning": "TimeWindow | SuspiciousPathRegex | UnsignedOnly | RareSignerThreshold | MinFileSizeKB",
   "detection_logic_en": "A process (often LOLBin or user-launched program) loads a DLL from a user-writable/UNC/Temp path or unsigned/invalid signer. Within a short window the DLL is (a) newly written to disk, (b) spawned as follow-on execution (rundll32/regsvr32), or (c) establishes outbound C2."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1129",
   "technique_ja": "共有モジュール",
   "technique_en": "Shared Modules",
   "analytic_id": "AN0053",
   "detection_strategy_id": "DET0018",
   "analytic_name": "Analytic 0053",
   "platforms": "Linux",
   "log_sources": "Module Load (auditd:SYSCALL) | Process Creation (auditd:EXECVE) | Process Metadata (linux:syslog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "モジュール読み込み (auditd:SYSCALL) | プロセス生成 (auditd:EXECVE) | プロセスメタデータ (linux:syslog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "SuspiciousDirs | TimeWindow | EnvVarWatchlist | AllowedSigning/HashList",
   "detection_logic_en": "A process loads a shared object (.so) via dlopen/LD_PRELOAD/open from non-standard or temporary locations (e.g., /tmp, /dev/shm), especially shortly after that .so is written or fetched, or linked via manipulated environment variables (LD_PRELOAD/LD_LIBRARY_PATH)."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1129",
   "technique_ja": "共有モジュール",
   "technique_en": "Shared Modules",
   "analytic_id": "AN0054",
   "detection_strategy_id": "DET0018",
   "analytic_name": "Analytic 0054",
   "platforms": "macOS",
   "log_sources": "Module Load (macos:unifiedlog) | Process Creation (macos:endpointsecurity) | File Access (macos:endpointsecurity)",
   "log_sources_ja": "モジュール読み込み (macos:unifiedlog) | プロセス生成 (macos:endpointsecurity) | ファイルアクセス (macos:endpointsecurity)",
   "tuning": "SuspiciousDirs | UnsignedOnly | TimeWindow",
   "detection_logic_en": "A process loads a non-system .dylib/.so via dyld (dlopen/dlsym) from user-writable locations (~/Library, /tmp) or after the library was recently created/downloaded, often followed by network egress or persistence."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1197",
   "technique_ja": "BITSジョブ",
   "technique_en": "BITS Jobs",
   "analytic_id": "AN0274",
   "detection_strategy_id": "DET0098",
   "analytic_name": "Analytic 0274",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | Service Creation (WinEventLog:System)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | サービス作成 (WinEventLog:System)",
   "tuning": "TimeWindow | ExpectedUpdateHosts | SuspiciousCliSwitches | NotifyCmdBlockList | UserContext | ExternalNetCIDRs | JobLifetimeThreshold",
   "detection_logic_en": "Behavioral chain: (1) An actor creates or modifies a BITS job via bitsadmin.exe, PowerShell BITS cmdlets, or COM; (2) the job performs HTTP(S)/SMB network transfers while the owning user is logged on; (3) upon job completion/error, BITS launches a notify command (SetNotifyCmdLine) from svchost.exe -k netsvcs -s BITS, often establishing persistence by keeping long-lived jobs. The strategy correlates process creation, command/script telemetry, BITS-Client operational events, and network connections initiated by BITS."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1203",
   "technique_ja": "クライアント実行のための脆弱性悪用",
   "technique_en": "Exploitation for Client Execution",
   "analytic_id": "AN0797",
   "detection_strategy_id": "DET0287",
   "analytic_name": "Analytic 0797",
   "platforms": "Windows",
   "log_sources": "Application Log Content (WinEventLog:Application) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "アプリケーションログ内容 (WinEventLog:Application) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | HighRiskChildren | UserPaths | AllowedPlugins | EgressAllowlist",
   "detection_logic_en": "Cause→effect chain: (1) A client app (browser, Office, PDF/Flash/reader) experiences a crash/abnormal exit or loads from an unusual location, then (2) drops or modifies a file in user-writable paths, and/or (3) spawns an unexpected child (e.g., powershell/cmd/mshta/rundll32/wscript/installer), and (4) establishes outbound C2-like connections shortly after. Correlate application logs, file writes, process lineage, and network egress within a short window."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1203",
   "technique_ja": "クライアント実行のための脆弱性悪用",
   "technique_en": "Exploitation for Client Execution",
   "analytic_id": "AN0798",
   "detection_strategy_id": "DET0287",
   "analytic_name": "Analytic 0798",
   "platforms": "Linux",
   "log_sources": "Application Log Content (linux:syslog) | File Access (auditd:SYSCALL) | File Creation (auditd:SYSCALL) | File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Network Traffic Flow (NetFlow:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (linux:syslog) | ファイルアクセス (auditd:SYSCALL) | ファイル作成 (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | ネットワークトラフィックフロー (NetFlow:Flow)",
   "tuning": "TimeWindow | UserPaths | HighRiskChildren | PackageUpdaters",
   "detection_logic_en": "Cause→effect chain: (1) Browser/Office/reader process logs crash/segfault or abnormal sandbox message, (2) new executable/script/write occurs in $HOME (Downloads, ~/.cache, /tmp), (3) unexpected child like curl/wget/bash/python opens network connections soon after."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1203",
   "technique_ja": "クライアント実行のための脆弱性悪用",
   "technique_en": "Exploitation for Client Execution",
   "analytic_id": "AN0799",
   "detection_strategy_id": "DET0287",
   "analytic_name": "Analytic 0799",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | File Modification (fs:fsevents) | Process Creation (macos:osquery) | Network Traffic Flow (NSM:Connections)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | ファイル変更 (fs:fsevents) | プロセス生成 (macos:osquery) | ネットワークトラフィックフロー (NSM:Connections)",
   "tuning": "TimeWindow | HighRiskChildren | UserPaths | QuarantineBypass",
   "detection_logic_en": "Cause→effect chain: (1) App crash/abnormal termination in unified logs for Safari/Chrome/Office/Preview, (2) new files/scripts in ~/Library, ~/Downloads, /private/var/folders/*, (3) unexpected child (osascript, zsh, bash, curl) spawned by those apps, (4) new outbound connections."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204",
   "technique_ja": "ユーザー実行",
   "technique_en": "User Execution",
   "analytic_id": "AN1314",
   "detection_strategy_id": "DET0478",
   "analytic_name": "Analytic 1314",
   "platforms": "Windows",
   "log_sources": "Application Log Content (WinEventLog:Application) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "アプリケーションログ内容 (WinEventLog:Application) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | HighRiskParents | HighRiskChildren | UserPaths | EgressAllowList",
   "detection_logic_en": "Cause→effect chain: (1) User-facing app (Office/PDF/archiver/browser) records an open/click or abnormal event, then (2) a downloaded file is created in a user-writable path and/or decompressed, (3) the parent user app spawns a living-off-the-land binary (e.g., powershell/cmd/mshta/rundll32/msiexec/wscript/expand/zip) or installer, and (4) immediate outbound HTTP(S)/DNS/SMB from the same lineage."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204",
   "technique_ja": "ユーザー実行",
   "technique_en": "User Execution",
   "analytic_id": "AN1315",
   "detection_strategy_id": "DET0478",
   "analytic_name": "Analytic 1315",
   "platforms": "Linux",
   "log_sources": "Application Log Content (linux:syslog) | File Access (auditd:SYSCALL) | File Creation (auditd:SYSCALL) | File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (linux:syslog) | ファイルアクセス (auditd:SYSCALL) | ファイル作成 (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "TimeWindow | UserPaths | HighRiskChildren | PkgUpdaters",
   "detection_logic_en": "Cause→effect chain: (1) User app/browser/archiver logs an open/click or abnormal exit, (2) new executable/script/archive extracted into $HOME/Downloads, /tmp, or ~/.cache, (3) parent app spawns shell/interpreter (bash/sh/python/node/curl/wget) or desktop file, and (4) new outbound connection(s) from the child lineage."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204",
   "technique_ja": "ユーザー実行",
   "technique_en": "User Execution",
   "analytic_id": "AN1316",
   "detection_strategy_id": "DET0478",
   "analytic_name": "Analytic 1316",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | File Creation (fs:fileevents) | Process Creation (macos:osquery) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | ファイル作成 (fs:fileevents) | プロセス生成 (macos:osquery) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "TimeWindow | HighRiskChildren | QuarantineSignals",
   "detection_logic_en": "Cause→effect chain: (1) unified logs show application open/click or crash for Safari/Chrome/Office/Preview/archiver, (2) file write/extraction into ~/Downloads, /private/var/folders/* or ~/Library, (3) parent app spawns osascript/bash/zsh/curl/python or opens a quarantined app with Gatekeeper prompts, (4) network egress from child."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204",
   "technique_ja": "ユーザー実行",
   "technique_en": "User Execution",
   "analytic_id": "AN1317",
   "detection_strategy_id": "DET0478",
   "analytic_name": "Analytic 1317",
   "platforms": "Containers",
   "log_sources": "Container Creation (docker:events) | Container Start (docker:events) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "コンテナ作成 (docker:events) | コンテナ起動 (docker:events) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TrustedRegistries | AllowedEntrypoints | TimeWindow",
   "detection_logic_en": "Cause→effect chain in CI/dev desktops: (1) user triggers container run/pull after opening a doc/link/script, (2) newly created image/container uses unexpected external registry or entrypoint, (3) container starts and immediately egresses to suspicious destinations."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204",
   "technique_ja": "ユーザー実行",
   "technique_en": "User Execution",
   "analytic_id": "AN1318",
   "detection_strategy_id": "DET0478",
   "analytic_name": "Analytic 1318",
   "platforms": "IaaS",
   "log_sources": "Instance Creation (AWS:CloudTrail) | Instance Start (AWS:CloudTrail) | Network Traffic Content (gcp:vpcflow)",
   "log_sources_ja": "インスタンス作成 (AWS:CloudTrail) | インスタンス起動 (AWS:CloudTrail) | ネットワークトラフィック内容 (gcp:vpcflow)",
   "tuning": "ApprovedImages | UserContext | TimeWindow",
   "detection_logic_en": "Cause→effect chain in cloud consoles: (1) user clicks link then invokes instance/image creation via API, (2) instance/image originates from external AMI or unknown image, (3) instance immediately egresses or retrieves payloads."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204.001",
   "technique_ja": "悪意あるリンク",
   "technique_en": "Malicious Link",
   "analytic_id": "AN0178",
   "detection_strategy_id": "DET0066",
   "analytic_name": "Analytic 0178",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TimeWindow | BrowserParents | UserPaths | SuspiciousTLDs | AllowedCDNs",
   "detection_logic_en": "Behavioral chain: (1) a user-facing app (browser/Office/email client) launches a URL or handles a link, then (2) the same process lineage makes an outbound connection to an untrusted domain/IP, (3) a file is downloaded or unpacked to a user-writable location shortly after the click. Optional enrichment: subsequent child execution by LOLBINs."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204.001",
   "technique_ja": "悪意あるリンク",
   "technique_en": "Malicious Link",
   "analytic_id": "AN0179",
   "detection_strategy_id": "DET0066",
   "analytic_name": "Analytic 0179",
   "platforms": "Linux",
   "log_sources": "Network Connection Creation (auditd:SYSCALL) | File Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (auditd:SYSCALL) | ファイル作成 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TimeWindow | UserPaths | HighRiskExtensions | DomainRiskScore",
   "detection_logic_en": "Behavioral chain: (1) browser/office/GUI mail client opens a URL, (2) outbound connection to untrusted domain, (3) a new file is saved in $HOME/Downloads, /tmp, or cache immediately after."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204.001",
   "technique_ja": "悪意あるリンク",
   "technique_en": "Malicious Link",
   "analytic_id": "AN0180",
   "detection_strategy_id": "DET0066",
   "analytic_name": "Analytic 0180",
   "platforms": "macOS",
   "log_sources": "Network Traffic Content (macos:unifiedlog) | Network Connection Creation (NSM:Connections) | File Creation (fs:fsevents)",
   "log_sources_ja": "ネットワークトラフィック内容 (macos:unifiedlog) | ネットワーク接続確立 (NSM:Connections) | ファイル作成 (fs:fsevents)",
   "tuning": "TimeWindow | QuarantinePolicy | SuspiciousTLDs",
   "detection_logic_en": "Behavioral chain: (1) Safari/Chrome/Firefox/Office handles a URL; unified logs show open/click or LSQuarantine assignment, (2) outbound connection to untrusted domain, (3) a new file appears in ~/Downloads or /private/var/folders/* with quarantine flag."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204.002",
   "technique_ja": "悪意あるファイル",
   "technique_en": "Malicious File",
   "analytic_id": "AN0819",
   "detection_strategy_id": "DET0294",
   "analytic_name": "Analytic 0819",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | SuspiciousExtensions | UserPaths | ParentApps | SignerAllowList",
   "detection_logic_en": "User opens a file delivered by email, web, chat, or share. The handler application (Word/PDF reader/archiver) creates a file in user-controlled paths (Downloads, Temp, Desktop) and then spawns a new or unusual child process (e.g., powershell.exe, wscript.exe, cmd.exe, regsvr32.exe, rundll32.exe, msiexec.exe). Optional precursors include FileStreamCreated (URL/UNC) and Office → system32 batch writes."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204.002",
   "technique_ja": "悪意あるファイル",
   "technique_en": "Malicious File",
   "analytic_id": "AN0820",
   "detection_strategy_id": "DET0294",
   "analytic_name": "Analytic 0820",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (macos:endpointsecurity)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:endpointsecurity)",
   "tuning": "TimeWindow | QuarantineRequired | ParentApps",
   "detection_logic_en": "User opens a downloaded document/installer leading to EndpointSecurity file create in ~/Downloads or ~/Library paths then an exec of a suspicious utility (osascript, bash/zsh, curl, chmod, open with -a Terminal). Correlates File Creation with subsequent process exec and, optionally, quarantine/LSQuarantine events."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204.002",
   "technique_ja": "悪意あるファイル",
   "technique_en": "Malicious File",
   "analytic_id": "AN0821",
   "detection_strategy_id": "DET0294",
   "analytic_name": "Analytic 0821",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイル作成 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "TimeWindow | DesktopParentMap",
   "detection_logic_en": "User or desktop application writes a new file to ~/Downloads, /tmp, or mounted removable media followed by execve of a risky interpreter/loader (bash, sh, python, perl, php, node, curl|wget piping to sh, ld.so, rdesktop, xdg-open - with unusual args). Uses auditd PATH+SYSCALL (open/creat/write/rename) with execve event linking."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204.003",
   "technique_ja": "悪意あるイメージ",
   "technique_en": "Malicious Image",
   "analytic_id": "AN0691",
   "detection_strategy_id": "DET0248",
   "analytic_name": "Analytic 0691",
   "platforms": "Linux",
   "log_sources": "Image Creation (containerd:events) | Container Creation (kubernetes:audit) | Container Start (kubernetes:events) | Command Execution (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "イメージ作成 (containerd:events) | コンテナ作成 (kubernetes:audit) | コンテナ起動 (kubernetes:events) | コマンド実行 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ImageRegistryAllowList | TimeWindow | SuspiciousBinaries | NamespaceScope | OutboundCIDRBlockList",
   "detection_logic_en": "CONTAINERS (Docker/K8s/containerd): A user pulls an untrusted image from a public/unknown registry and then creates/starts a container from that image. Shortly after start, the container spawns unexpected utilities (e.g., curl/wget/bash/python), or makes outbound network connections atypical for the namespace/workload. The analytic correlates Image Creation/Download → Container Creation → Container Start → Command Execution/Network activity within a short window and with a consistent image digest."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204.003",
   "technique_ja": "悪意あるイメージ",
   "technique_en": "Malicious Image",
   "analytic_id": "AN0692",
   "detection_strategy_id": "DET0248",
   "analytic_name": "Analytic 0692",
   "platforms": "Windows",
   "log_sources": "Instance Start (AWS:CloudTrail) | Instance Creation (azure:activity) | Process Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "インスタンス起動 (AWS:CloudTrail) | インスタンス作成 (azure:activity) | プロセス生成 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ApprovedImageCatalog | UserDataInspection | FirstBootWindow | VMTagScope",
   "detection_logic_en": "IAAS (Cloud images/VMs): A new VM/instance is launched from a non-approved or newly-seen image (AMI/GCP Image/Azure Image). On first boot, cloud-init/user-data or embedded agents download code, spawn system utilities, or open outbound C2/mining traffic. The analytic correlates Instance/Image Creation → Instance Start → in-guest Process/Command Execution and/or anomalous network traffic."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204.004",
   "technique_ja": "悪意あるコピー&ペースト",
   "technique_en": "Malicious Copy and Paste",
   "analytic_id": "AN0962",
   "detection_strategy_id": "DET0340",
   "analytic_name": "Analytic 0962",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Command Execution (WinEventLog:PowerShell) | File Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | コマンド実行 (WinEventLog:PowerShell) | ファイル作成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TimeWindow | ParentProcessAllowList | SuspiciousArgPatterns | WritePaths | OutboundCIDRBlockList",
   "detection_logic_en": "A user is socially engineered (web page, email, document) to open Run/PowerShell/CMD and paste an obfuscated one-liner. The chain is: (1) user context active in a browser/email/office app → (2) process creation of a command interpreter with suspicious arguments (base64/Invoke-Expression/web download/pipeline to shell) → (3) optional file drop in %TEMP% or %APPDATA% → (4) outbound network connection to an external domain. Events are correlated within a short window and with consistent user/session."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204.004",
   "technique_ja": "悪意あるコピー&ペースト",
   "technique_en": "Malicious Copy and Paste",
   "analytic_id": "AN0963",
   "detection_strategy_id": "DET0340",
   "analytic_name": "Analytic 0963",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Creation (auditd:SYSCALL) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル作成 (auditd:SYSCALL) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "TerminalProcessNames | RiskyFilePaths | AnomalousUserSet | TimeWindow",
   "detection_logic_en": "User pastes a multi-line or one-liner into a terminal (bash/zsh) that downloads/decodes and executes content. Chain: terminal exec of curl/wget/bash/sh with pipe to interpreter or base64-decode → transient file under /tmp|~/.cache → immediate outbound egress."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204.004",
   "technique_ja": "悪意あるコピー&ペースト",
   "technique_en": "Malicious Copy and Paste",
   "analytic_id": "AN0964",
   "detection_strategy_id": "DET0340",
   "analytic_name": "Analytic 0964",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Command Execution (macos:osquery) | File Creation (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | コマンド実行 (macos:osquery) | ファイル作成 (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ParentAppScope | CommandPatternList | AllowListedDevUsers",
   "detection_logic_en": "User pastes an obfuscated command into Terminal.app/iTerm2 that decodes or downloads code and executes. Detects Terminal/iTerm2 spawning bash/zsh/python with suspicious pipeline/base64 patterns followed by file writes in ~/Library or /tmp and outbound network connections."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204.005",
   "technique_ja": "悪意あるライブラリ",
   "technique_en": "Malicious Library",
   "analytic_id": "AN0698",
   "detection_strategy_id": "DET0252",
   "analytic_name": "Analytic 0698",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Creation (auditd:PATH) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル作成 (auditd:PATH) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "PackageManagerList | InstallWritePaths | UserContextScope | TimeWindow",
   "detection_logic_en": "User-initiated installation of Python (pip), NodeJS (npm), or other language libraries, followed by unexpected network connections, credential access, or startup file modifications. Defender sees `pip install` or `npm install` commands run by a non-root user, followed shortly by new `.py`, `.sh`, or `.js` files in hidden directories, or interpreter-based execution during boot/login."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204.005",
   "technique_ja": "悪意あるライブラリ",
   "technique_en": "Malicious Library",
   "analytic_id": "AN0699",
   "detection_strategy_id": "DET0252",
   "analytic_name": "Analytic 0699",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "AllowedParentProcesses | InstallPathsToWatch | ExecutableEntropyThreshold",
   "detection_logic_en": "Execution of `pip.exe`, `npm.cmd`, or MSI installers within user context, followed by script interpreter startup (e.g., python.exe) or PowerShell with unusual child processes or file writes in `%APPDATA%`, `%TEMP%`, or `%LOCALAPPDATA%`. Defender correlates command-line install tools with Sysmon and Event Logs to trace downstream behavior."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1204.005",
   "technique_ja": "悪意あるライブラリ",
   "technique_en": "Malicious Library",
   "analytic_id": "AN0700",
   "detection_strategy_id": "DET0252",
   "analytic_name": "Analytic 0700",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Metadata (macos:unifiedlog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイルメタデータ (macos:unifiedlog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "StartupAgentPaths | UnsignedBinaryAlerting | InstallToNetWindow",
   "detection_logic_en": "Execution of Homebrew, pip3, npm, or manually downloaded PKGs from Terminal or shell, followed by the creation of startup agents, interpreter spawns, or outbound connections to unfamiliar domains. Defender links Terminal commands to plist creation, unsigned binary launches, and `python3` or `node` processes connecting to remote endpoints."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1559",
   "technique_ja": "プロセス間通信",
   "technique_en": "Inter-Process Communication",
   "analytic_id": "AN1357",
   "detection_strategy_id": "DET0493",
   "analytic_name": "Analytic 1357",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Security) | Named Pipe Metadata (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Security) | 名前付きパイプメタデータ (WinEventLog:Sysmon)",
   "tuning": "PipeNamePattern | AllowedParentChildPairs",
   "detection_logic_en": "Detects anomalous use of COM, DDE, or named pipes for execution. Correlates creation or access of IPC mechanisms (e.g., named pipes, COM objects) with unusual parent-child process relationships or code injection patterns (e.g., Office spawning cmd.exe via DDE)."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1559",
   "technique_ja": "プロセス間通信",
   "technique_en": "Inter-Process Communication",
   "analytic_id": "AN1358",
   "detection_strategy_id": "DET0493",
   "analytic_name": "Analytic 1358",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Access (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルアクセス (auditd:SYSCALL)",
   "tuning": "SocketPathBaseline | FIFOAccessPatterns",
   "detection_logic_en": "Detects abuse of UNIX domain sockets, pipes, or message queues for unauthorized code execution. Correlates unexpected socket creation with suspicious binaries, abnormal shell pipelines, or injected processes establishing IPC channels."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1559",
   "technique_ja": "プロセス間通信",
   "technique_en": "Inter-Process Communication",
   "analytic_id": "AN1359",
   "detection_strategy_id": "DET0493",
   "analytic_name": "Analytic 1359",
   "platforms": "macOS",
   "log_sources": "Process Access (macos:unifiedlog) | Script Execution (macos:osquery)",
   "log_sources_ja": "プロセスアクセス (macos:unifiedlog) | スクリプト実行 (macos:osquery)",
   "tuning": "AllowedAppleEventTargets | MachPortBaseline",
   "detection_logic_en": "Detects anomalous use of Mach ports, Apple Events, or XPC services for inter-process execution or code injection. Focuses on unexpected processes attempting to send privileged Apple Events (e.g., automation scripts injecting into security-sensitive apps)."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1559.001",
   "technique_ja": "コンポーネントオブジェクトモデル(COM)",
   "technique_en": "Component Object Model",
   "analytic_id": "AN0628",
   "detection_strategy_id": "DET0224",
   "analytic_name": "Analytic 0628",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Windows Registry Key Access (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | Windowsレジストリキーアクセス (WinEventLog:Security)",
   "tuning": "COMObjectAllowList | ParentProcessExclusions | TimeWindow",
   "detection_logic_en": "Detects anomalous use of COM objects for execution, such as Office applications spawning scripting engines, enumeration of COM interfaces via registry queries, or processes loading atypical DLLs through COM activation. Correlates process creation, module loads, and registry queries to flag suspicious COM-based code execution or persistence."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1559.002",
   "technique_ja": "動的データ交換(DDE)",
   "technique_en": "Dynamic Data Exchange",
   "analytic_id": "AN1393",
   "detection_strategy_id": "DET0504",
   "analytic_name": "Analytic 1393",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Windows Registry Key Access (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | Windowsレジストリキーアクセス (WinEventLog:Security)",
   "tuning": "AllowedParentChildPairs | TimeWindow | SuspiciousDLLList",
   "detection_logic_en": "Detects anomalous use of Dynamic Data Exchange (DDE) for code execution, such as Office applications (WINWORD.EXE, EXCEL.EXE) spawning command interpreters, or loading unusual modules through DDEAUTO/DDE formulas. Correlates suspicious parent-child process relationships, registry keys enabling DDE, and module loads inconsistent with normal Office usage."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1559.003",
   "technique_ja": "XPCサービス",
   "technique_en": "XPC Services",
   "analytic_id": "AN0948",
   "detection_strategy_id": "DET0335",
   "analytic_name": "Analytic 0948",
   "platforms": "macOS",
   "log_sources": "Process Access (macos:unifiedlog) | Process Creation (macos:unifiedlog) | Named Pipe Metadata (macos:unifiedlog)",
   "log_sources_ja": "プロセスアクセス (macos:unifiedlog) | プロセス生成 (macos:unifiedlog) | 名前付きパイプメタデータ (macos:unifiedlog)",
   "tuning": "AllowedXPCClients | TimeWindow | UnsignedBinaryAlertLevel",
   "detection_logic_en": "Detects anomalous use of macOS XPC services for code execution. Monitors for processes invoking privileged XPC daemons with abnormal parameters, unexpected binaries communicating over NSXPCConnection, or helper tools executing code outside of their expected parent process lineage. Correlates process access attempts to system-level daemons, privilege escalations via XPC misconfigurations, and injection of malicious payloads through inter-process communication."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1569",
   "technique_ja": "システムサービス",
   "technique_en": "System Services",
   "analytic_id": "AN0778",
   "detection_strategy_id": "DET0279",
   "analytic_name": "Analytic 0778",
   "platforms": "Windows",
   "log_sources": "Service Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "サービス作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "ServiceAllowlist | TimeWindow",
   "detection_logic_en": "Monitor for abnormal creation or modification of Windows services (e.g., via sc.exe, PowerShell, or API calls) that load non-standard executables. Correlate registry changes in service keys with service creation events and process execution to detect service abuse for persistence or execution."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1569",
   "technique_ja": "システムサービス",
   "technique_en": "System Services",
   "analytic_id": "AN0779",
   "detection_strategy_id": "DET0279",
   "analytic_name": "Analytic 0779",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Service Creation (linux:syslog) | File Modification (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | サービス作成 (linux:syslog) | ファイル変更 (auditd:SYSCALL)",
   "tuning": "ServiceBinaryPaths | UserContext",
   "detection_logic_en": "Detect unusual invocations of systemctl, service, or init scripts creating or modifying daemons. Monitor audit logs for execution of binaries from unexpected paths linked to service start/stop activity."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1569",
   "technique_ja": "システムサービス",
   "technique_en": "System Services",
   "analytic_id": "AN0780",
   "detection_strategy_id": "DET0279",
   "analytic_name": "Analytic 0780",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog)",
   "tuning": "PlistAllowlist | PayloadEntropyThreshold",
   "detection_logic_en": "Monitor launchd service definitions and property list (.plist) modifications for non-standard executables. Detect unauthorized processes registered as launch daemons or agents."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1569.001",
   "technique_ja": "Launchctl",
   "technique_en": "Launchctl",
   "analytic_id": "AN0736",
   "detection_strategy_id": "DET0265",
   "analytic_name": "Analytic 0736",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Modification (macos:unifiedlog) | Process Creation (macos:unifiedlog) | Service Creation (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog) | サービス作成 (macos:unifiedlog)",
   "tuning": "MonitoredPaths | SuspiciousExecPaths | TimeWindow",
   "detection_logic_en": "Abuse of launchctl to execute or manage Launch Agents and Daemons. Defender perspective: correlation of suspicious plist file creation or modification in LaunchAgents/LaunchDaemons directories with subsequent execution of the launchctl command. Abnormal executable paths (e.g., /tmp, /Shared) or launchctl activity followed by network connections are highly suspicious."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1569.002",
   "technique_ja": "サービス実行",
   "technique_en": "Service Execution",
   "analytic_id": "AN1185",
   "detection_strategy_id": "DET0421",
   "analytic_name": "Analytic 1185",
   "platforms": "Windows",
   "log_sources": "Service Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "サービス作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "ServiceBinaryAllowlist | ParentProcessCorrelationWindow | RemoteExecutionHosts",
   "detection_logic_en": "Detection focuses on abnormal service executions initiated via service control manager APIs, sc.exe, net.exe, or PsExec creating temporary services. Defenders observe process creation of services.exe spawning non-standard binaries, registry changes in service keys followed by rapid execution, and network connections originating from processes tied to transient services. Correlation across process lineage, registry activity, and service logs provides strong signals of malicious service execution."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1569.003",
   "technique_ja": "Systemctl",
   "technique_en": "Systemctl",
   "analytic_id": "AN0200",
   "detection_strategy_id": "DET0073",
   "analytic_name": "Analytic 0200",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:EXECVE) | File Modification (auditd:SYSCALL) | Process Creation (auditd:EXECVE) | Service Creation (auditd:CONFIG_CHANGE)",
   "log_sources_ja": "コマンド実行 (auditd:EXECVE) | ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:EXECVE) | サービス作成 (auditd:CONFIG_CHANGE)",
   "tuning": "MonitoredPaths | SuspiciousSubcommands | CorrelationWindow",
   "detection_logic_en": "Abuse of systemctl to execute commands or manage systemd services. Defender perspective: correlate suspicious service creation or modification with execution of systemctl subcommands such as start, enable, or status. Detect cases where systemctl is used to load services from unusual locations (e.g., /tmp, /dev/shm) or where new service units are created outside of expected administrative workflows."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1574",
   "technique_ja": "実行フローの乗っ取り",
   "technique_en": "Hijack Execution Flow",
   "analytic_id": "AN0609",
   "detection_strategy_id": "DET0218",
   "analytic_name": "Analytic 0609",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Security) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "ServiceBaseline | AllowedDllPaths | TimeWindow",
   "detection_logic_en": "Unusual modifications to service binary paths, registry keys, or DLL load paths resulting in alternate execution flow. Defender observes registry key modifications, suspicious file writes into system directories, and processes loading libraries from abnormal paths."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1574",
   "technique_ja": "実行フローの乗っ取り",
   "technique_en": "Hijack Execution Flow",
   "analytic_id": "AN0610",
   "detection_strategy_id": "DET0218",
   "analytic_name": "Analytic 0610",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Service Metadata (linux:syslog) | Process Creation (linux:osquery)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | サービスメタデータ (linux:syslog) | プロセス生成 (linux:osquery)",
   "tuning": "MonitoredDirectories | EnvVarMonitors",
   "detection_logic_en": "Adversary manipulation of shared library paths, environment variables, or replacement of service binaries. Defender observes suspicious modifications in /etc/ld.so.preload, service config changes, or file writes replacing existing executables."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1574",
   "technique_ja": "実行フローの乗っ取り",
   "technique_en": "Hijack Execution Flow",
   "analytic_id": "AN0611",
   "detection_strategy_id": "DET0218",
   "analytic_name": "Analytic 0611",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:unifiedlog) | Module Load (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog) | モジュール読み込み (macos:unifiedlog)",
   "tuning": "AllowedDylibPaths | PlistMonitors",
   "detection_logic_en": "Abuse of DYLD_INSERT_LIBRARIES or hijacking framework paths for malicious libraries. Defender observes processes invoking abnormal dylibs, modified plist files, or persistence entries pointing to altered binaries."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1574.001",
   "technique_ja": "DLL",
   "technique_en": "DLL",
   "analytic_id": "AN0577",
   "detection_strategy_id": "DET0201",
   "analytic_name": "Analytic 0577",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "AllowedDllPaths | ProcessAllowList | TimeWindow | HashBaseline",
   "detection_logic_en": "DLL hijacking behaviors including unexpected DLL loads from non-standard directories, replacement of DLLs, phantom DLL insertion, redirection file creation, and substitution of legitimate DLLs. Defender correlates file system modifications, registry changes, and module load telemetry to detect abnormal DLL behavior in trusted processes."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1574.004",
   "technique_ja": "Dylibハイジャック",
   "technique_en": "Dylib Hijacking",
   "analytic_id": "AN0435",
   "detection_strategy_id": "DET0152",
   "analytic_name": "Analytic 0435",
   "platforms": "macOS",
   "log_sources": "Module Load (macos:unifiedlog) | File Creation (macos:unifiedlog) | File Modification (macos:unifiedlog)",
   "log_sources_ja": "モジュール読み込み (macos:unifiedlog) | ファイル作成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog)",
   "tuning": "MonitoredDirectories | BaselineDylibs | CorrelationWindow",
   "detection_logic_en": "Detection focuses on adversaries placing or modifying malicious dylibs in locations searched by legitimate applications. From the defender’s perspective, observable patterns include unexpected creation or modification of dylib files in application bundle paths, unusual module loads by processes compared to historical baselines, and execution of applications loading dylibs from suspicious directories (e.g., /tmp, user-controlled paths). Correlation across file system changes, process execution, and module loads provides high-fidelity detection."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1574.005",
   "technique_ja": "実行可能インストーラのファイル権限の弱点",
   "technique_en": "Executable Installer File Permissions Weakness",
   "analytic_id": "AN0108",
   "detection_strategy_id": "DET0038",
   "analytic_name": "Analytic 0108",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "MonitoredDirectories | HashBaseline | TimeWindow | UserContext",
   "detection_logic_en": "Executables written or modified in installer directories (e.g., %TEMP% subdirectories or Program Files installer paths) followed by execution under elevated context. Defender observes abnormal file replacement activity, process creation by installer processes pointing to attacker-supplied binaries, and unexpected module loads in elevated processes."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1574.006",
   "technique_ja": "動的リンカーハイジャック",
   "technique_en": "Dynamic Linker Hijacking",
   "analytic_id": "AN1209",
   "detection_strategy_id": "DET0435",
   "analytic_name": "Analytic 1209",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Creation (auditd:PATH) | Process Metadata (linux:osquery)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル作成 (auditd:PATH) | プロセスメタデータ (linux:osquery)",
   "tuning": "WatchedEnvVars | MonitoredDirectories | CorrelationWindow",
   "detection_logic_en": "Detection focuses on identifying abuse of LD_PRELOAD and related linker variables. Defender perspective: monitor unexpected setting or modification of LD_PRELOAD in shell initialization scripts or environment exports, file creation of suspicious shared libraries, and correlation of these modifications with anomalous process execution. Key signals include execve events with LD_PRELOAD defined, newly created .so files in user directories, and processes hooking libc functions exhibiting abnormal behavior."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1574.006",
   "technique_ja": "動的リンカーハイジャック",
   "technique_en": "Dynamic Linker Hijacking",
   "analytic_id": "AN1210",
   "detection_strategy_id": "DET0435",
   "analytic_name": "Analytic 1210",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:unifiedlog) | Module Load (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog) | モジュール読み込み (macos:unifiedlog)",
   "tuning": "WatchedEnvVars | BaselineDylibs | MonitoredDirectories",
   "detection_logic_en": "Detection centers on DYLD_INSERT_LIBRARIES and DYLD_LIBRARY_PATH abuse. Defender perspective: monitor for modification of these environment variables in shell or plist files, file creation of dylibs in user-controlled paths, and correlation of environment variable usage with unexpected module loads by user applications. Suspicious indicators include processes with DYLD_INSERT_LIBRARIES set, execution of applications loading untrusted dylibs, and anomalies in module load history."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1574.007",
   "technique_ja": "PATH環境変数によるパス横取り",
   "technique_en": "Path Interception by PATH Environment Variable",
   "analytic_id": "AN0009",
   "detection_strategy_id": "DET0004",
   "analytic_name": "Analytic 0009",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "MonitoredRegistryKeys | SuspiciousBinaryList | TimeWindow",
   "detection_logic_en": "Abnormal modification of the PATH environment variable or registry keys controlling system paths, combined with execution of binaries named after legitimate system tools from user-writable directories. Defender correlates registry modifications, file creation of suspicious binaries, and process execution paths inconsistent with baseline system directories."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1574.007",
   "technique_ja": "PATH環境変数によるパス横取り",
   "technique_en": "Path Interception by PATH Environment Variable",
   "analytic_id": "AN0010",
   "detection_strategy_id": "DET0004",
   "analytic_name": "Analytic 0010",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (linux:osquery)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (linux:osquery)",
   "tuning": "MonitoredShellConfigs | AllowedUserBins",
   "detection_logic_en": "User modification of the $PATH environment variable in shell configuration files or direct runtime PATH changes, followed by execution of binaries from user-controlled directories. Defender observes file edits to ~/.bashrc, ~/.profile, or /etc/paths.d and process execution resolving to unexpected binary locations."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1574.007",
   "technique_ja": "PATH環境変数によるパス横取り",
   "technique_en": "Path Interception by PATH Environment Variable",
   "analytic_id": "AN0011",
   "detection_strategy_id": "DET0004",
   "analytic_name": "Analytic 0011",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "WatchedPathsDirs | TrustedExecutables",
   "detection_logic_en": "Modification of PATH or HOME environment variables through shell config files, launchctl, or /etc/paths.d entries, combined with process execution from attacker-controlled directories. Defender correlates file changes in /etc/paths.d with process execution resolving to malicious binaries."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1574.008",
   "technique_ja": "検索順ハイジャックによるパス横取り",
   "technique_en": "Path Interception by Search Order Hijacking",
   "analytic_id": "AN1560",
   "detection_strategy_id": "DET0564",
   "analytic_name": "Analytic 1560",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "SuspiciousBinaryList | MonitoredDirectories | TimeWindow | ParentProcessBaseline",
   "detection_logic_en": "Processes executing binaries named after legitimate system utilities (e.g., net.exe, findstr.exe, python.exe) from non-standard or application-specific directories, combined with file creation or modification events for such binaries. Defender correlates file writes in vulnerable directories, process execution paths inconsistent with baseline system paths, and abnormal parent-child relationships in process lineage."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1574.009",
   "technique_ja": "引用符なしパスによるパス横取り",
   "technique_en": "Path Interception by Unquoted Path",
   "analytic_id": "AN0176",
   "detection_strategy_id": "DET0064",
   "analytic_name": "Analytic 0176",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon)",
   "tuning": "MonitoredServices | SuspiciousBinaryList | TimeWindow | BaselineServiceConfig",
   "detection_logic_en": "Unquoted service or shortcut paths that contain spaces and allow path interception by higher-level executables. Defender observes registry service configurations with unquoted paths, file creation of executables in parent directories of unquoted paths, and subsequent process execution from unexpected locations."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1574.010",
   "technique_ja": "サービスのファイル権限の弱点",
   "technique_en": "Services File Permissions Weakness",
   "analytic_id": "AN1211",
   "detection_strategy_id": "DET0436",
   "analytic_name": "Analytic 1211",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon) | Service Creation (WinEventLog:System) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon) | サービス作成 (WinEventLog:System) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "MonitoredServices | HashBaseline | TimeWindow | PrivilegedAccounts",
   "detection_logic_en": "Modification or replacement of service executables due to weak file or directory permissions. Defender observes file writes to service binary paths, unexpected modifications of executables associated with registered services, and subsequent service execution of attacker-supplied binaries under elevated permissions."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1574.011",
   "technique_ja": "サービスのレジストリ権限の弱点",
   "technique_en": "Services Registry Permissions Weakness",
   "analytic_id": "AN1195",
   "detection_strategy_id": "DET0427",
   "analytic_name": "Analytic 1195",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Service Modification (WinEventLog:System) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | サービス変更 (WinEventLog:System) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "MonitoredServiceKeys | BaselineServiceConfig | TimeWindow | PrivilegedAccounts",
   "detection_logic_en": "Unauthorized modification of service-related registry keys such as ImagePath, FailureCommand, ServiceDll, or Performance/Parameters keys. Defender correlates registry modifications, anomalous service metadata changes, and subsequent service process executions that deviate from baseline configurations."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1574.012",
   "technique_ja": "COR_PROFILER",
   "technique_en": "COR_PROFILER",
   "analytic_id": "AN1319",
   "detection_strategy_id": "DET0479",
   "analytic_name": "Analytic 1319",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "AllowedProfilers | ProcessScope | TimeWindow | ProfilerDllPaths",
   "detection_logic_en": "Modification of COR_PROFILER-related environment variables or Registry keys (COR_ENABLE_PROFILING, COR_PROFILER, COR_PROFILER_PATH), combined with anomalous .NET process creation or unmanaged DLL loads. Defender observes registry modifications, suspicious process creation with altered environment variables, and profiler DLLs loaded unexpectedly into .NET CLR processes."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1574.013",
   "technique_ja": "KernelCallbackTable",
   "technique_en": "KernelCallbackTable",
   "analytic_id": "AN1593",
   "detection_strategy_id": "DET0577",
   "analytic_name": "Analytic 1593",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Kernel-Process)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Kernel-Process)",
   "tuning": "MonitoredProcesses | CallbackFunctions | TimeWindow | AccessMaskThresholds",
   "detection_logic_en": "Unexpected modification of the KernelCallbackTable in a process’s PEB followed by invocation of modified callback functions (e.g., fnCOPYDATA) through Windows messages. Defender observes suspicious API call chains such as NtQueryInformationProcess → WriteProcessMemory → abnormal GUI callback execution, often correlating to anomalous process behavior such as network activity or code injection."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1574.014",
   "technique_ja": "AppDomainManager",
   "technique_en": "AppDomainManager",
   "analytic_id": "AN1433",
   "detection_strategy_id": "DET0517",
   "analytic_name": "Analytic 1433",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "TargetProcesses | AssemblyWhitelist | ConfigFilePaths | TimeWindow",
   "detection_logic_en": "Detection focuses on unauthorized manipulation of .NET AppDomainManager behavior. Defenders may observe suspicious creation of new AppDomains within trusted processes, anomalous loading of assemblies via non-standard configuration files, or registry/environment variable changes redirecting AppDomainManager to malicious assemblies. Correlated events include config file tampering, new process creation of .NET host processes (e.g., w3wp.exe, powershell.exe) with modified runtime parameters, and module loads of unusual or unsigned .NET DLLs."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1609",
   "technique_ja": "コンテナ管理コマンド",
   "technique_en": "Container Administration Command",
   "analytic_id": "AN0177",
   "detection_strategy_id": "DET0065",
   "analytic_name": "Analytic 0177",
   "platforms": "Containers",
   "log_sources": "Command Execution (docker:daemon) | Process Creation (kubernetes:apiserver)",
   "log_sources_ja": "コマンド実行 (docker:daemon) | プロセス生成 (kubernetes:apiserver)",
   "tuning": "AuthorizedAdminUsers | ExecFrequencyThreshold | SourceIPRange | NamespaceScope",
   "detection_logic_en": "Defenders may detect abuse of container administration commands by observing anomalous use of management utilities (`docker exec`, `kubectl exec`, or API calls to kubelet) correlated with unexpected process creation inside containers. Behavioral chains include unauthorized API requests followed by command execution within running pods or containers, often originating from unusual user accounts, automation scripts, or IP addresses outside the expected cluster management plane."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1610",
   "technique_ja": "コンテナのデプロイ",
   "technique_en": "Deploy Container",
   "analytic_id": "AN0693",
   "detection_strategy_id": "DET0249",
   "analytic_name": "Analytic 0693",
   "platforms": "Containers",
   "log_sources": "Application Log Content (docker:daemon) | Container Start (containerd:runtime) | Process Creation (ebpf:syscalls) | Network Traffic Content (docker:events)",
   "log_sources_ja": "アプリケーションログ内容 (docker:daemon) | コンテナ起動 (containerd:runtime) | プロセス生成 (ebpf:syscalls) | ネットワークトラフィック内容 (docker:events)",
   "tuning": "known_images | known_admins | TimeWindow | RiskThreshold | PrivilegedFlags",
   "detection_logic_en": "Remote/API driven creation **and** start of a container whose image is not on an allow‑list (or is tagged `latest`), executed by a non-admin principal, and/or started with risky runtime attributes (e.g., `--privileged`, host PID/NET namespaces, sensitive host path mounts, capability adds). Correlates *create* ➜ *start* ➜ first network/process actions from that container within a short time window."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1648",
   "technique_ja": "サーバーレス実行",
   "technique_en": "Serverless Execution",
   "analytic_id": "AN1053",
   "detection_strategy_id": "DET0374",
   "analytic_name": "Analytic 1053",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Modification (AWS:CloudTrail) | Application Log Content (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス変更 (AWS:CloudTrail) | アプリケーションログ内容 (AWS:CloudTrail)",
   "tuning": "RoleScope | AllowedFunctions | TimeWindow",
   "detection_logic_en": "Correlate creation or modification of serverless functions (e.g., AWS Lambda, GCP Cloud Functions, Azure Functions) with anomalous IAM role assignments or permissions escalation events. Detect subsequent executions of newly created functions that perform unexpected actions such as spawning outbound network connections, accessing sensitive resources, or creating additional credentials."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1648",
   "technique_ja": "サーバーレス実行",
   "technique_en": "Serverless Execution",
   "analytic_id": "AN1054",
   "detection_strategy_id": "DET0374",
   "analytic_name": "Analytic 1054",
   "platforms": "Office Suite",
   "log_sources": "Cloud Service Modification (m365:unified) | Application Log Content (m365:exchange)",
   "log_sources_ja": "クラウドサービス変更 (m365:unified) | アプリケーションログ内容 (m365:exchange)",
   "tuning": "UserContext | FlowActions",
   "detection_logic_en": "Monitor for creation of new Power Automate flows or equivalent automation scripts that trigger on user or file events. Detect anomalous actions performed by these automations, such as email forwarding, anonymous link creation, or unexpected API calls to external endpoints."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1648",
   "technique_ja": "サーバーレス実行",
   "technique_en": "Serverless Execution",
   "analytic_id": "AN1055",
   "detection_strategy_id": "DET0374",
   "analytic_name": "Analytic 1055",
   "platforms": "SaaS",
   "log_sources": "Cloud Service Modification (saas:appsscript) | Application Log Content (saas:googledrive)",
   "log_sources_ja": "クラウドサービス変更 (saas:appsscript) | アプリケーションログ内容 (saas:googledrive)",
   "tuning": "ScriptScope | TriggerTypes",
   "detection_logic_en": "Track creation or update of SaaS automation scripts (e.g., Google Workspace Apps Script). Detect when these scripts are bound to user events such as file opens or account modifications, and correlate with subsequent abnormal API calls that exfiltrate or modify user data."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1651",
   "technique_ja": "クラウド管理コマンド",
   "technique_en": "Cloud Administration Command",
   "analytic_id": "AN1502",
   "detection_strategy_id": "DET0545",
   "analytic_name": "Analytic 1502",
   "platforms": "IaaS",
   "log_sources": "Command Execution (AWS:CloudTrail) | Script Execution (azure:activity) | Process Creation (azure:vmguest)",
   "log_sources_ja": "コマンド実行 (AWS:CloudTrail) | スクリプト実行 (azure:activity) | プロセス生成 (azure:vmguest)",
   "tuning": "UserContext | TimeWindow | AllowedScripts",
   "detection_logic_en": "Monitor for suspicious use of cloud-native administrative command services (e.g., AWS Systems Manager Run Command, Azure RunCommand, GCP OS Config) to execute code inside VMs. Detect anomalies such as commands/scripts executed by unexpected users, execution outside of maintenance windows, or commands initiated by service accounts not normally tied to administration. Correlate cloud control-plane activity logs with host-level execution (process creation, script execution) to validate if commands materialized inside the guest OS."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1674",
   "technique_ja": "入力インジェクション",
   "technique_en": "Input Injection",
   "analytic_id": "AN1567",
   "detection_strategy_id": "DET0568",
   "analytic_name": "Analytic 1567",
   "platforms": "Windows",
   "log_sources": "Drive Creation (WinEventLog:System) | Process Creation (WinEventLog:Security) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "ドライブ作成 (WinEventLog:System) | プロセス生成 (WinEventLog:Security) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "AuthorizedUSBDevices | ExecutionTimeWindow | ParentProcessWhitelist",
   "detection_logic_en": "Detects suspicious USB HID device enumeration and keystroke injection patterns, such as rapid sequences of input with no user context, scripts executed through simulated keystrokes, or rogue devices presenting themselves as keyboards."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1674",
   "technique_ja": "入力インジェクション",
   "technique_en": "Input Injection",
   "analytic_id": "AN1568",
   "detection_strategy_id": "DET0568",
   "analytic_name": "Analytic 1568",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Drive Creation (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ドライブ作成 (linux:syslog)",
   "tuning": "USBVendorIDs | ScriptExecutionThreshold",
   "detection_logic_en": "Detects USB HID device enumeration under `/sys/bus/usb/devices/` and rapid keystroke injection resulting in command execution such as bash or Python scripts launched without interactive user activity."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1674",
   "technique_ja": "入力インジェクション",
   "technique_en": "Input Injection",
   "analytic_id": "AN1569",
   "detection_strategy_id": "DET0568",
   "analytic_name": "Analytic 1569",
   "platforms": "macOS",
   "log_sources": "Drive Creation (macos:unifiedlog) | Script Execution (macos:unifiedlog)",
   "log_sources_ja": "ドライブ作成 (macos:unifiedlog) | スクリプト実行 (macos:unifiedlog)",
   "tuning": "AllowedAppleScripts | TimeWindow",
   "detection_logic_en": "Detects abnormal HID device enumeration via I/O Registry (ioreg -p IOUSB) and keystroke injection targeting AppleScript, osascript, or PowerShell equivalents. Defender correlates new USB device connections with rapid script execution."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1675",
   "technique_ja": "ESXi管理コマンド",
   "technique_en": "ESXi Administration Command",
   "analytic_id": "AN0646",
   "detection_strategy_id": "DET0232",
   "analytic_name": "Analytic 0646",
   "platforms": "ESXi",
   "log_sources": "Application Log Content (esxi:hostd)",
   "log_sources_ja": "アプリケーションログ内容 (esxi:hostd)",
   "tuning": "ExpectedAdminUsers | TimeWindow | OperationThreshold | AuthorizedVMs",
   "detection_logic_en": "Detects anomalous usage of ESXi Guest Operations APIs such as StartProgramInGuest, ListProcessesInGuest, ListFileInGuest, or InitiateFileTransferFromGuest. Defender perspective focuses on unusual frequency of guest API calls, invocation from unexpected management accounts, or execution outside of business hours. These correlated signals indicate adversarial abuse of ESXi administrative services to run commands on guest VMs."
  },
  {
   "tactic_id": "TA0002",
   "tactic_ja": "実行",
   "technique_id": "T1677",
   "technique_ja": "汚染パイプライン実行",
   "technique_en": "Poisoned Pipeline Execution",
   "analytic_id": "AN1473",
   "detection_strategy_id": "DET0533",
   "analytic_name": "Analytic 1473",
   "platforms": "SaaS",
   "log_sources": "Cloud Service Modification (saas:github) | Cloud Service Metadata (saas:github) | Cloud Storage Access (saas:github) | File Metadata (saas:RepoEvents) | Command Execution (saas:PRMetadata)",
   "log_sources_ja": "クラウドサービス変更 (saas:github) | クラウドサービスメタデータ (saas:github) | クラウドストレージアクセス (saas:github) | ファイルメタデータ (saas:RepoEvents) | コマンド実行 (saas:PRMetadata)",
   "tuning": "TimeWindow | UserContext | TriggerTypeAllowlist | ArtifactEntropyThreshold | SecretAccessRateThreshold",
   "detection_logic_en": "Detects anomalous CI/CD workflow execution originating from forked repositories, with pull request (PR) metadata or commit messages containing suspicious patterns (e.g., encoded payloads), coupled with the use of insecure pipeline triggers like `pull_request_target` or excessive API usage of CI/CD secrets. Correlation with unusual artifact generation or secret exfiltration via encoded or external network destination URLs confirms suspicious behavior."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1037",
   "technique_ja": "起動/ログオン初期化スクリプト",
   "technique_en": "Boot or Logon Initialization Scripts",
   "analytic_id": "AN0311",
   "detection_strategy_id": "DET0112",
   "analytic_name": "Analytic 0311",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Security) | Scheduled Job Creation (WinEventLog:TaskScheduler)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Security) | スケジュールジョブ作成 (WinEventLog:TaskScheduler)",
   "tuning": "TargetObject | ParentProcessName | TimeWindow",
   "detection_logic_en": "Monitoring modification and execution of user or system logon scripts such as in registry Run keys or startup folders."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1037",
   "technique_ja": "起動/ログオン初期化スクリプト",
   "technique_en": "Boot or Logon Initialization Scripts",
   "analytic_id": "AN0312",
   "detection_strategy_id": "DET0112",
   "analytic_name": "Analytic 0312",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Metadata (auditd:PATH) | File Modification (linux:osquery)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルメタデータ (auditd:PATH) | ファイル変更 (linux:osquery)",
   "tuning": "FilePath | UserContext | TimeWindow",
   "detection_logic_en": "Detection of changes or execution of shell initialization scripts like .bashrc, .profile, or /etc/profile for persistence."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1037",
   "technique_ja": "起動/ログオン初期化スクリプト",
   "technique_en": "Boot or Logon Initialization Scripts",
   "analytic_id": "AN0313",
   "detection_strategy_id": "DET0112",
   "analytic_name": "Analytic 0313",
   "platforms": "macOS",
   "log_sources": "Script Execution (macos:unifiedlog) | File Access (fs:fsusage) | Service Metadata (macos:osquery)",
   "log_sources_ja": "スクリプト実行 (macos:unifiedlog) | ファイルアクセス (fs:fsusage) | サービスメタデータ (macos:osquery)",
   "tuning": "Label | ProgramArguments | UserContext",
   "detection_logic_en": "Monitoring for modification and execution of login hook scripts or LaunchAgents/LaunchDaemons used for persistence."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1037",
   "technique_ja": "起動/ログオン初期化スクリプト",
   "technique_en": "Boot or Logon Initialization Scripts",
   "analytic_id": "AN0314",
   "detection_strategy_id": "DET0112",
   "analytic_name": "Analytic 0314",
   "platforms": "ESXi",
   "log_sources": "Script Execution (esxi:vmkernel) | File Modification (esxi:hostd)",
   "log_sources_ja": "スクリプト実行 (esxi:vmkernel) | ファイル変更 (esxi:hostd)",
   "tuning": "ScriptName | LogSeverity",
   "detection_logic_en": "Detection of modification to ESXi rc.local.d or rc scripts that are used to execute on boot."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1037",
   "technique_ja": "起動/ログオン初期化スクリプト",
   "technique_en": "Boot or Logon Initialization Scripts",
   "analytic_id": "AN0315",
   "detection_strategy_id": "DET0112",
   "analytic_name": "Analytic 0315",
   "platforms": "Network Devices",
   "log_sources": "File Modification (networkdevice:syslog)",
   "log_sources_ja": "ファイル変更 (networkdevice:syslog)",
   "tuning": "Interface | CommandPattern",
   "detection_logic_en": "Detection of changes to device startup-config files that include boot scripts or scheduled execution routines."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1037.001",
   "technique_ja": "ログオンスクリプト(Windows)",
   "technique_en": "Logon Script (Windows)",
   "analytic_id": "AN0199",
   "detection_strategy_id": "DET0072",
   "analytic_name": "Analytic 0199",
   "platforms": "Windows",
   "log_sources": "File Access (WinEventLog:Security) | Script Execution (WinEventLog:System) | Logon Session Creation (WinEventLog:Security) | Process Creation (WinEventLog:Security)",
   "log_sources_ja": "ファイルアクセス (WinEventLog:Security) | スクリプト実行 (WinEventLog:System) | ログオンセッション作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Security)",
   "tuning": "script_path_keywords | execution_time_window | user_context",
   "detection_logic_en": "Detects adversary use of logon script configuration via Group Policy or user object attributes, followed by script execution post-authentication. Behavior includes modification of script path or file, then process execution under user logon context."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1037.002",
   "technique_ja": "ログインフック",
   "technique_en": "Login Hook",
   "analytic_id": "AN0682",
   "detection_strategy_id": "DET0244",
   "analytic_name": "Analytic 0682",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (fs:plist)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (fs:plist)",
   "tuning": "login_hook_path | user_context | time_window | parent_process_name",
   "detection_logic_en": "Detection of persistent login hooks configured via defaults or plist modifications that result in execution of scripts or binaries at user login, breaking expected parent-child process lineage."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1037.003",
   "technique_ja": "ネットワークログオンスクリプト",
   "technique_en": "Network Logon Script",
   "analytic_id": "AN1034",
   "detection_strategy_id": "DET0367",
   "analytic_name": "Analytic 1034",
   "platforms": "Windows",
   "log_sources": "Network Share Access (WinEventLog:Security) | Process Creation (WinEventLog:Security) | Script Execution (WinEventLog:System)",
   "log_sources_ja": "ネットワーク共有アクセス (WinEventLog:Security) | プロセス生成 (WinEventLog:Security) | スクリプト実行 (WinEventLog:System)",
   "tuning": "TargetObject | ParentProcessName | TimeWindow | UserContext",
   "detection_logic_en": "Correlates Group Policy updates that configure network logon scripts with subsequent remote file execution behaviors triggered by user logons to identify potential persistence or execution chains tied to adversarial manipulation of logon scripts."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1037.004",
   "technique_ja": "RCスクリプト",
   "technique_en": "RC Scripts",
   "analytic_id": "AN0658",
   "detection_strategy_id": "DET0237",
   "analytic_name": "Analytic 0658",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Script Execution (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | スクリプト実行 (linux:syslog)",
   "tuning": "script_path | user_context | time_window",
   "detection_logic_en": "Detection of modified or newly created /etc/rc.local or /etc/init.d scripts followed by suspicious execution during system startup."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1037.004",
   "technique_ja": "RCスクリプト",
   "technique_en": "RC Scripts",
   "analytic_id": "AN0659",
   "detection_strategy_id": "DET0237",
   "analytic_name": "Analytic 0659",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (fs:fsusage)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (fs:fsusage)",
   "tuning": "script_name | event_interval | file_permission",
   "detection_logic_en": "Detection of edits or additions to /etc/rc.common, /Library/StartupItems, or /System/Library/StartupItems and associated script execution during login or reboot."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1037.004",
   "technique_ja": "RCスクリプト",
   "technique_en": "RC Scripts",
   "analytic_id": "AN0660",
   "detection_strategy_id": "DET0237",
   "analytic_name": "Analytic 0660",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:syslog) | File Modification (esxi:shell)",
   "log_sources_ja": "コマンド実行 (esxi:syslog) | ファイル変更 (esxi:shell)",
   "tuning": "script_section | command_type | execution_trigger",
   "detection_logic_en": "Detection of changes to /etc/rc.local.d/local.sh or rc.local during post-boot script execution with abnormal commands or additions."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1037.004",
   "technique_ja": "RCスクリプト",
   "technique_en": "RC Scripts",
   "analytic_id": "AN0661",
   "detection_strategy_id": "DET0237",
   "analytic_name": "Analytic 0661",
   "platforms": "Network Devices",
   "log_sources": "File Modification (networkdevice:syslog) | Command Execution (networkdevice:syslog)",
   "log_sources_ja": "ファイル変更 (networkdevice:syslog) | コマンド実行 (networkdevice:syslog)",
   "tuning": "firmware_family | config_line_pattern | reboot_time_window",
   "detection_logic_en": "Detection of modified boot-time configuration scripts that persist malicious CLI commands across reboots."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1037.005",
   "technique_ja": "スタートアップアイテム",
   "technique_en": "Startup Items",
   "analytic_id": "AN1197",
   "detection_strategy_id": "DET0429",
   "analytic_name": "Analytic 1197",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (macos:fsevents)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:fsevents)",
   "tuning": "directory_path | user_context | time_window | process_name",
   "detection_logic_en": "Detects the modification or addition of Launch Agents or Startup Items to establish persistence. Adversaries may write plist or executable files to ~/Library/LaunchAgents/, /Library/StartupItems/, or similar directories and configure them to run at user or system boot. Detection requires correlating file creation or modification events with subsequent user logon or boot-time process execution."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1053",
   "technique_ja": "スケジュールされたタスク/ジョブ",
   "technique_en": "Scheduled Task/Job",
   "analytic_id": "AN0258",
   "detection_strategy_id": "DET0094",
   "analytic_name": "Analytic 0258",
   "platforms": "Windows",
   "log_sources": "Scheduled Job Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | File Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "スケジュールジョブ作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Sysmon)",
   "tuning": "TaskAuthor | CommandLineRegex | ExecutionWindow",
   "detection_logic_en": "Detects creation or modification of scheduled tasks using schtasks.exe, at.exe, or COM objects followed by execution of outlier processes tied to the scheduled job."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1053",
   "technique_ja": "スケジュールされたタスク/ジョブ",
   "technique_en": "Scheduled Task/Job",
   "analytic_id": "AN0259",
   "detection_strategy_id": "DET0094",
   "analytic_name": "Analytic 0259",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Scheduled Job Creation (linux:osquery)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | スケジュールジョブ作成 (linux:osquery)",
   "tuning": "CronSchedulePattern | ServiceUser | BinaryEntropy",
   "detection_logic_en": "Detects creation or modification of cron jobs via crontab, /etc/cron.* directories, or systemd timer units with execution by unusual users or non-standard intervals."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1053",
   "technique_ja": "スケジュールされたタスク/ジョブ",
   "technique_en": "Scheduled Task/Job",
   "analytic_id": "AN0260",
   "detection_strategy_id": "DET0094",
   "analytic_name": "Analytic 0260",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (fs:fsusage) | Scheduled Job Creation (macos:osquery)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (fs:fsusage) | スケジュールジョブ作成 (macos:osquery)",
   "tuning": "PlistLabel | LaunchPath | JobRunInterval",
   "detection_logic_en": "Detects creation or alteration of LaunchAgents or LaunchDaemons with corresponding plist modification followed by execution of associated binaries."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1053",
   "technique_ja": "スケジュールされたタスク/ジョブ",
   "technique_en": "Scheduled Task/Job",
   "analytic_id": "AN0261",
   "detection_strategy_id": "DET0094",
   "analytic_name": "Analytic 0261",
   "platforms": "Containers",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Modification (containerd:runtime)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル変更 (containerd:runtime)",
   "tuning": "ContainerLabel | ScriptFrequency | ImageSource",
   "detection_logic_en": "Detects unusual use of `cron` or `sleep` loops inside containers executing unfamiliar scripts or binaries repeatedly."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1053",
   "technique_ja": "スケジュールされたタスク/ジョブ",
   "technique_en": "Scheduled Task/Job",
   "analytic_id": "AN0262",
   "detection_strategy_id": "DET0094",
   "analytic_name": "Analytic 0262",
   "platforms": "ESXi",
   "log_sources": "Scheduled Job Creation (esxi:vmkernel) | Command Execution (esxi:hostd) | File Modification (esxi:cron)",
   "log_sources_ja": "スケジュールジョブ作成 (esxi:vmkernel) | コマンド実行 (esxi:hostd) | ファイル変更 (esxi:cron)",
   "tuning": "StartupScriptName | ExecutionContext | PersistenceInterval",
   "detection_logic_en": "Detects modification of ESXi cron jobs, local.sh scripts, or scheduled API calls to persist custom binaries or shell scripts."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1053.002",
   "technique_ja": "At",
   "technique_en": "At",
   "analytic_id": "AN0943",
   "detection_strategy_id": "DET0333",
   "analytic_name": "Analytic 0943",
   "platforms": "Windows",
   "log_sources": "Scheduled Job Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "スケジュールジョブ作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TaskUser | ExecutionTimeWindow | CommandLinePattern",
   "detection_logic_en": "Detects creation of scheduled tasks via `at.exe` or WMI `Win32_ScheduledJob` class, followed by execution of anomalous processes by svchost.exe or taskeng.exe."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1053.002",
   "technique_ja": "At",
   "technique_en": "At",
   "analytic_id": "AN0944",
   "detection_strategy_id": "DET0333",
   "analytic_name": "Analytic 0944",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Modification (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL)",
   "tuning": "AtJobPath | ScheduleLatency | JobScriptEntropy",
   "detection_logic_en": "Detects usage of `at` command to schedule jobs, followed by job execution and modification of job files under /var/spool/cron/atjobs."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1053.002",
   "technique_ja": "At",
   "technique_en": "At",
   "analytic_id": "AN0945",
   "detection_strategy_id": "DET0333",
   "analytic_name": "Analytic 0945",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Modification (fs:fsusage) | Process Creation (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル変更 (fs:fsusage) | プロセス生成 (macos:osquery)",
   "tuning": "AtPermissions | ExecutionCommand | RunUser",
   "detection_logic_en": "Detects user or root invocation of `at` command to schedule a job, followed by job execution using LaunchServices and activity in /usr/lib/cron/at."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1053.003",
   "technique_ja": "Cron",
   "technique_en": "Cron",
   "analytic_id": "AN0805",
   "detection_strategy_id": "DET0290",
   "analytic_name": "Analytic 0805",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "CronFilePath | RunUser | ExecutionFrequency",
   "detection_logic_en": "Detects creation or modification of crontab entries by non-root users or from abnormal parent processes, followed by the execution of uncommon binaries at scheduled intervals."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1053.003",
   "technique_ja": "Cron",
   "technique_en": "Cron",
   "analytic_id": "AN0806",
   "detection_strategy_id": "DET0290",
   "analytic_name": "Analytic 0806",
   "platforms": "macOS",
   "log_sources": "Scheduled Job Creation (macos:unifiedlog) | File Modification (fs:fsusage)",
   "log_sources_ja": "スケジュールジョブ作成 (macos:unifiedlog) | ファイル変更 (fs:fsusage)",
   "tuning": "ScriptPath | CronScheduleSyntax | InteractiveUserContext",
   "detection_logic_en": "Detects crontab job additions or modifications via `crontab` utility or direct edits, especially those created by interactive users executing hidden or renamed scripts."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1053.003",
   "technique_ja": "Cron",
   "technique_en": "Cron",
   "analytic_id": "AN0807",
   "detection_strategy_id": "DET0290",
   "analytic_name": "Analytic 0807",
   "platforms": "ESXi",
   "log_sources": "File Modification (esxi:hostd) | Scheduled Job Creation (esxi:cron) | Process Creation (esxi:vmkernel)",
   "log_sources_ja": "ファイル変更 (esxi:hostd) | スケジュールジョブ作成 (esxi:cron) | プロセス生成 (esxi:vmkernel)",
   "tuning": "CrontabFileMonitored | ShellCommandPayload | JobInterval",
   "detection_logic_en": "Detects direct modification of crontab entries in /var/spool/cron/crontabs/root or /etc/rc.local.d/local.sh followed by execution of scripts linked to lateral movement or malware persistence."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1053.005",
   "technique_ja": "スケジュールされたタスク",
   "technique_en": "Scheduled Task",
   "analytic_id": "AN1221",
   "detection_strategy_id": "DET0441",
   "analytic_name": "Analytic 1221",
   "platforms": "Windows",
   "log_sources": "Scheduled Job Creation (WinEventLog:Security) | Scheduled Job Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "スケジュールジョブ作成 (WinEventLog:Security) | スケジュールジョブ変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext | TaskNamePattern | CommandLineEntropyThreshold",
   "detection_logic_en": "Detects the creation, modification, or deletion of scheduled tasks through Task Scheduler, WMI, PowerShell, or API-based methods followed by execution from svchost.exe or taskeng.exe. Includes detection of hidden or anomalous scheduled tasks, especially those created under SYSTEM or suspicious user contexts."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1053.006",
   "technique_ja": "systemdタイマー",
   "technique_en": "Systemd Timers",
   "analytic_id": "AN0645",
   "detection_strategy_id": "DET0231",
   "analytic_name": "Analytic 0645",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Scheduled Job Creation (linux:osquery)",
   "log_sources_ja": "ファイル作成 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | スケジュールジョブ作成 (linux:osquery)",
   "tuning": "TimerIntervalThreshold | ParentProcessID | UserContext | TimerCreationPath",
   "detection_logic_en": "Detects adversarial abuse of systemd timers by correlating file creation/modification of .timer and .service units in system directories with the execution of abnormal child processes launched by 'systemd' (PID 1), especially as root."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1053.007",
   "technique_ja": "コンテナオーケストレーションジョブ",
   "technique_en": "Container Orchestration Job",
   "analytic_id": "AN0582",
   "detection_strategy_id": "DET0206",
   "analytic_name": "Analytic 0582",
   "platforms": "Containers",
   "log_sources": "Scheduled Job Creation (kubernetes:apiserver) | Container Creation (kubernetes:events) | Network Traffic Content (container:proxy)",
   "log_sources_ja": "スケジュールジョブ作成 (kubernetes:apiserver) | コンテナ作成 (kubernetes:events) | ネットワークトラフィック内容 (container:proxy)",
   "tuning": "NamespaceScope | ImageRepository | ScheduleWindow | ExecutionCommand",
   "detection_logic_en": "Detects abuse of container orchestration platforms (e.g., Kubernetes) where adversaries create CronJobs to maintain persistence or execute malicious Jobs across the cluster."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1543",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1543",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | User Account Authentication (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | ユーザーアカウント認証 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "LogonType | TimeWindow | GeoIPMismatch",
   "detection_logic_en": "Detection of compromised or misused valid accounts via anomalous logon patterns, abnormal logon types, and inconsistent geographic or time-based activity across Windows endpoints."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1544",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1544",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | User Account Authentication (NSM:Connections)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ユーザーアカウント認証 (NSM:Connections)",
   "tuning": "UserContext | HostDensityThreshold | LoginMethod",
   "detection_logic_en": "Detection of valid account misuse through SSH logins, sudo/su abuse, and service account anomalies outside expected patterns."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1545",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1545",
   "platforms": "macOS",
   "log_sources": "Logon Session Metadata (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ログオンセッションメタデータ (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "LoginOrigin | ProcessTreeDepth",
   "detection_logic_en": "Detection of interactive and remote logins by service accounts or users at unusual times, with unexpected child process activity."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1546",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1546",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (saas:okta)",
   "log_sources_ja": "ユーザーアカウント認証 (saas:okta)",
   "tuning": "MFAFailureCount | RiskScoreThreshold | IPGeoVelocity",
   "detection_logic_en": "Detection of valid account abuse in IdP logs via geographic anomalies, impossible travel, risky sign-ins, and multiple MFA attempts or failures."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1547",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1547",
   "platforms": "Containers",
   "log_sources": "User Account Authentication (kubernetes:audit)",
   "log_sources_ja": "ユーザーアカウント認証 (kubernetes:audit)",
   "tuning": "ServiceAccountScope | ClusterIPWhitelist",
   "detection_logic_en": "Detection of containerized service accounts or compromised kubeconfigs being used for cluster access from unexpected nodes or IPs."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1283",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1283",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security)",
   "tuning": "UserContext | TimeWindow",
   "detection_logic_en": "Detection of default account usage such as Guest or Administrator performing interactive or remote logons on systems outside of installation or maintenance windows."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1284",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1284",
   "platforms": "Linux",
   "log_sources": "Logon Session Metadata (auditd:USER_LOGIN)",
   "log_sources_ja": "ログオンセッションメタデータ (auditd:USER_LOGIN)",
   "tuning": "SSHMethod | RemoteIPWhitelist",
   "detection_logic_en": "Monitoring for SSH logins from default accounts such as 'root', especially when login is via password and not key-based authentication."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1285",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1285",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (AWS:CloudTrail)",
   "log_sources_ja": "ユーザーアカウント認証 (AWS:CloudTrail)",
   "tuning": "AccountList | GeoLocation",
   "detection_logic_en": "Use of known default service accounts or root-level cloud accounts performing authentication or changes to IAM policy."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1286",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1286",
   "platforms": "ESXi",
   "log_sources": "User Account Authentication (esxi:auth)",
   "log_sources_ja": "ユーザーアカウント認証 (esxi:auth)",
   "tuning": "AccountName | IPRange",
   "detection_logic_en": "Abuse of system-generated or default privileged accounts such as 'root' or 'vpxuser' logging into ESXi hosts."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1287",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1287",
   "platforms": "Network Devices",
   "log_sources": "User Account Authentication (networkdevice:syslog)",
   "log_sources_ja": "ユーザーアカウント認証 (networkdevice:syslog)",
   "tuning": "Username | InterfaceType",
   "detection_logic_en": "Login activity from default admin credentials (e.g., 'admin', 'cisco') on routers, firewalls, and switches."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Accounts",
   "analytic_id": "AN0590",
   "detection_strategy_id": "DET0210",
   "analytic_name": "Analytic 0590",
   "platforms": "Windows",
   "log_sources": "Logon Session Metadata (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッションメタデータ (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext | LogonType",
   "detection_logic_en": "Detection of suspicious logon behavior using valid domain accounts across multiple hosts, off-hours, or simultaneous sessions from geographically distant locations."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Accounts",
   "analytic_id": "AN0591",
   "detection_strategy_id": "DET0210",
   "analytic_name": "Analytic 0591",
   "platforms": "Linux",
   "log_sources": "User Account Authentication (auditd:SYSCALL) | Logon Session Metadata (linux:syslog)",
   "log_sources_ja": "ユーザーアカウント認証 (auditd:SYSCALL) | ログオンセッションメタデータ (linux:syslog)",
   "tuning": "HostnameScope | AccountDomain",
   "detection_logic_en": "Use of domain accounts via sssd or winbind for logon activity outside of typical patterns, especially on sensitive systems or with lateral movement tools."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Accounts",
   "analytic_id": "AN0592",
   "detection_strategy_id": "DET0210",
   "analytic_name": "Analytic 0592",
   "platforms": "macOS",
   "log_sources": "User Account Authentication (macos:unifiedlog)",
   "log_sources_ja": "ユーザーアカウント認証 (macos:unifiedlog)",
   "tuning": "UserLocation | LogonMethod",
   "detection_logic_en": "Domain logins using network accounts or mobile accounts via Open Directory or Active Directory plugins, especially outside business hours or on atypical endpoints."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Accounts",
   "analytic_id": "AN0593",
   "detection_strategy_id": "DET0210",
   "analytic_name": "Analytic 0593",
   "platforms": "ESXi",
   "log_sources": "User Account Authentication (esxi:vpxd) | Logon Session Metadata (esxi:hostd)",
   "log_sources_ja": "ユーザーアカウント認証 (esxi:vpxd) | ログオンセッションメタデータ (esxi:hostd)",
   "tuning": "AccountType | LoginInterface",
   "detection_logic_en": "Login to vSphere or ESXi hosts using domain accounts, especially those associated with vpxuser or unexpected group memberships."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078.003",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Accounts",
   "analytic_id": "AN1137",
   "detection_strategy_id": "DET0407",
   "analytic_name": "Analytic 1137",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Logon Session Metadata (WinEventLog:Security)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | ログオンセッションメタデータ (WinEventLog:Security)",
   "tuning": "TimeWindow | UserContext",
   "detection_logic_en": "Detects anomalous usage of local accounts to log into a system, especially accounts not typically used interactively or outside business hours."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078.003",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Accounts",
   "analytic_id": "AN1138",
   "detection_strategy_id": "DET0407",
   "analytic_name": "Analytic 1138",
   "platforms": "Linux",
   "log_sources": "Logon Session Metadata (auditd:USER_LOGIN) | User Account Authentication (linux:auth)",
   "log_sources_ja": "ログオンセッションメタデータ (auditd:USER_LOGIN) | ユーザーアカウント認証 (linux:auth)",
   "tuning": "TimeWindow | HostRole",
   "detection_logic_en": "Detects interactive or service logins from local accounts outside expected operational context or at anomalous times."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078.003",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Accounts",
   "analytic_id": "AN1139",
   "detection_strategy_id": "DET0407",
   "analytic_name": "Analytic 1139",
   "platforms": "macOS",
   "log_sources": "Logon Session Metadata (macos:unifiedlog)",
   "log_sources_ja": "ログオンセッションメタデータ (macos:unifiedlog)",
   "tuning": "UserContext | TimeWindow",
   "detection_logic_en": "Detects abnormal or rare logins via local accounts through system or remote mechanisms such as SSH."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Accounts",
   "analytic_id": "AN1503",
   "detection_strategy_id": "DET0546",
   "analytic_name": "Analytic 1503",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (azure:signinlogs) | Logon Session Metadata (saas:okta)",
   "log_sources_ja": "ユーザーアカウント認証 (azure:signinlogs) | ログオンセッションメタデータ (saas:okta)",
   "tuning": "AnomalousLocationThreshold | ProtocolType",
   "detection_logic_en": "Detects anomalous authentication activity such as sign-ins from impossible geolocations or legacy protocols from high-privileged accounts."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Accounts",
   "analytic_id": "AN1504",
   "detection_strategy_id": "DET0546",
   "analytic_name": "Analytic 1504",
   "platforms": "IaaS",
   "log_sources": "User Account Authentication (AWS:CloudTrail) | Logon Session Creation (gcp:audit)",
   "log_sources_ja": "ユーザーアカウント認証 (AWS:CloudTrail) | ログオンセッション作成 (gcp:audit)",
   "tuning": "ServiceInteractionBaseline | RoleSwitchRateThreshold",
   "detection_logic_en": "Detects cloud account use for API calls that exceed normal scope, such as IAM changes or access to services never used before."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Accounts",
   "analytic_id": "AN1505",
   "detection_strategy_id": "DET0546",
   "analytic_name": "Analytic 1505",
   "platforms": "SaaS",
   "log_sources": "Logon Session Metadata (m365:unified) | User Account Authentication (gcp:audit)",
   "log_sources_ja": "ログオンセッションメタデータ (m365:unified) | ユーザーアカウント認証 (gcp:audit)",
   "tuning": "FileDownloadThreshold | SharingPolicyViolationThreshold",
   "detection_logic_en": "Detects unexpected access or usage of cloud productivity tools (e.g., downloading large numbers of files, creating external shares) by internal users."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1078.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Accounts",
   "analytic_id": "AN1506",
   "detection_strategy_id": "DET0546",
   "analytic_name": "Analytic 1506",
   "platforms": "Office Suite",
   "log_sources": "Logon Session Metadata (m365:signinlogs) | User Account Authentication (gcp:audit)",
   "log_sources_ja": "ログオンセッションメタデータ (m365:signinlogs) | ユーザーアカウント認証 (gcp:audit)",
   "tuning": "BusinessHours | OfficeProductivityToolBaseline",
   "detection_logic_en": "Detects login and usage patterns deviating from typical Microsoft 365 or Google Workspace user profiles."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098",
   "technique_ja": "アカウント操作",
   "technique_en": "Account Manipulation",
   "analytic_id": "AN0265",
   "detection_strategy_id": "DET0096",
   "analytic_name": "Analytic 0265",
   "platforms": "Windows",
   "log_sources": "User Account Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ユーザーアカウント変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | HighPrivilegeGroupList | SubjectTargetMismatch",
   "detection_logic_en": "Account attribute changes (e.g., password set, group membership, servicePrincipalName, logon hours) correlated with unusual process lineage or timing, indicating privilege escalation or persistence via valid accounts."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098",
   "technique_ja": "アカウント操作",
   "technique_en": "Account Manipulation",
   "analytic_id": "AN0266",
   "detection_strategy_id": "DET0096",
   "analytic_name": "Analytic 0266",
   "platforms": "Linux",
   "log_sources": "User Account Modification (auditd:SYSCALL) | File Modification (auditd:PATH)",
   "log_sources_ja": "ユーザーアカウント変更 (auditd:SYSCALL) | ファイル変更 (auditd:PATH)",
   "tuning": "SudoPath | ModifiedShellList",
   "detection_logic_en": "Use of native tools or scripting (e.g., `usermod`, `passwd`, `groupmod`) to escalate permissions or persist access on existing users, correlated with login or process events."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098",
   "technique_ja": "アカウント操作",
   "technique_en": "Account Manipulation",
   "analytic_id": "AN0267",
   "detection_strategy_id": "DET0096",
   "analytic_name": "Analytic 0267",
   "platforms": "macOS",
   "log_sources": "User Account Modification (macos:unifiedlog)",
   "log_sources_ja": "ユーザーアカウント変更 (macos:unifiedlog)",
   "tuning": "ModifiedUserList | GroupMembershipChanges",
   "detection_logic_en": "Modifications to user accounts via `dscl`, `pwpolicy`, or System Preferences CLI (`sysadminctl`) that alter user groups, enable root, or bypass MDM restrictions."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098",
   "technique_ja": "アカウント操作",
   "technique_en": "Account Manipulation",
   "analytic_id": "AN0268",
   "detection_strategy_id": "DET0096",
   "analytic_name": "Analytic 0268",
   "platforms": "Identity Provider",
   "log_sources": "User Account Modification (saas:okta)",
   "log_sources_ja": "ユーザーアカウント変更 (saas:okta)",
   "tuning": "RoleAssignmentBaseline | APIUsageContext",
   "detection_logic_en": "Modifications to SSO/SAML user attributes (e.g., `isAdmin`, `role`, MFA bypass, App assignments) often through CLI, API, or rogue IdP apps."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098",
   "technique_ja": "アカウント操作",
   "technique_en": "Account Manipulation",
   "analytic_id": "AN0269",
   "detection_strategy_id": "DET0096",
   "analytic_name": "Analytic 0269",
   "platforms": "ESXi",
   "log_sources": "Active Directory Object Modification (esxi:vpxa)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (esxi:vpxa)",
   "tuning": "VMAdminAccountName | NetworkAccessLocation",
   "detection_logic_en": "Addition of new users or changes to role permissions (e.g., ReadOnly -> Admin) via API or vSphere Client, particularly from non-jumpbox IPs."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098",
   "technique_ja": "アカウント操作",
   "technique_en": "Account Manipulation",
   "analytic_id": "AN0270",
   "detection_strategy_id": "DET0096",
   "analytic_name": "Analytic 0270",
   "platforms": "SaaS",
   "log_sources": "User Account Modification (m365:unified)",
   "log_sources_ja": "ユーザーアカウント変更 (m365:unified)",
   "tuning": "SharingSensitivityLabel | CrossOrgChanges",
   "detection_logic_en": "Role escalation (e.g., Editor → Owner) in cloud collaboration tools (Google Workspace, O365) or file sharing apps to maintain elevated access."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.001",
   "technique_ja": "追加のクラウド認証情報",
   "technique_en": "Additional Cloud Credentials",
   "analytic_id": "AN1469",
   "detection_strategy_id": "DET0531",
   "analytic_name": "Analytic 1469",
   "platforms": "Identity Provider",
   "log_sources": "User Account Modification (azure:audit)",
   "log_sources_ja": "ユーザーアカウント変更 (azure:audit)",
   "tuning": "MFABypassMechanism | SourceIPAllowlist | ApplicationCredentialType",
   "detection_logic_en": "Addition of credentials (keys, app passwords, x.509 certs) to existing cloud accounts, service principals, or OAuth apps via portal or API by non-standard identities or IP ranges."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.001",
   "technique_ja": "追加のクラウド認証情報",
   "technique_en": "Additional Cloud Credentials",
   "analytic_id": "AN1470",
   "detection_strategy_id": "DET0531",
   "analytic_name": "Analytic 1470",
   "platforms": "IaaS",
   "log_sources": "Active Directory Object Creation (AWS:CloudTrail) | User Account Modification (gcp:audit)",
   "log_sources_ja": "Active Directoryオブジェクト作成 (AWS:CloudTrail) | ユーザーアカウント変更 (gcp:audit)",
   "tuning": "CallerIdentityContext | NewCredentialUsageWindow | IAMRoleBaseline",
   "detection_logic_en": "Cloud API usage to create/import SSH keys or generate new access keys (CreateAccessKey, ImportKeyPair, CreateLoginProfile) from non-console access or unusual principals."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.001",
   "technique_ja": "追加のクラウド認証情報",
   "technique_en": "Additional Cloud Credentials",
   "analytic_id": "AN1471",
   "detection_strategy_id": "DET0531",
   "analytic_name": "Analytic 1471",
   "platforms": "SaaS",
   "log_sources": "User Account Modification (gcp:audit) | Active Directory Object Modification (m365:unified)",
   "log_sources_ja": "ユーザーアカウント変更 (gcp:audit) | Active Directoryオブジェクト変更 (m365:unified)",
   "tuning": "OAuthClientRedirectURIBaseline | TokenScopeSensitivity",
   "detection_logic_en": "Credential-related configuration changes in productivity apps, such as API key creation in Google Workspace, app tokens in Slack, or user-level OAuth credentials in M365."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.002",
   "technique_ja": "追加のメール委任権限",
   "technique_en": "Additional Email Delegate Permissions",
   "analytic_id": "AN1051",
   "detection_strategy_id": "DET0373",
   "analytic_name": "Analytic 1051",
   "platforms": "Office Suite",
   "log_sources": "User Account Modification (m365:unified)",
   "log_sources_ja": "ユーザーアカウント変更 (m365:unified)",
   "tuning": "DelegatePermissionLevel | FolderTargetScope | DelegatorToDelegatePairing | MailflowAnomalyThreshold",
   "detection_logic_en": "Detection of anomalous or unauthorized mailbox delegation activity (e.g., Add-MailboxPermission, Default/Anonymous mailbox permissions, Gmail delegation setup)."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.002",
   "technique_ja": "追加のメール委任権限",
   "technique_en": "Additional Email Delegate Permissions",
   "analytic_id": "AN1052",
   "detection_strategy_id": "DET0373",
   "analytic_name": "Analytic 1052",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Application Log Content (m365:unified)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | アプリケーションログ内容 (m365:unified)",
   "tuning": "PowerShellCmdletFilter | ExecutionParent | TimeWindow",
   "detection_logic_en": "Execution of PowerShell commands that modify mailbox permissions using Exchange cmdlets (e.g., Add-MailboxPermission), often tied to BEC or post-compromise persistence."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.003",
   "technique_ja": "追加のクラウドロール",
   "technique_en": "Additional Cloud Roles",
   "analytic_id": "AN0771",
   "detection_strategy_id": "DET0277",
   "analytic_name": "Analytic 0771",
   "platforms": "IaaS",
   "log_sources": "User Account Modification (AWS:CloudTrail)",
   "log_sources_ja": "ユーザーアカウント変更 (AWS:CloudTrail)",
   "tuning": "RoleScope | UserContext | PolicyChangeTimeWindow | ExternalRoleOrigin",
   "detection_logic_en": "Detection of new IAM roles or policies attached to a user/service in AWS/GCP/Azure outside normal patterns or hours, often following account compromise."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.003",
   "technique_ja": "追加のクラウドロール",
   "technique_en": "Additional Cloud Roles",
   "analytic_id": "AN0772",
   "detection_strategy_id": "DET0277",
   "analytic_name": "Analytic 0772",
   "platforms": "Identity Provider",
   "log_sources": "User Account Modification (m365:audit)",
   "log_sources_ja": "ユーザーアカウント変更 (m365:audit)",
   "tuning": "AdminRoleThreshold | RoleAssignmentMethod | GrantContext",
   "detection_logic_en": "Behavioral chain of a user being granted elevated privileges or roles in Entra ID or Okta following suspicious login or account creation activity."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.003",
   "technique_ja": "追加のクラウドロール",
   "technique_en": "Additional Cloud Roles",
   "analytic_id": "AN0773",
   "detection_strategy_id": "DET0277",
   "analytic_name": "Analytic 0773",
   "platforms": "Office Suite",
   "log_sources": "User Account Modification (m365:unified)",
   "log_sources_ja": "ユーザーアカウント変更 (m365:unified)",
   "tuning": "OfficeRoleType | TimeWindow | ActionOrigin",
   "detection_logic_en": "Detection of new admin or role assignment actions within Microsoft 365/O365 environments to elevate access for persistence or lateral movement."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.004",
   "technique_ja": "SSH認証鍵",
   "technique_en": "SSH Authorized Keys",
   "analytic_id": "AN0350",
   "detection_strategy_id": "DET0126",
   "analytic_name": "Analytic 0350",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "TimeWindow | UserContext | TargetPath",
   "detection_logic_en": "Adversary attempts to gain persistence by modifying ~/.ssh/authorized_keys via shell, text editor, echo or redirected output."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.004",
   "technique_ja": "SSH認証鍵",
   "technique_en": "SSH Authorized Keys",
   "analytic_id": "AN0351",
   "detection_strategy_id": "DET0126",
   "analytic_name": "Analytic 0351",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:auth)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:auth)",
   "tuning": "ParentProcess | InteractiveSessionFlag",
   "detection_logic_en": "Insertion of public keys into authorized_keys using bash/zsh or editor tools, correlated with suspicious process ancestry."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.004",
   "technique_ja": "SSH認証鍵",
   "technique_en": "SSH Authorized Keys",
   "analytic_id": "AN0352",
   "detection_strategy_id": "DET0126",
   "analytic_name": "Analytic 0352",
   "platforms": "IaaS",
   "log_sources": "File Modification (gcp:audit)",
   "log_sources_ja": "ファイル変更 (gcp:audit)",
   "tuning": "MetadataFieldName | AccountType | TargetRoleEscalation",
   "detection_logic_en": "Abuse of cloud metadata APIs or CLI to push SSH public keys to authorized_keys of virtual machines."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.004",
   "technique_ja": "SSH認証鍵",
   "technique_en": "SSH Authorized Keys",
   "analytic_id": "AN0353",
   "detection_strategy_id": "DET0126",
   "analytic_name": "Analytic 0353",
   "platforms": "ESXi",
   "log_sources": "File Modification (esxi:shell)",
   "log_sources_ja": "ファイル変更 (esxi:shell)",
   "tuning": "SSHConfigPath | ESXiShellActivity",
   "detection_logic_en": "Direct modification of /etc/ssh/keys-<user>/authorized_keys or enabling SSH in sshd_config to support public key auth."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.004",
   "technique_ja": "SSH認証鍵",
   "technique_en": "SSH Authorized Keys",
   "analytic_id": "AN0354",
   "detection_strategy_id": "DET0126",
   "analytic_name": "Analytic 0354",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:cli)",
   "log_sources_ja": "コマンド実行 (networkdevice:cli)",
   "tuning": "CLIUserRole | DeviceModel",
   "detection_logic_en": "Use of command-line like `ip ssh pubkey-chain` to bind SSH keys to privileged accounts on routers or switches."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.005",
   "technique_ja": "デバイス登録",
   "technique_en": "Device Registration",
   "analytic_id": "AN0103",
   "detection_strategy_id": "DET0036",
   "analytic_name": "Analytic 0103",
   "platforms": "Identity Provider",
   "log_sources": "User Account Modification (azure:audit) | Application Log Content (ApplicationLog:EntraIDPortal) | Active Directory Object Creation (azure:audit)",
   "log_sources_ja": "ユーザーアカウント変更 (azure:audit) | アプリケーションログ内容 (ApplicationLog:EntraIDPortal) | Active Directoryオブジェクト作成 (azure:audit)",
   "tuning": "ActorUserPrincipalName | IP Address | TimeWindow",
   "detection_logic_en": "Adversary registers new devices to compromised user accounts to bypass MFA or conditional access policies via Azure Entra ID, Okta, or Duo self-enrollment portals."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.005",
   "technique_ja": "デバイス登録",
   "technique_en": "Device Registration",
   "analytic_id": "AN0104",
   "detection_strategy_id": "DET0036",
   "analytic_name": "Analytic 0104",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Creation (WinEventLog:Security) | Application Log Content (ApplicationLog:Intune/MDM Logs)",
   "log_sources_ja": "Active Directoryオブジェクト作成 (WinEventLog:Security) | アプリケーションログ内容 (ApplicationLog:Intune/MDM Logs)",
   "tuning": "DeviceNamePattern | UserContext | EnrollmentMethod",
   "detection_logic_en": "Adversary registers a Windows device to Entra ID or bypasses conditional access by adding device via Intune registration pipeline using stolen credentials."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.006",
   "technique_ja": "追加のコンテナクラスタロール",
   "technique_en": "Additional Container Cluster Roles",
   "analytic_id": "AN1579",
   "detection_strategy_id": "DET0572",
   "analytic_name": "Analytic 1579",
   "platforms": "Containers",
   "log_sources": "User Account Modification (kubernetes:audit)",
   "log_sources_ja": "ユーザーアカウント変更 (kubernetes:audit)",
   "tuning": "UserAgent | RoleName | TimeWindow | UserContext",
   "detection_logic_en": "Detects assignment of high-privilege roles to user or service accounts via Kubernetes RoleBinding or ClusterRoleBinding objects, especially outside of CI/CD automation or from unknown IPs."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.007",
   "technique_ja": "追加のローカル/ドメイングループ",
   "technique_en": "Additional Local or Domain Groups",
   "analytic_id": "AN0865",
   "detection_strategy_id": "DET0310",
   "analytic_name": "Analytic 0865",
   "platforms": "Windows",
   "log_sources": "User Account Modification (WinEventLog:Security)",
   "log_sources_ja": "ユーザーアカウント変更 (WinEventLog:Security)",
   "tuning": "TargetGroup | TimeWindow | UserContext",
   "detection_logic_en": "Detects unauthorized additions of users or machine accounts to privileged local or domain groups (e.g., Administrators, Remote Desktop Users)."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.007",
   "technique_ja": "追加のローカル/ドメイングループ",
   "technique_en": "Additional Local or Domain Groups",
   "analytic_id": "AN0866",
   "detection_strategy_id": "DET0310",
   "analytic_name": "Analytic 0866",
   "platforms": "Linux",
   "log_sources": "User Account Modification (auditd:SYSCALL)",
   "log_sources_ja": "ユーザーアカウント変更 (auditd:SYSCALL)",
   "tuning": "GroupName | UserContext | TimeWindow",
   "detection_logic_en": "Detects unexpected use of usermod, gpasswd, or direct modification of /etc/group to elevate user group membership."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1098.007",
   "technique_ja": "追加のローカル/ドメイングループ",
   "technique_en": "Additional Local or Domain Groups",
   "analytic_id": "AN0867",
   "detection_strategy_id": "DET0310",
   "analytic_name": "Analytic 0867",
   "platforms": "macOS",
   "log_sources": "User Account Modification (macos:unifiedlog)",
   "log_sources_ja": "ユーザーアカウント変更 (macos:unifiedlog)",
   "tuning": "GroupName | UserContext | TimeWindow",
   "detection_logic_en": "Detects use of `dseditgroup` or `dscl` to add users to privileged macOS groups (e.g., admin)."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1112",
   "technique_ja": "レジストリの変更",
   "technique_en": "Modify Registry",
   "analytic_id": "AN0781",
   "detection_strategy_id": "DET0280",
   "analytic_name": "Analytic 0781",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "RegistryKeyPathPatterns | ParentProcessAllowList | TimeWindow | SignatureCheck",
   "detection_logic_en": "Behavior chain involving abnormal registry modifications via CLI, PowerShell, WMI, or direct API calls, especially targeting persistence, privilege escalation, or defense evasion keys, potentially followed by service restart or process execution. Such as editing Notify/Userinit/Startup keys, or disabling SafeDllSearchMode."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1133",
   "technique_ja": "外部リモートサービス",
   "technique_en": "External Remote Services",
   "analytic_id": "AN1004",
   "detection_strategy_id": "DET0354",
   "analytic_name": "Analytic 1004",
   "platforms": "Windows",
   "log_sources": "User Account Authentication (WinEventLog:Security) | Application Log Content (WinEventLog:Application) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ユーザーアカウント認証 (WinEventLog:Security) | アプリケーションログ内容 (WinEventLog:Application) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "BusinessHours | KnownRemoteIPs | FailedLogonThreshold | GeoIPWhitelist | TimeWindow",
   "detection_logic_en": "Unusual or unauthorized external remote access attempts (e.g., RDP, VPN, Citrix) → repeated failed logins followed by a successful session from uncommon geolocations or outside business hours → subsequent internal lateral movement or data exfiltration activities."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1133",
   "technique_ja": "外部リモートサービス",
   "technique_en": "External Remote Services",
   "analytic_id": "AN1005",
   "detection_strategy_id": "DET0354",
   "analytic_name": "Analytic 1005",
   "platforms": "Linux",
   "log_sources": "Logon Session Metadata (auditd:SYSCALL) | Application Log Content (NSM:Connections) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "ログオンセッションメタデータ (auditd:SYSCALL) | アプリケーションログ内容 (NSM:Connections) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "KnownSSHClients | FailedLogonThreshold | TimeWindow",
   "detection_logic_en": "Repeated SSH, VPN, or RDP gateway authentication attempts from external IPs → subsequent successful logon → remote shell or lateral movement activity (e.g., scp/sftp)."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1133",
   "technique_ja": "外部リモートサービス",
   "technique_en": "External Remote Services",
   "analytic_id": "AN1006",
   "detection_strategy_id": "DET0354",
   "analytic_name": "Analytic 1006",
   "platforms": "macOS",
   "log_sources": "Logon Session Metadata (macos:unifiedlog) | Network Connection Creation (macos:unifiedlog) | Network Traffic Flow (PF:Logs)",
   "log_sources_ja": "ログオンセッションメタデータ (macos:unifiedlog) | ネットワーク接続確立 (macos:unifiedlog) | ネットワークトラフィックフロー (PF:Logs)",
   "tuning": "KnownVNCServers | TimeWindow",
   "detection_logic_en": "Unexpected inbound or outbound VNC/SSH/Screen Sharing connections from external sources → repeated failed logins followed by success → remote interactive sessions or abnormal file transfers."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1133",
   "technique_ja": "外部リモートサービス",
   "technique_en": "External Remote Services",
   "analytic_id": "AN1007",
   "detection_strategy_id": "DET0354",
   "analytic_name": "Analytic 1007",
   "platforms": "Containers",
   "log_sources": "Application Log Content (ApplicationLog:API) | Logon Session Metadata (kubernetes:audit) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (ApplicationLog:API) | ログオンセッションメタデータ (kubernetes:audit) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "AllowedCIDRs | TimeWindow",
   "detection_logic_en": "Connections to exposed container services (e.g., Docker API, Kubernetes API server) from unauthorized external IPs → abnormal container creation/start → lateral activity within cluster nodes."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1136",
   "technique_ja": "アカウントの作成",
   "technique_en": "Create Account",
   "analytic_id": "AN1604",
   "detection_strategy_id": "DET0583",
   "analytic_name": "Analytic 1604",
   "platforms": "Windows",
   "log_sources": "User Account Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ユーザーアカウント作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | ParentProcessName | UserContext",
   "detection_logic_en": "Adversary uses built-in OS tools or API calls to create local or domain accounts for persistence or lateral movement. Tools such as 'net user', PowerShell, or MMC snap-ins may be used. Detection focuses on Event ID 4720 paired with process lineage and user context."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1136",
   "technique_ja": "アカウントの作成",
   "technique_en": "Create Account",
   "analytic_id": "AN1605",
   "detection_strategy_id": "DET0583",
   "analytic_name": "Analytic 1605",
   "platforms": "Linux",
   "log_sources": "User Account Creation (auditd:SYSCALL) | File Modification (auditd:SYSCALL)",
   "log_sources_ja": "ユーザーアカウント作成 (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL)",
   "tuning": "BinaryPath | ExecutionTime",
   "detection_logic_en": "Adversary invokes 'useradd', 'adduser', or equivalent system commands or scripts to create local users. Detection focuses on command execution and audit trail of passwd/shadow file modifications."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1136",
   "technique_ja": "アカウントの作成",
   "technique_en": "Create Account",
   "analytic_id": "AN1606",
   "detection_strategy_id": "DET0583",
   "analytic_name": "Analytic 1606",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Modification (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog)",
   "tuning": "UsernamePattern | ExecutionSource",
   "detection_logic_en": "Adversary creates new users using 'dscl' commands, GUI tools, or by modifying user plist files. Detection includes monitoring dscl invocation and user-related plist changes."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1136",
   "technique_ja": "アカウントの作成",
   "technique_en": "Create Account",
   "analytic_id": "AN1607",
   "detection_strategy_id": "DET0583",
   "analytic_name": "Analytic 1607",
   "platforms": "Identity Provider",
   "log_sources": "User Account Creation (azure:audit)",
   "log_sources_ja": "ユーザーアカウント作成 (azure:audit)",
   "tuning": "AdminThreshold | AutomationExemptions",
   "detection_logic_en": "Adversary creates users via IAM/IdP API or portal (e.g., Azure AD, Okta). Detection involves monitoring API calls, admin action logs, and correlation with role assignments."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1136",
   "technique_ja": "アカウントの作成",
   "technique_en": "Create Account",
   "analytic_id": "AN1608",
   "detection_strategy_id": "DET0583",
   "analytic_name": "Analytic 1608",
   "platforms": "IaaS",
   "log_sources": "User Account Creation (AWS:CloudTrail) | User Account Modification (AWS:CloudTrail)",
   "log_sources_ja": "ユーザーアカウント作成 (AWS:CloudTrail) | ユーザーアカウント変更 (AWS:CloudTrail)",
   "tuning": "Region | ServiceScope",
   "detection_logic_en": "Account creation via cloud service APIs or CLI, often associated with key generation. Monitored via CloudTrail or equivalent audit logs."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1136.001",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Account",
   "analytic_id": "AN1235",
   "detection_strategy_id": "DET0447",
   "analytic_name": "Analytic 1235",
   "platforms": "Windows",
   "log_sources": "User Account Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ユーザーアカウント作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "ParentProcessName | TimeWindow | UserContext",
   "detection_logic_en": "Adversary uses built-in tools like 'net user /add', PowerShell, or WMI to create a local user. Sequence: Account creation event (4720) follows process creation of a suspicious executable (e.g., powershell.exe or net.exe)."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1136.001",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Account",
   "analytic_id": "AN1236",
   "detection_strategy_id": "DET0447",
   "analytic_name": "Analytic 1236",
   "platforms": "Linux",
   "log_sources": "User Account Creation (auditd:SYSCALL) | File Modification (auditd:SYSCALL)",
   "log_sources_ja": "ユーザーアカウント作成 (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL)",
   "tuning": "BinaryPath | ExecutionSource",
   "detection_logic_en": "Local user accounts are created via binaries like 'useradd', 'adduser', or by editing passwd/shadow. Behavior chain includes execution of user management binaries or modification of user database files."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1136.001",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Account",
   "analytic_id": "AN1237",
   "detection_strategy_id": "DET0447",
   "analytic_name": "Analytic 1237",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Modification (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog)",
   "tuning": "UsernamePattern | SessionOrigin",
   "detection_logic_en": "Account creation using 'dscl -create' or via GUI tools. Detection involves command execution and file changes to the local directory services database."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1136.001",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Account",
   "analytic_id": "AN1238",
   "detection_strategy_id": "DET0447",
   "analytic_name": "Analytic 1238",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:vmkernel)",
   "log_sources_ja": "コマンド実行 (esxi:vmkernel)",
   "tuning": "CommandOrigin",
   "detection_logic_en": "Account created using esxcli commands. Sequence includes esxcli execution and successful modification to account DB."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1136.001",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Account",
   "analytic_id": "AN1239",
   "detection_strategy_id": "DET0447",
   "analytic_name": "Analytic 1239",
   "platforms": "Containers",
   "log_sources": "Command Execution (ebpf:syscalls)",
   "log_sources_ja": "コマンド実行 (ebpf:syscalls)",
   "tuning": "ContainerContext | NamespaceScope",
   "detection_logic_en": "Account created in a running container (e.g., via 'useradd' or by modifying /etc/passwd directly). Detectable via runtime telemetry (e.g., Falco or eBPF hooks)."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1136.001",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Account",
   "analytic_id": "AN1240",
   "detection_strategy_id": "DET0447",
   "analytic_name": "Analytic 1240",
   "platforms": "Network Devices",
   "log_sources": "User Account Creation (networkdevice:syslog)",
   "log_sources_ja": "ユーザーアカウント作成 (networkdevice:syslog)",
   "tuning": "PrivilegeLevel | RemoteSessionFlag",
   "detection_logic_en": "Account created via CLI using 'username' command or REST API. Detectable through AAA logging or CLI history telemetry."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1136.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Account",
   "analytic_id": "AN0006",
   "detection_strategy_id": "DET0003",
   "analytic_name": "Analytic 0006",
   "platforms": "Windows",
   "log_sources": "User Account Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ユーザーアカウント作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | ParentProcessName | UserContext | HostRole",
   "detection_logic_en": "Adversary uses built-in tools such as 'net user /add /domain' or PowerShell to create a domain user account. The behavior chain includes: (1) suspicious process execution on a domain controller followed by (2) user account creation event (Event ID 4720) on the same host."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1136.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Account",
   "analytic_id": "AN0007",
   "detection_strategy_id": "DET0003",
   "analytic_name": "Analytic 0007",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | User Account Authentication (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ユーザーアカウント認証 (NSM:Flow)",
   "tuning": "DomainToolUsed | TrafficWindow | SessionType",
   "detection_logic_en": "Adversary with access to domain management tools (e.g., `realmd`, `samba-tool`, `ldapmodify`) creates a new domain user via command-line utilities. Behavior chain: LDAP command or script triggers → user entry added in AD via Kerberos/LDAP traffic."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1136.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Account",
   "analytic_id": "AN0008",
   "detection_strategy_id": "DET0003",
   "analytic_name": "Analytic 0008",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Logon Session Creation (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ログオンセッション作成 (macos:unifiedlog)",
   "tuning": "EnrollmentStatus | AccountType",
   "detection_logic_en": "macOS clients joined to AD via LDAP may script account provisioning via `dsconfigad`, `dscl`, or LDAP scripts. Detection occurs when such tools run on a domain-joined system, followed by authentication attempts by a previously unseen account."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1136.003",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Account",
   "analytic_id": "AN0899",
   "detection_strategy_id": "DET0319",
   "analytic_name": "Analytic 0899",
   "platforms": "Identity Provider",
   "log_sources": "User Account Creation (azure:audit) | User Account Modification (azure:audit) | User Account Authentication (azure:signinlogs)",
   "log_sources_ja": "ユーザーアカウント作成 (azure:audit) | ユーザーアカウント変更 (azure:audit) | ユーザーアカウント認証 (azure:signinlogs)",
   "tuning": "IPAddress | RoleThreshold | ServicePrincipalFlag",
   "detection_logic_en": "Adversaries create user accounts via identity provider APIs or admin portals (e.g., Azure AD, Okta). These accounts may be assigned elevated privileges or used in chained authentication. Detection monitors Add User activity from suspicious IPs or automation sources, followed by role/permission escalation."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1136.003",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Account",
   "analytic_id": "AN0900",
   "detection_strategy_id": "DET0319",
   "analytic_name": "Analytic 0900",
   "platforms": "IaaS",
   "log_sources": "User Account Creation (AWS:CloudTrail) | User Account Modification (AWS:CloudTrail)",
   "log_sources_ja": "ユーザーアカウント作成 (AWS:CloudTrail) | ユーザーアカウント変更 (AWS:CloudTrail)",
   "tuning": "Region | TimeWindow | UserAgent",
   "detection_logic_en": "Adversaries use cloud API, CLI, or console to create IAM users or roles. Initial CreateUser is followed by policy/role attachment. Detection monitors temporal chains involving IAM:CreateUser, AttachUserPolicy, and credential generation, especially from automation or foreign IP ranges."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1136.003",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Account",
   "analytic_id": "AN0901",
   "detection_strategy_id": "DET0319",
   "analytic_name": "Analytic 0901",
   "platforms": "SaaS",
   "log_sources": "User Account Creation (saas:zoom)",
   "log_sources_ja": "ユーザーアカウント作成 (saas:zoom)",
   "tuning": "ApplicationScope | AdminUserList",
   "detection_logic_en": "Adversaries create SaaS accounts via admin dashboards or integrations (e.g., Zoom, Salesforce, Slack). Monitor lifecycle.create or account provisioning events from non-standard sources or times."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1136.003",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Account",
   "analytic_id": "AN0902",
   "detection_strategy_id": "DET0319",
   "analytic_name": "Analytic 0902",
   "platforms": "Office Suite",
   "log_sources": "User Account Creation (m365:unified) | Group Modification (m365:unified)",
   "log_sources_ja": "ユーザーアカウント作成 (m365:unified) | グループ変更 (m365:unified)",
   "tuning": "GroupSensitivity | GuestFlag",
   "detection_logic_en": "Adversaries leverage M365 or Google Workspace APIs to create users, service accounts, or guest accounts. Follow-on behaviors include login activity, role escalation, or service principal token generation."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1137",
   "technique_ja": "Officeアプリ起動",
   "technique_en": "Office Application Startup",
   "analytic_id": "AN1116",
   "detection_strategy_id": "DET0398",
   "analytic_name": "Analytic 1116",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | Application Log Content (WinEventLog:Application)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | アプリケーションログ内容 (WinEventLog:Application)",
   "tuning": "ParentProcessName | RegistryPath | TimeWindow | UserContext",
   "detection_logic_en": "Office-based persistence via Office template macros, Outlook forms/rules/homepage, or registry-persistent scripts. Adversary modifies registry keys or Office application directories to load malicious scripts at startup."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1137",
   "technique_ja": "Officeアプリ起動",
   "technique_en": "Office Application Startup",
   "analytic_id": "AN1117",
   "detection_strategy_id": "DET0398",
   "analytic_name": "Analytic 1117",
   "platforms": "Office Suite",
   "log_sources": "User Account Modification (m365:unified) | Application Log Content (m365:mailboxaudit)",
   "log_sources_ja": "ユーザーアカウント変更 (m365:unified) | アプリケーションログ内容 (m365:mailboxaudit)",
   "tuning": "RuleAction | MailboxTarget | TimeWindow",
   "detection_logic_en": "Startup-based persistence mechanisms within Microsoft Office Suite like template macros and home page redirects being configured through internal automation or client-side settings."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1137.001",
   "technique_ja": "Officeテンプレートマクロ",
   "technique_en": "Office Template Macros",
   "analytic_id": "AN1436",
   "detection_strategy_id": "DET0519",
   "analytic_name": "Analytic 1436",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | Command Execution (WinEventLog:Microsoft-Office-Alerts)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:Microsoft-Office-Alerts)",
   "tuning": "TemplatePath | RegistryPath | TimeWindow | UserContext",
   "detection_logic_en": "Adversaries inject VBA macros into Office templates such as Normal.dotm or Personal.xlsb or redirect Office template load path via registry key (GlobalDotName) to gain persistence. Template macros trigger execution of malicious code on application startup."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1137.001",
   "technique_ja": "Officeテンプレートマクロ",
   "technique_en": "Office Template Macros",
   "analytic_id": "AN1437",
   "detection_strategy_id": "DET0519",
   "analytic_name": "Analytic 1437",
   "platforms": "Office Suite",
   "log_sources": "Command Execution (m365:unified)",
   "log_sources_ja": "コマンド実行 (m365:unified)",
   "tuning": "TemplateSource | MacroSecurityLevel",
   "detection_logic_en": "Malicious VBA macros embedded in base templates like Normal.dotm or Personal.xlsb are automatically loaded and executed at startup. Template path may be hijacked to load a remote or attacker-controlled template via GlobalDotName registry setting."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1137.002",
   "technique_ja": "Office Test",
   "technique_en": "Office Test",
   "analytic_id": "AN0880",
   "detection_strategy_id": "DET0315",
   "analytic_name": "Analytic 0880",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:Microsoft-Office-Alerts)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:Microsoft-Office-Alerts)",
   "tuning": "RegistryPath | DLLPath | OfficeProcessName | TimeWindow | UserContext",
   "detection_logic_en": "Adversaries create the 'Office Test\\Special\\Perf' registry key and specify a malicious DLL path that is auto-loaded when an Office application starts. This DLL is injected into the Office process memory space and can provide persistent execution without requiring macro enablement."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1137.002",
   "technique_ja": "Office Test",
   "technique_en": "Office Test",
   "analytic_id": "AN0881",
   "detection_strategy_id": "DET0315",
   "analytic_name": "Analytic 0881",
   "platforms": "Office Suite",
   "log_sources": "Module Load (m365:unified) | Command Execution (m365:office)",
   "log_sources_ja": "モジュール読み込み (m365:unified) | コマンド実行 (m365:office)",
   "tuning": "TrustedLocationBypass | AuditPolicyScope",
   "detection_logic_en": "Office application auto-loads a non-standard DLL during startup triggered via Office Test Registry key, often without macro warning banners. DLL persistence mechanism circumvents traditional macro defenses."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1137.003",
   "technique_ja": "Outlookフォーム",
   "technique_en": "Outlook Forms",
   "analytic_id": "AN0085",
   "detection_strategy_id": "DET0029",
   "analytic_name": "Analytic 0085",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Application Log Content (WinEventLog:Application) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | アプリケーションログ内容 (WinEventLog:Application) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "FormStorageLocation | ChildProcessName | TimeWindow | OutlookVersion | UserContext",
   "detection_logic_en": "Adversary uses a tool like Ruler to insert a malicious custom form into the user's Outlook mailbox. The form is designed to auto-execute on Outlook startup or on receipt of a specially crafted email. This results in child processes launched from outlook.exe and possibly network connections or payload loading."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1137.003",
   "technique_ja": "Outlookフォーム",
   "technique_en": "Outlook Forms",
   "analytic_id": "AN0086",
   "detection_strategy_id": "DET0029",
   "analytic_name": "Analytic 0086",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified) | Command Execution (m365:messagetrace)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | コマンド実行 (m365:messagetrace)",
   "tuning": "AuditPolicyScope | MessageSenderAnomalyThreshold | FormExecutionRate",
   "detection_logic_en": "Outlook form execution upon message receipt or client launch results in automated code execution within user session. Form definitions deviate from standard templates and include script logic or COM object calls embedded in form fields."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1137.004",
   "technique_ja": "Outlookホームページ",
   "technique_en": "Outlook Home Page",
   "analytic_id": "AN0502",
   "detection_strategy_id": "DET0177",
   "analytic_name": "Analytic 0502",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Application Log Content (WinEventLog:Application) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | アプリケーションログ内容 (WinEventLog:Application) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "TargetFolder | HTMLPayloadLocation | ChildProcessName | TimeWindow | FormViewBehavior",
   "detection_logic_en": "Adversary uses a tool like Ruler to configure a malicious Outlook folder Home Page that loads a remote or embedded HTML payload upon folder interaction. Execution chain begins with Outlook launching, a specific folder being accessed, and a suspicious child process being spawned or COM-based execution invoked."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1137.004",
   "technique_ja": "Outlookホームページ",
   "technique_en": "Outlook Home Page",
   "analytic_id": "AN0503",
   "detection_strategy_id": "DET0177",
   "analytic_name": "Analytic 0503",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified) | Command Execution (m365:messagetrace)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | コマンド実行 (m365:messagetrace)",
   "tuning": "AuditPolicyScope | FolderAccessRate | ExternalURLAllowlist",
   "detection_logic_en": "Malicious HTML or script is rendered as a Home Page for a specific Outlook folder. Outlook accesses that folder, loads remote content, and executes embedded JavaScript or ActiveX/COM logic resulting in unauthorized actions or local execution."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1137.005",
   "technique_ja": "Outlookルール",
   "technique_en": "Outlook Rules",
   "analytic_id": "AN0263",
   "detection_strategy_id": "DET0095",
   "analytic_name": "Analytic 0263",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Application Log Content (WinEventLog:Application) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | アプリケーションログ内容 (WinEventLog:Application) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "ChildProcessName | RuleTriggerCondition | ParentProcessName | TimeWindow",
   "detection_logic_en": "Adversary uses a tool like Ruler or MFCMapi to create a malicious Outlook rule that triggers execution upon receipt of a crafted email. On email delivery, Outlook executes the rule, resulting in code execution (e.g., launching mshta.exe or PowerShell). Outlook spawns a non-standard child process, often unsanctioned, without user interaction."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1137.005",
   "technique_ja": "Outlookルール",
   "technique_en": "Outlook Rules",
   "analytic_id": "AN0264",
   "detection_strategy_id": "DET0095",
   "analytic_name": "Analytic 0264",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified) | Command Execution (m365:messagetrace)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | コマンド実行 (m365:messagetrace)",
   "tuning": "AuditPolicyScope | RuleProviderName | TriggerSubjectKeywords | UserContext",
   "detection_logic_en": "Adversary adds a new Outlook rule with modified or obfuscated PR_RULE_MSG_NAME and PR_RULE_MSG_PROVIDER attributes using MFCMapi or Ruler. Rule is triggered when email arrives, executing embedded or external code. Mailbox audit logs or Unified Audit Log shows automated rule-triggered action without user interaction."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1137.006",
   "technique_ja": "アドイン",
   "technique_en": "Add-ins",
   "analytic_id": "AN0137",
   "detection_strategy_id": "DET0050",
   "analytic_name": "Analytic 0137",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | File Modification (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "AddInExtension | TrustedPath | RegistryPath | ChildProcessName | TimeWindow",
   "detection_logic_en": "An adversary writes or drops a malicious Office Add-in (e.g., WLL, XLL, COM) to a trusted directory or modifies registry keys to load malicious add-ins on Office application launch. Upon user opening Word or Excel, the add-in is automatically loaded, triggering execution of the payload, often spawning scripting engines or anomalous child processes."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1137.006",
   "technique_ja": "アドイン",
   "technique_en": "Add-ins",
   "analytic_id": "AN0138",
   "detection_strategy_id": "DET0050",
   "analytic_name": "Analytic 0138",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (WinEventLog:Application) | Command Execution (WinEventLog:Microsoft-Office/OutlookAddinMonitor)",
   "log_sources_ja": "アプリケーションログ内容 (WinEventLog:Application) | コマンド実行 (WinEventLog:Microsoft-Office/OutlookAddinMonitor)",
   "tuning": "UnsignedAddInBehavior | OfficeProductVersion | AddInTrigger",
   "detection_logic_en": "Malicious Office add-ins loaded via VSTO, COM, or VBA auto-load paths. Upon launch of Word/Excel/Outlook, the add-in executes code without user action. Add-in resides in trusted directory or registered via Office COM/VBE subsystem. Behavior includes unsigned add-in execution, anomalous load context, or add-in spawning interpreter process."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1176",
   "technique_ja": "ソフトウェア拡張機能",
   "technique_en": "Software Extensions",
   "analytic_id": "AN0251",
   "detection_strategy_id": "DET0092",
   "analytic_name": "Analytic 0251",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "Image | ParentImage | RegistryPath | TimeWindow",
   "detection_logic_en": "Installation or execution of a malicious browser or IDE extension, followed by abnormal registry entries or outbound network connections from the host application"
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1176",
   "technique_ja": "ソフトウェア拡張機能",
   "technique_en": "Software Extensions",
   "analytic_id": "AN0252",
   "detection_strategy_id": "DET0092",
   "analytic_name": "Analytic 0252",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Creation (macos:unifiedlog) | Network Traffic Flow (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル作成 (macos:unifiedlog) | ネットワークトラフィックフロー (macos:unifiedlog)",
   "tuning": "PlistPath | CommandLine | TimeWindow",
   "detection_logic_en": "Installation of configuration profiles or plist entries associated with malicious or unauthorized browser extensions"
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1176",
   "technique_ja": "ソフトウェア拡張機能",
   "technique_en": "Software Extensions",
   "analytic_id": "AN0253",
   "detection_strategy_id": "DET0092",
   "analytic_name": "Analytic 0253",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Creation (fs:fileevents) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル作成 (fs:fileevents) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "DirectoryPath | ExecPath | TimeWindow",
   "detection_logic_en": "Manual or script-based installation of extension-like modules into browser config directories or IDE plugin paths, followed by suspicious network activity"
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1176.001",
   "technique_ja": "ブラウザ拡張機能",
   "technique_en": "Browser Extensions",
   "analytic_id": "AN0123",
   "detection_strategy_id": "DET0044",
   "analytic_name": "Analytic 0123",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "UserContext | BrowserExecutablePath | ExtensionInstallPath",
   "detection_logic_en": "Installation of a new browser extension followed by suspicious file writes or outbound network connections to untrusted domains by the browser process."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1176.001",
   "technique_ja": "ブラウザ拡張機能",
   "technique_en": "Browser Extensions",
   "analytic_id": "AN0124",
   "detection_strategy_id": "DET0044",
   "analytic_name": "Analytic 0124",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Creation (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル作成 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "PlistPath | CommandLineFlags",
   "detection_logic_en": "Installation of malicious .mobileconfig profiles or browser extension plist entries followed by abnormal browser child process activity."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1176.001",
   "technique_ja": "ブラウザ拡張機能",
   "technique_en": "Browser Extensions",
   "analytic_id": "AN0125",
   "detection_strategy_id": "DET0044",
   "analytic_name": "Analytic 0125",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Network Traffic Content (NSM:Flow) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "ExtensionDir | DomainWatchlist",
   "detection_logic_en": "Manual or scripted installation of Chrome extensions using user scripts or config files, followed by unexpected network connections from browser processes."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1176.002",
   "technique_ja": "IDE拡張機能",
   "technique_en": "IDE Extensions",
   "analytic_id": "AN1548",
   "detection_strategy_id": "DET0561",
   "analytic_name": "Analytic 1548",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "IDEList | SuspiciousCLI | ServerZones | AllowedHosts | TimeWindow",
   "detection_logic_en": "Adversary installs or side-loads an IDE extension (VS Code, IntelliJ/JetBrains, Eclipse) or enables IDE tunneling. Chain: (1) IDE binary starts on a non-developer endpoint or server, often with install/force/tunnel flags → (2) extension files/registrations appear under user profile → (3) browser/IDE initiates outbound connections to extension marketplaces, update endpoints, or IDE remote/tunnel services → (4) optional child tools (ssh, node, powershell) execute under the IDE context."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1176.002",
   "technique_ja": "IDE拡張機能",
   "technique_en": "IDE Extensions",
   "analytic_id": "AN1549",
   "detection_strategy_id": "DET0561",
   "analytic_name": "Analytic 1549",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル作成 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "IDEPaths | DomainAllowlist | UserRoleScope | TimeWindow",
   "detection_logic_en": "Adversary installs or abuses IDE extensions via CLI or direct write to profile directories and then communicates with marketplaces or remote tunnel services. Chain: auditd execve (code/idea/eclipse) with install/update flags or writes under ~/.vscode/extensions, ~/.config/JetBrains → outbound flows to *.visualstudio.com, marketplace.visualstudio.com, *.jetbrains.com, githubusercontent.com, or SSH/WebSocket tunnel endpoints → optional ssh/node processes spawned by IDE."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1176.002",
   "technique_ja": "IDE拡張機能",
   "technique_en": "IDE Extensions",
   "analytic_id": "AN1550",
   "detection_strategy_id": "DET0561",
   "analytic_name": "Analytic 1550",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (macos:unifiedlog) | Network Traffic Flow (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:unifiedlog) | ネットワークトラフィックフロー (macos:unifiedlog)",
   "tuning": "PlistLocations | MDMProfiles | TimeWindow",
   "detection_logic_en": "Adversary adds IDE extensions or plugins (VS Code, JetBrains Toolbox/EAP, Eclipse) via GUI or CLI, possibly via managed profiles. Chain: process start with install/update flags → plist/extension folder changes under ~/Library/Application Support/Code or ~/Library/Application Support/JetBrains → outbound connections to marketplaces/tunnel services → optional helper (ssh/node) spawned."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1197",
   "technique_ja": "BITSジョブ",
   "technique_en": "BITS Jobs",
   "analytic_id": "AN0274",
   "detection_strategy_id": "DET0098",
   "analytic_name": "Analytic 0274",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | Service Creation (WinEventLog:System)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | サービス作成 (WinEventLog:System)",
   "tuning": "TimeWindow | ExpectedUpdateHosts | SuspiciousCliSwitches | NotifyCmdBlockList | UserContext | ExternalNetCIDRs | JobLifetimeThreshold",
   "detection_logic_en": "Behavioral chain: (1) An actor creates or modifies a BITS job via bitsadmin.exe, PowerShell BITS cmdlets, or COM; (2) the job performs HTTP(S)/SMB network transfers while the owning user is logged on; (3) upon job completion/error, BITS launches a notify command (SetNotifyCmdLine) from svchost.exe -k netsvcs -s BITS, often establishing persistence by keeping long-lived jobs. The strategy correlates process creation, command/script telemetry, BITS-Client operational events, and network connections initiated by BITS."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1205",
   "technique_ja": "トラフィックシグナリング",
   "technique_en": "Traffic Signaling",
   "analytic_id": "AN1448",
   "detection_strategy_id": "DET0524",
   "analytic_name": "Analytic 1448",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Flow (WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィックフロー (WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "TimeWindowKnock | PortSequenceMinLen | SuspiciousProcesses | AllowedFirewallChangers | WoLAllowedWindows",
   "detection_logic_en": "A remote host sends a short sequence of failed connection attempts (RST/ICMP unreachable) to a set of closed ports. Within a brief window the endpoint (a) adds/enables a firewall rule or (b) a sniffer-backed process begins listening or opens a new socket, after which a successful connection occurs. Also detects Wake-on-LAN magic packets seen on local segment."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1205",
   "technique_ja": "トラフィックシグナリング",
   "technique_en": "Traffic Signaling",
   "analytic_id": "AN1449",
   "detection_strategy_id": "DET0524",
   "analytic_name": "Analytic 1449",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ServicePort | KnockResetRatio | ProcessAllowList",
   "detection_logic_en": "Closed-port knock sequence from a remote IP followed by on-host firewall change (iptables/nftables) or daemon starts listening (socket open) and a successful TCP/UDP connect. Optional detection of libpcap/raw-socket sniffers spawning to watch for secret values."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1205",
   "technique_ja": "トラフィックシグナリング",
   "technique_en": "Traffic Signaling",
   "analytic_id": "AN1450",
   "detection_strategy_id": "DET0524",
   "analytic_name": "Analytic 1450",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Flow (macos:unifiedlog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィックフロー (macos:unifiedlog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "PFAnchorPaths | DeveloperMode",
   "detection_logic_en": "Remote knock sequence followed by PF/socketfilterfw rule update or a background process listening on a new port; then a successful TCP session. Also flags WoL magic packets on local segment."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1205",
   "technique_ja": "トラフィックシグナリング",
   "technique_en": "Traffic Signaling",
   "analytic_id": "AN1451",
   "detection_strategy_id": "DET0524",
   "analytic_name": "Analytic 1451",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Flow (networkdevice:syslog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィックフロー (networkdevice:syslog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "MgmtPortSet | DeviceRole",
   "detection_logic_en": "Crafted ‘synful knock’ patterns toward routers/switches (same src hits interface/broadcast/network address on same port in short order) followed by ACL/telnet/SSH enablement or module change. Detect device image/ACL updates then a new mgmt session."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1205.001",
   "technique_ja": "ポートノッキング",
   "technique_en": "Port Knocking",
   "analytic_id": "AN0842",
   "detection_strategy_id": "DET0302",
   "analytic_name": "Analytic 0842",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Flow (WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィックフロー (WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall)",
   "tuning": "TimeWindow | MinSequenceLen | RuleChangeAllowList | WatchedPorts",
   "detection_logic_en": "A remote source rapidly touches a short sequence of closed ports (SYN→RST/S0) on a Windows host. Within a short window the host changes firewall state (WFP rule added/modified or service starts listening) and then the same source completes the first successful handshake to the newly opened port."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1205.001",
   "technique_ja": "ポートノッキング",
   "technique_en": "Port Knocking",
   "analytic_id": "AN0843",
   "detection_strategy_id": "DET0302",
   "analytic_name": "Analytic 0843",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "ServicePort | KnockTolerance | MgmtAllowList",
   "detection_logic_en": "A source performs a short closed-port sequence; the host then modifies iptables/nftables/ufw rules or starts a daemon binding a new socket, followed by a successful connection from the same source."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1205.001",
   "technique_ja": "ポートノッキング",
   "technique_en": "Port Knocking",
   "analytic_id": "AN0844",
   "detection_strategy_id": "DET0302",
   "analytic_name": "Analytic 0844",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Flow (macos:unifiedlog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィックフロー (macos:unifiedlog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "PFAnchorPaths | DevMode",
   "detection_logic_en": "A source performs a closed-port sequence; the endpoint enables a PF/socketfilterfw rule or a background process binds a port; then a successful connection completes from the same source."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1205.001",
   "technique_ja": "ポートノッキング",
   "technique_en": "Port Knocking",
   "analytic_id": "AN0845",
   "detection_strategy_id": "DET0302",
   "analytic_name": "Analytic 0845",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Flow (networkdevice:syslog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィックフロー (networkdevice:syslog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "MgmtPortSet | DeviceRole",
   "detection_logic_en": "Router/switch receives a knock pattern (same src touches device unicast, broadcast, and network-address on same or stepped ports) followed by ACL/line-vty/service enable and the first mgmt session success."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1205.002",
   "technique_ja": "ソケットフィルタ",
   "technique_en": "Socket Filters",
   "analytic_id": "AN0462",
   "detection_strategy_id": "DET0162",
   "analytic_name": "Analytic 0462",
   "platforms": "Windows",
   "log_sources": "Service Creation (WinEventLog:System) | Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Driver Load (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "サービス作成 (WinEventLog:System) | プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ドライバ読み込み (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TimeWindow | CaptureLibIndicators | AllowedInstallers | ReversePorts",
   "detection_logic_en": "Adversary installs/uses packet-capture or raw-socket capability (WinPcap/Npcap, wpcap/packet DLLs or raw socket attach) and sets a filter. A crafted inbound packet is observed; within a short window the host process that loaded capture libraries initiates an outbound connection (e.g., reverse shell) to the packet origin."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1205.002",
   "technique_ja": "ソケットフィルタ",
   "technique_en": "Socket Filters",
   "analytic_id": "AN0463",
   "detection_strategy_id": "DET0162",
   "analytic_name": "Analytic 0463",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (linux:osquery) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (linux:osquery) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "UserContext | MinPayloadEntropy | AFPacketAllowList",
   "detection_logic_en": "Process creates a raw/packet socket and attaches a (e)BPF filter (setsockopt SO_ATTACH_FILTER/ATTACH_BPF or bpf(BPF_PROG_LOAD)). Immediately after a matching inbound packet, the same process binds/connects outward to a remote host (reverse shell or beacon)."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1205.002",
   "technique_ja": "ソケットフィルタ",
   "technique_en": "Socket Filters",
   "analytic_id": "AN0464",
   "detection_strategy_id": "DET0162",
   "analytic_name": "Analytic 0464",
   "platforms": "macOS",
   "log_sources": "Process Creation (OpenBSM:AuditTrail) | Network Connection Creation (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (OpenBSM:AuditTrail) | ネットワーク接続確立 (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "BPFDevicePath | DeveloperMode",
   "detection_logic_en": "Process opens /dev/bpf* (libpcap) or loads NetworkExtension filter, then after a crafted inbound packet the same process initiates an outbound connection to the trigger origin."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1505",
   "technique_ja": "サーバーソフトウェアコンポーネント",
   "technique_en": "Server Software Component",
   "analytic_id": "AN1507",
   "detection_strategy_id": "DET0547",
   "analytic_name": "Analytic 1507",
   "platforms": "Windows",
   "log_sources": "Scheduled Job Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Application Log Content (WinEventLog:Application)",
   "log_sources_ja": "スケジュールジョブ作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | アプリケーションログ内容 (WinEventLog:Application)",
   "tuning": "TimeWindow | ParentProcessName",
   "detection_logic_en": "Installation of malicious IIS/Apache/SQL server modules that later execute command-line interpreters or establish outbound connections."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1505",
   "technique_ja": "サーバーソフトウェアコンポーネント",
   "technique_en": "Server Software Component",
   "analytic_id": "AN1508",
   "detection_strategy_id": "DET0547",
   "analytic_name": "Analytic 1508",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Application Log Content (linux:syslog) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | アプリケーションログ内容 (linux:syslog) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "ServerBinaryPath | OutboundPortRange",
   "detection_logic_en": "Abuse of extensible server modules (e.g., Apache, Nginx, Tomcat) to load rogue plugins that initiate bash, connect to C2, or spawn reverse shells."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1505",
   "technique_ja": "サーバーソフトウェアコンポーネント",
   "technique_en": "Server Software Component",
   "analytic_id": "AN1509",
   "detection_strategy_id": "DET0547",
   "analytic_name": "Analytic 1509",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Content (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィック内容 (macos:unifiedlog)",
   "tuning": "ParentBinaryPath",
   "detection_logic_en": "Malicious use of webserver plugins (e.g., for nginx, PHP, Node.js) that execute AppleScript or open network sockets."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1505",
   "technique_ja": "サーバーソフトウェアコンポーネント",
   "technique_en": "Server Software Component",
   "analytic_id": "AN1510",
   "detection_strategy_id": "DET0547",
   "analytic_name": "Analytic 1510",
   "platforms": "ESXi",
   "log_sources": "Application Log Content (esxi:hostd) | Command Execution (esxi:vmkernel)",
   "log_sources_ja": "アプリケーションログ内容 (esxi:hostd) | コマンド実行 (esxi:vmkernel)",
   "tuning": "PluginVendorName | AccessVector",
   "detection_logic_en": "Use of ESXi web interface plugins or vSphere extensions to embed persistent malicious scripts or services."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1505.001",
   "technique_ja": "SQLストアドプロシージャ",
   "technique_en": "SQL Stored Procedures",
   "analytic_id": "AN0511",
   "detection_strategy_id": "DET0181",
   "analytic_name": "Analytic 0511",
   "platforms": "Windows",
   "log_sources": "Script Execution (WinEventLog:Application) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Application)",
   "log_sources_ja": "スクリプト実行 (WinEventLog:Application) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Application)",
   "tuning": "xp_cmdshell_invocation_threshold | CLRAssemblyNameWhitelist | TimeWindow",
   "detection_logic_en": "Creation or modification of stored procedures invoking xp_cmdshell or CLR assemblies for command execution and persistence."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1505.001",
   "technique_ja": "SQLストアドプロシージャ",
   "technique_en": "SQL Stored Procedures",
   "analytic_id": "AN0512",
   "detection_strategy_id": "DET0181",
   "analytic_name": "Analytic 0512",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Script Execution (ApplicationLogs:SQL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | スクリプト実行 (ApplicationLogs:SQL)",
   "tuning": "CommandRegex | TimeWindow",
   "detection_logic_en": "SQL stored procedures that invoke OS-level commands via `xp_cmdshell` equivalent or via UDF (User-Defined Functions) mechanisms."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1505.002",
   "technique_ja": "トランスポートエージェント",
   "technique_en": "Transport Agent",
   "analytic_id": "AN0472",
   "detection_strategy_id": "DET0166",
   "analytic_name": "Analytic 0472",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | Module Load (WinEventLog:Sysmon) | Application Log Content (WinEventLog:Application) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | モジュール読み込み (WinEventLog:Sysmon) | アプリケーションログ内容 (WinEventLog:Application) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | AssemblyPath | CmdletInvocationThreshold",
   "detection_logic_en": "Adversary registers a malicious Microsoft Exchange transport agent DLL (.NET assembly), configures it via PowerShell or Exchange Management Shell, and persists code execution by manipulating email processing logic based on rules or headers."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1505.002",
   "technique_ja": "トランスポートエージェント",
   "technique_en": "Transport Agent",
   "analytic_id": "AN0473",
   "detection_strategy_id": "DET0166",
   "analytic_name": "Analytic 0473",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Application Log Content (linux:syslog) | Process Creation (auditd:EXECVE) | File Creation (auditd:SYSCALL) | Module Load (linux:Sysmon)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | アプリケーションログ内容 (linux:syslog) | プロセス生成 (auditd:EXECVE) | ファイル作成 (auditd:SYSCALL) | モジュール読み込み (linux:Sysmon)",
   "tuning": "MailTransportScriptPath | UserContext | ExecFrequencyThreshold",
   "detection_logic_en": "Adversary installs or modifies email content filters or transport scripts (e.g., Postfix milter, Sendmail milter, Exim filters) using shell access or configuration manipulation."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1505.003",
   "technique_ja": "Webシェル",
   "technique_en": "Web Shell",
   "analytic_id": "AN1108",
   "detection_strategy_id": "DET0394",
   "analytic_name": "Analytic 1108",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Logon Session Creation (WinEventLog:Security) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ログオンセッション作成 (WinEventLog:Security) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "WebRootPath | ParentProcess",
   "detection_logic_en": "Unexpected file creation in web directories followed by web server processes (e.g., w3wp.exe) spawning command shells or script interpreters (e.g., cmd.exe, powershell.exe)"
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1505.003",
   "technique_ja": "Webシェル",
   "technique_en": "Web Shell",
   "analytic_id": "AN1109",
   "detection_strategy_id": "DET0394",
   "analytic_name": "Analytic 1109",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ファイル作成 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "WebRootPath | PayloadEntropyThreshold | TimeWindow",
   "detection_logic_en": "File creation of unauthorized script (e.g., .php, .sh) in /var/www/html followed by execution of unexpected system utilities (e.g., curl, bash, nc) by apache/nginx"
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1505.003",
   "technique_ja": "Webシェル",
   "technique_en": "Web Shell",
   "analytic_id": "AN1110",
   "detection_strategy_id": "DET0394",
   "analytic_name": "Analytic 1110",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (auditd:SYSCALL)",
   "tuning": "InterpreterName | ExecutionParent",
   "detection_logic_en": "Web servers (e.g., httpd) spawning abnormal processes post file upload into /Library/WebServer/Documents or /usr/local/var/www"
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1505.004",
   "technique_ja": "IISコンポーネント",
   "technique_en": "IIS Components",
   "analytic_id": "AN0184",
   "detection_strategy_id": "DET0068",
   "analytic_name": "Analytic 0184",
   "platforms": "Windows",
   "log_sources": "File Modification (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Application Log Content (WinEventLog:System) | Service Modification (WinEventLog:Microsoft-IIS-Configuration)",
   "log_sources_ja": "ファイル変更 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | アプリケーションログ内容 (WinEventLog:System) | サービス変更 (WinEventLog:Microsoft-IIS-Configuration)",
   "tuning": "TimeWindow | UserContext | WatchedPaths | DLLNameEntropyThreshold | ParentProcessName",
   "detection_logic_en": "Adversary installs or modifies IIS components (ISAPI filters, extensions, or modules) using DLL files registered via configuration changes or administrative tools like AppCmd.exe. These components intercept or manipulate HTTP requests/responses for persistence or C2."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1505.005",
   "technique_ja": "ターミナルサービスDLL",
   "technique_en": "Terminal Services DLL",
   "analytic_id": "AN0595",
   "detection_strategy_id": "DET0212",
   "analytic_name": "Analytic 0595",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TargetDLLPath | RegistryKeyTarget | TimeWindow | ParentProcessName",
   "detection_logic_en": "Adversary modifies or replaces the Terminal Services DLL (`termsrv.dll`) or changes the associated `ServiceDll` Registry value to load an arbitrary or patched DLL that enables persistent and enhanced RDP access. This may include binary replacement, registry tampering, and unexpected module loads by the `svchost.exe -k termsvcs` process."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1505.006",
   "technique_ja": "vSphereインストールバンドル",
   "technique_en": "vSphere Installation Bundles",
   "analytic_id": "AN1475",
   "detection_strategy_id": "DET0535",
   "analytic_name": "Analytic 1475",
   "platforms": "ESXi",
   "log_sources": "Application Log Content (esxi:esxupdate) | Command Execution (esxi:shell) | File Modification (linux:fim)",
   "log_sources_ja": "アプリケーションログ内容 (esxi:esxupdate) | コマンド実行 (esxi:shell) | ファイル変更 (linux:fim)",
   "tuning": "AcceptanceLevel | InstallCommandThreshold | StartupPathRegex",
   "detection_logic_en": "Malicious VIB installation for persistence via `esxcli software vib install` using `--force` or `--no-sig-check`, enabling custom startup scripts or firewall rules. Behavior chain: (1) unsigned/suspicious VIB installation → (2) startup script or binary placed in persistent boot path → (3) persistence across reboot via /etc/rc.local.d or other boot hook)."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1525",
   "technique_ja": "内部イメージへの埋め込み",
   "technique_en": "Implant Internal Image",
   "analytic_id": "AN0946",
   "detection_strategy_id": "DET0334",
   "analytic_name": "Analytic 0946",
   "platforms": "Containers",
   "log_sources": "Image Creation (docker:daemon) | Image Modification (docker:registry)",
   "log_sources_ja": "イメージ作成 (docker:daemon) | イメージ変更 (docker:registry)",
   "tuning": "TimeWindow | UserContext | RegistryNameRegex",
   "detection_logic_en": "Implantation of malicious code into container images followed by registry push and use in new deployments."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1525",
   "technique_ja": "内部イメージへの埋め込み",
   "technique_en": "Implant Internal Image",
   "analytic_id": "AN0947",
   "detection_strategy_id": "DET0334",
   "analytic_name": "Analytic 0947",
   "platforms": "IaaS",
   "log_sources": "Image Creation (AWS:CloudTrail) | Image Modification (AWS:CloudTrail) | Instance Start (AWS:CloudTrail)",
   "log_sources_ja": "イメージ作成 (AWS:CloudTrail) | イメージ変更 (AWS:CloudTrail) | インスタンス起動 (AWS:CloudTrail)",
   "tuning": "IAMRole | ImageTagRegex | LaunchWindow",
   "detection_logic_en": "Creation or modification of cloud virtual machine images (AMIs, custom images) with persistence mechanisms, followed by infrastructure provisioning that uses these implanted images."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1542",
   "technique_ja": "OS起動前ブート",
   "technique_en": "Pre-OS Boot",
   "analytic_id": "AN0774",
   "detection_strategy_id": "DET0278",
   "analytic_name": "Analytic 0774",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Drive Access (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | ドライブアクセス (WinEventLog:Sysmon)",
   "tuning": "AllowedFirmwareUpdateTools | TimeWindow | EntropyThreshold",
   "detection_logic_en": "Unusual modification of boot records (MBR, VBR) or EFI partitions not associated with legitimate patch cycles or OS upgrades. Registry or WMI events associated with firmware update tools executed from unexpected parent processes. API calls (e.g., DeviceIoControl) writing directly to raw disk sectors. Subsequent abnormal boot configuration changes followed by unsigned driver loads."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1542",
   "technique_ja": "OS起動前ブート",
   "technique_en": "Pre-OS Boot",
   "analytic_id": "AN0775",
   "detection_strategy_id": "DET0278",
   "analytic_name": "Analytic 0775",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Command Execution (auditd:EXECVE)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | コマンド実行 (auditd:EXECVE)",
   "tuning": "PackageManagerUpdateWhitelist | FilesystemPaths",
   "detection_logic_en": "Detection of writes to /boot or EFI directories outside of expected package manager updates. Monitoring kernel log and auditd events for attempts to overwrite bootloader binaries (e.g., grub, shim). Unexpected execution of efibootmgr or dd writing to /dev/sdX devices followed by boot parameter changes."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1542",
   "technique_ja": "OS起動前ブート",
   "technique_en": "Pre-OS Boot",
   "analytic_id": "AN0776",
   "detection_strategy_id": "DET0278",
   "analytic_name": "Analytic 0776",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog)",
   "tuning": "AllowedBootUtilities | BootParamBaseline",
   "detection_logic_en": "Abnormal modification of EFI firmware binaries in /System/Library/CoreServices/ or NVRAM parameters not associated with OS updates. Unified logs capturing calls to bless or nvram commands executed from untrusted parent processes. Sudden unsigned kext loads after EFI variable tampering."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1542",
   "technique_ja": "OS起動前ブート",
   "technique_en": "Pre-OS Boot",
   "analytic_id": "AN0777",
   "detection_strategy_id": "DET0278",
   "analytic_name": "Analytic 0777",
   "platforms": "Network Devices",
   "log_sources": "Firmware Modification (networkdevice:config) | Drive Modification (networkdevice:firmware)",
   "log_sources_ja": "ファームウェア変更 (networkdevice:config) | ドライブ変更 (networkdevice:firmware)",
   "tuning": "ApprovedFirmwareHashes | MaintenanceWindows",
   "detection_logic_en": "Unexpected firmware image uploads via TFTP/FTP/SCP. Configuration changes modifying boot image pointers. Logs showing boot variable redirection to non-standard images. Anomalous reboots immediately following firmware changes not tied to patch schedules."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1542.001",
   "technique_ja": "システムファームウェア",
   "technique_en": "System Firmware",
   "analytic_id": "AN0275",
   "detection_strategy_id": "DET0099",
   "analytic_name": "Analytic 0275",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Drive Access (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ドライブアクセス (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "AllowedFirmwareUpdateTools | TimeWindow | KnownGoodFirmwareHashes",
   "detection_logic_en": "Unexpected write operations to BIOS/UEFI firmware regions or EFI boot partitions that do not correlate with legitimate vendor firmware updates. API calls or utilities such as fwupdate.exe or vendor flash tools executed from non-administrative or non-IT management accounts. Suspicious raw disk writes targeting System Firmware GUID partitions followed by abnormal reboot sequences."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1542.001",
   "technique_ja": "システムファームウェア",
   "technique_en": "System Firmware",
   "analytic_id": "AN0276",
   "detection_strategy_id": "DET0099",
   "analytic_name": "Analytic 0276",
   "platforms": "Network Devices",
   "log_sources": "Firmware Modification (networkdevice:config) | Drive Modification (networkdevice:runtime)",
   "log_sources_ja": "ファームウェア変更 (networkdevice:config) | ドライブ変更 (networkdevice:runtime)",
   "tuning": "ApprovedFirmwareHashes | MaintenanceWindows | SourceIPWhitelist",
   "detection_logic_en": "Unauthorized firmware uploads to routers, switches, or firewalls via TFTP/FTP/SCP. Logs showing boot variable or startup image path changes redirecting to non-standard firmware images. Abnormal reboots or firmware rollback attempts following configuration modification events."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1542.002",
   "technique_ja": "コンポーネントファームウェア",
   "technique_en": "Component Firmware",
   "analytic_id": "AN0916",
   "detection_strategy_id": "DET0323",
   "analytic_name": "Analytic 0916",
   "platforms": "Windows",
   "log_sources": "Driver Load (WinEventLog:Sysmon) | Firmware Modification (firmware:integrity )",
   "log_sources_ja": "ドライバ読み込み (WinEventLog:Sysmon) | ファームウェア変更 (firmware:integrity )",
   "tuning": "KnownGoodFirmwareHashes | DriverAllowList | TimeWindow",
   "detection_logic_en": "Detection of anomalous driver and firmware interactions, including unsigned or unexpected firmware updates, driver loads linked to hardware components, and suspicious use of privileged APIs to read/write firmware or controller memory."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1542.002",
   "technique_ja": "コンポーネントファームウェア",
   "technique_en": "Component Firmware",
   "analytic_id": "AN0917",
   "detection_strategy_id": "DET0323",
   "analytic_name": "Analytic 0917",
   "platforms": "Linux",
   "log_sources": "Firmware Modification (auditd:SYSCALL) | Driver Load (linux:syslog)",
   "log_sources_ja": "ファームウェア変更 (auditd:SYSCALL) | ドライバ読み込み (linux:syslog)",
   "tuning": "FirmwareImageBaseline | AlertThresholds",
   "detection_logic_en": "Detection of suspicious use of ioctl/sysfs calls to access device firmware, unexpected flashing tools execution, and anomalous firmware checksums logged by SMART or kernel audit mechanisms."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1542.002",
   "technique_ja": "コンポーネントファームウェア",
   "technique_en": "Component Firmware",
   "analytic_id": "AN0918",
   "detection_strategy_id": "DET0323",
   "analytic_name": "Analytic 0918",
   "platforms": "macOS",
   "log_sources": "Firmware Modification (macos:unifiedlog)",
   "log_sources_ja": "ファームウェア変更 (macos:unifiedlog)",
   "tuning": "ApprovedKextList | EFIHashBaseline",
   "detection_logic_en": "Detection of EFI/firmware manipulation attempts via abnormal driver loads, unsigned kexts, or tampered NVRAM variables associated with component firmware configuration."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1542.003",
   "technique_ja": "ブートキット",
   "technique_en": "Bootkit",
   "analytic_id": "AN0428",
   "detection_strategy_id": "DET0150",
   "analytic_name": "Analytic 0428",
   "platforms": "Windows",
   "log_sources": "Drive Access (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ドライブアクセス (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "KnownGoodMBRHashes | ESPFileWhitelist | TimeWindow",
   "detection_logic_en": "Detection of raw access to physical drives, modification of boot records (MBR/VBR), and suspicious file creation or alteration within the EFI System Partition (ESP). Correlates privileged process execution with low-level disk modification and unexpected driver or firmware interactions."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1542.003",
   "technique_ja": "ブートキット",
   "technique_en": "Bootkit",
   "analytic_id": "AN0429",
   "detection_strategy_id": "DET0150",
   "analytic_name": "Analytic 0429",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Drive Modification (linux:syslog)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | ドライブ変更 (linux:syslog)",
   "tuning": "BootloaderHashBaseline | EFIFileAllowlist | AlertThresholds",
   "detection_logic_en": "Detection of suspicious write operations to block devices, modifications of bootloader files (GRUB, initrd, vmlinuz), and unexpected changes within the EFI System Partition. Monitors privileged execution of utilities like dd, grub-install, or efibootmgr that modify boot sectors or loader entries."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1542.004",
   "technique_ja": "ROMMONkit",
   "technique_en": "ROMMONkit",
   "analytic_id": "AN0497",
   "detection_strategy_id": "DET0175",
   "analytic_name": "Analytic 0497",
   "platforms": "Network Devices",
   "log_sources": "Firmware Modification (networkdevice:config) | OS API Execution (networkdevice:syslog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "ファームウェア変更 (networkdevice:config) | OS API実行 (networkdevice:syslog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "ApprovedROMMONVersions | TimeWindow | AdminUserContext",
   "detection_logic_en": "Detection of anomalous ROMMON image changes or upgrades, unexpected reboots following firmware updates, and unauthorized use of firmware upgrade commands or TFTP transfers. Correlation of config modification, privilege escalation, and boot cycle anomalies provides visibility into ROMMON tampering attempts."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1542.005",
   "technique_ja": "TFTPブート",
   "technique_en": "TFTP Boot",
   "analytic_id": "AN1603",
   "detection_strategy_id": "DET0582",
   "analytic_name": "Analytic 1603",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:config) | Firmware Modification (networkdevice:syslog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (networkdevice:config) | ファームウェア変更 (networkdevice:syslog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "ApprovedTFTPServers | TimeWindow | BaselineBootImageHash",
   "detection_logic_en": "Detection of unauthorized changes to boot configurations pointing to TFTP servers, unusual firmware loads during netbooting, or suspicious TFTP traffic. Correlation of boot config modifications, command history logs, and unexpected system image hashes provides detection coverage for adversaries attempting to persist via malicious TFTP boot images."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1543",
   "technique_ja": "システムプロセスの作成/変更",
   "technique_en": "Create or Modify System Process",
   "analytic_id": "AN1575",
   "detection_strategy_id": "DET0571",
   "analytic_name": "Analytic 1575",
   "platforms": "Windows",
   "log_sources": "Service Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "サービス作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "ServiceNamePattern | ParentProcessFilter | RegistryPathList",
   "detection_logic_en": "Detects command-line or API-based creation/modification of Windows Services via `sc.exe`, `powershell.exe`, `services.exe`, or `ChangeServiceConfig`. Looks for creation/modification of autostart services via registry changes, file drops to `System32\\services`, and anomalous parent-child process trees."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1543",
   "technique_ja": "システムプロセスの作成/変更",
   "technique_en": "Create or Modify System Process",
   "analytic_id": "AN1576",
   "detection_strategy_id": "DET0571",
   "analytic_name": "Analytic 1576",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Command Execution (auditd:SYSCALL)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | コマンド実行 (auditd:SYSCALL)",
   "tuning": "ServicePathRegex | UserContextList | CommandNameList",
   "detection_logic_en": "Detects creation or modification of `systemd` service units, addition of cron jobs that invoke binaries on boot, or suspicious writes to `/etc/init.d/`. Monitors `chmod +x` and `systemctl` execution paths, especially from non-root parent processes."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1543",
   "technique_ja": "システムプロセスの作成/変更",
   "technique_en": "Create or Modify System Process",
   "analytic_id": "AN1577",
   "detection_strategy_id": "DET0571",
   "analytic_name": "Analytic 1577",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Modification (fs:fsusage)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル変更 (fs:fsusage)",
   "tuning": "PlistPathList | PlistKeyMonitor | UnsignedBinaryAlert",
   "detection_logic_en": "Detects creation or modification of `LaunchDaemon` or `LaunchAgent` plist files under `/Library/LaunchDaemons/`, `~/Library/LaunchAgents/`, or similar. Monitors execution of `launchctl`, property list edits, and file permission changes."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1543",
   "technique_ja": "システムプロセスの作成/変更",
   "technique_en": "Create or Modify System Process",
   "analytic_id": "AN1578",
   "detection_strategy_id": "DET0571",
   "analytic_name": "Analytic 1578",
   "platforms": "Containers",
   "log_sources": "Container Creation (docker:events) | File Modification (auditd:SYSCALL)",
   "log_sources_ja": "コンテナ作成 (docker:events) | ファイル変更 (auditd:SYSCALL)",
   "tuning": "EntrypointOverridePattern | RestartPolicyMatch | KubeInitModPath",
   "detection_logic_en": "Detects creation of new container system processes via `docker run --restart`, `kubectl exec` to init containers, or modification of container init specs. Flags container images that override entrypoints to embed persistence behaviors."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1543.001",
   "technique_ja": "Launch Agent",
   "technique_en": "Launch Agent",
   "analytic_id": "AN1208",
   "detection_strategy_id": "DET0434",
   "analytic_name": "Analytic 1208",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Creation (fs:fsusage) | File Modification (fs:fsusage) | Service Creation (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル作成 (fs:fsusage) | ファイル変更 (fs:fsusage) | サービス作成 (macos:osquery)",
   "tuning": "PlistDirectoryList | PlistKeyMonitor | ExecutablePathPattern | UnsignedBinaryAlert | UserContextScope",
   "detection_logic_en": "Detects creation or modification of user-level Launch Agents in monitored directories using `.plist` files with suspicious `ProgramArguments` or `RunAtLoad` keys. Correlates file write activity with execution of `launchctl` or unsigned binaries invoked at login."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1543.002",
   "technique_ja": "systemdサービス",
   "technique_en": "Systemd Service",
   "analytic_id": "AN0701",
   "detection_strategy_id": "DET0253",
   "analytic_name": "Analytic 0701",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:SYSCALL) | File Modification (auditd:SYSCALL) | Command Execution (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Service Creation (linux:osquery)",
   "log_sources_ja": "ファイル作成 (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL) | コマンド実行 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | サービス作成 (linux:osquery)",
   "tuning": "ServicePathRegex | ExecStartPathAllowlist | UserContextFilter | FileEntropyThreshold | SystemctlOperationSet",
   "detection_logic_en": "Detects the creation or modification of `.service` unit files in system/user-level directories, combined with execution of `systemctl`, `service`, or dynamically created drop-ins via systemd generators. Detects persistence by analyzing the `ExecStart` path, file entropy, and symlink usage, especially when paired with execution from `/tmp`, `/dev/shm`, or unmounted volumes."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1543.003",
   "technique_ja": "Windowsサービス",
   "technique_en": "Windows Service",
   "analytic_id": "AN1527",
   "detection_strategy_id": "DET0552",
   "analytic_name": "Analytic 1527",
   "platforms": "Windows",
   "log_sources": "Service Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | Driver Load (WinEventLog:Sysmon)",
   "log_sources_ja": "サービス作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ドライバ読み込み (WinEventLog:Sysmon)",
   "tuning": "ServiceNamePattern | ImagePathFilter | DriverExtensionList | StartupTypeChangeWindow | UnsignedBinaryAlert",
   "detection_logic_en": "Detects creation or modification of Windows Services through command-line tools (e.g., `sc.exe`, `powershell.exe`), Registry key changes under `HKLM\\System\\CurrentControlSet\\Services`, and service execution under SYSTEM with unsigned or anomalous binary paths. Detects privilege escalation via driver installation or `CreateServiceW` usage. Correlates parent-child lineage, startup behavior, and rare service names."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1543.004",
   "technique_ja": "Launch Daemon",
   "technique_en": "Launch Daemon",
   "analytic_id": "AN1126",
   "detection_strategy_id": "DET0401",
   "analytic_name": "Analytic 1126",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (fs:launchdaemons) | File Modification (fs:launchdaemons) | Service Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (fs:launchdaemons) | ファイル変更 (fs:launchdaemons) | サービス作成 (macos:unifiedlog)",
   "tuning": "ProgramPathRegex | TimeWindow | UserContext | UnsignedBinaryFlag",
   "detection_logic_en": "Creation or modification of `.plist` files in /Library/LaunchDaemons/, especially those with suspicious Program or ProgramArguments paths, combined with execution activity under launchd with elevated privileges. Detectable through correlated Unified Logs, file monitoring, and process telemetry."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1543.005",
   "technique_ja": "コンテナサービス",
   "technique_en": "Container Service",
   "analytic_id": "AN1304",
   "detection_strategy_id": "DET0473",
   "analytic_name": "Analytic 1304",
   "platforms": "Containers",
   "log_sources": "Process Creation (auditd:SYSCALL) | Container Creation (systemd:unit) | Pod Creation (kubernetes:audit) | Service Creation (kubernetes:audit)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | コンテナ作成 (systemd:unit) | Pod作成 (kubernetes:audit) | サービス作成 (kubernetes:audit)",
   "tuning": "restartPolicy | targetNamespace | nodeSelector|nodeName | unitFilePath | TimeWindow",
   "detection_logic_en": "Correlate the creation or modification of containers using restart policies (e.g., 'always') or DaemonSets with elevated host access, service account misuse, or privileged container contexts. Watch for manipulation of systemd units involving containers or pod scheduling targeting specific nodes or namespaces."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546",
   "technique_ja": "イベントトリガー実行",
   "technique_en": "Event Triggered Execution",
   "analytic_id": "AN0024",
   "detection_strategy_id": "DET0010",
   "analytic_name": "Analytic 0024",
   "platforms": "Windows",
   "log_sources": "Scheduled Job Creation (WinEventLog:Security) | WMI Creation (WinEventLog:WMI) | Windows Registry Key Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "スケジュールジョブ作成 (WinEventLog:Security) | WMI作成 (WinEventLog:WMI) | Windowsレジストリキー変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "UserContext | TimeWindow | PathAnomalyThreshold",
   "detection_logic_en": "Correlates unexpected modifications to WMI event filters, scheduled task triggers, or registry autorun keys with subsequent execution of non-standard binaries by SYSTEM-level processes."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546",
   "technique_ja": "イベントトリガー実行",
   "technique_en": "Event Triggered Execution",
   "analytic_id": "AN0025",
   "detection_strategy_id": "DET0010",
   "analytic_name": "Analytic 0025",
   "platforms": "Linux",
   "log_sources": "File Metadata (auditd:SYSCALL) | Scheduled Job Creation (linux:syslog) | Command Execution (auditd:SYSCALL)",
   "log_sources_ja": "ファイルメタデータ (auditd:SYSCALL) | スケジュールジョブ作成 (linux:syslog) | コマンド実行 (auditd:SYSCALL)",
   "tuning": "ExecutablePathRegex | WatchTargetPaths",
   "detection_logic_en": "Detects inotify or auditd configuration changes that monitor system files coupled with execution of script interpreters or binaries by cron or systemd timers."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546",
   "technique_ja": "イベントトリガー実行",
   "technique_en": "Event Triggered Execution",
   "analytic_id": "AN0026",
   "detection_strategy_id": "DET0010",
   "analytic_name": "Analytic 0026",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "PlistNamePattern | ParentProcessBaseline",
   "detection_logic_en": "Correlates launchd plist modifications with subsequent unauthorized script execution or anomalous parent-child process trees involving user agents."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546",
   "technique_ja": "イベントトリガー実行",
   "technique_en": "Event Triggered Execution",
   "analytic_id": "AN0027",
   "detection_strategy_id": "DET0010",
   "analytic_name": "Analytic 0027",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Modification (AWS:CloudTrail) | Command Execution (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス変更 (AWS:CloudTrail) | コマンド実行 (AWS:CloudTrail)",
   "tuning": "TriggerEventType | ServiceAccountRole",
   "detection_logic_en": "Monitors cloud function creation triggered by specific audit log events (e.g., IAM changes, object creation), followed by anomalous behavior from new service accounts."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546",
   "technique_ja": "イベントトリガー実行",
   "technique_en": "Event Triggered Execution",
   "analytic_id": "AN0028",
   "detection_strategy_id": "DET0010",
   "analytic_name": "Analytic 0028",
   "platforms": "SaaS",
   "log_sources": "Cloud Service Modification (m365:unified) | Command Execution (m365:unified)",
   "log_sources_ja": "クラウドサービス変更 (m365:unified) | コマンド実行 (m365:unified)",
   "tuning": "TriggerCondition | AppIdentityScope",
   "detection_logic_en": "Correlates Power Automate or similar logic app workflows triggered by SaaS file uploads or email rules with data forwarding or anomalous access patterns."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546",
   "technique_ja": "イベントトリガー実行",
   "technique_en": "Event Triggered Execution",
   "analytic_id": "AN0029",
   "detection_strategy_id": "DET0010",
   "analytic_name": "Analytic 0029",
   "platforms": "Office Suite",
   "log_sources": "Script Execution (m365:office) | Network Traffic Content (m365:office)",
   "log_sources_ja": "スクリプト実行 (m365:office) | ネットワークトラフィック内容 (m365:office)",
   "tuning": "MacroFunctionNames | TimeDeltaMacroToC2",
   "detection_logic_en": "Detects macros or VBA triggers set to execute on document open or close events, often correlating with embedded payloads or C2 traffic shortly after execution."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.001",
   "technique_ja": "既定のファイル関連付けの変更",
   "technique_en": "Change Default File Association",
   "analytic_id": "AN0170",
   "detection_strategy_id": "DET0061",
   "analytic_name": "Analytic 0170",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Logon Session Metadata (WinEventLog:Security)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ログオンセッションメタデータ (WinEventLog:Security)",
   "tuning": "TimeWindow | UserContext | SuspiciousHandlerPathRegex",
   "detection_logic_en": "Detects modification of registry keys used for default file handlers, followed by anomalous process execution from user-initiated file opens. This includes tracking changes under HKCU and HKCR for file extension mappings, and correlating them with new or suspicious handler paths launching unusual child processes (e.g., PowerShell, cmd, wscript)."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.002",
   "technique_ja": "スクリーンセーバー",
   "technique_en": "Screensaver",
   "analytic_id": "AN0441",
   "detection_strategy_id": "DET0154",
   "analytic_name": "Analytic 0441",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | SuspiciousPathRegex | ParentProcessAllowList | RegistryEditorProcessName",
   "detection_logic_en": "Unusual screensaver (.scr) executions correlated with recent registry modifications to HKCU\\Control Panel\\Desktop values such as SCRNSAVE.exe, ScreenSaveTimeout, and ScreenSaveActive. Detection focuses on PE image paths not consistent with known legitimate screensavers and triggered after user inactivity timeout."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.003",
   "technique_ja": "WMIイベントサブスクリプション",
   "technique_en": "Windows Management Instrumentation Event Subscription",
   "analytic_id": "AN0236",
   "detection_strategy_id": "DET0086",
   "analytic_name": "Analytic 0236",
   "platforms": "Windows",
   "log_sources": "WMI Creation (WinEventLog:WMI) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "WMI作成 (WinEventLog:WMI) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext | ProcessNameAllowlist | ParentProcessAnomalyThreshold",
   "detection_logic_en": "Monitor for creation of WMI EventFilter, EventConsumer, and FilterToConsumerBinding objects through WMI or MOF file execution. Detect command-line execution of `mofcomp.exe`, usage of `Register-WmiEvent` via PowerShell, and anomalous child processes of `WmiPrvSE.exe` that indicate triggered execution. Look for lateral anomalies in process lineage and WMI logging channels."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.004",
   "technique_ja": "Unixシェル構成の変更",
   "technique_en": "Unix Shell Configuration Modification",
   "analytic_id": "AN0059",
   "detection_strategy_id": "DET0020",
   "analytic_name": "Analytic 0059",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:EXECVE) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:EXECVE) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TimeWindow | TargetUser | FilePathRegex",
   "detection_logic_en": "Detects modification of shell startup/logout scripts such as ~/.bashrc, ~/.bash_profile, or /etc/profile, followed by anomalous process execution or network connections upon interactive or remote shell login."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.004",
   "technique_ja": "Unixシェル構成の変更",
   "technique_en": "Unix Shell Configuration Modification",
   "analytic_id": "AN0060",
   "detection_strategy_id": "DET0020",
   "analytic_name": "Analytic 0060",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:endpointsecurity)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:endpointsecurity)",
   "tuning": "FileTargetList | PayloadEntropyThreshold | UserContext",
   "detection_logic_en": "Correlates zsh shell configuration file changes (e.g., ~/.zshrc, ~/.zlogin, /etc/zprofile) with execution of unauthorized binaries or unexpected network activity triggered on Terminal.app launch."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.005",
   "technique_ja": "Trap",
   "technique_en": "Trap",
   "analytic_id": "AN1038",
   "detection_strategy_id": "DET0369",
   "analytic_name": "Analytic 1038",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Modification (auditd:SYSCALL) | File Access (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL) | ファイルアクセス (auditd:SYSCALL)",
   "tuning": "TargetShellFilePath | SignalTrapName | TimeWindow",
   "detection_logic_en": "Correlate file modifications in shell startup scripts (e.g., .bashrc, .profile) with embedded `trap` commands and observe if those changes are followed by the unexpected execution of child processes when terminal signals (e.g., SIGINT) are triggered. Use contextual linking with user session activity to detect privilege misuse."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.005",
   "technique_ja": "Trap",
   "technique_en": "Trap",
   "analytic_id": "AN1039",
   "detection_strategy_id": "DET0369",
   "analytic_name": "Analytic 1039",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog)",
   "tuning": "LoginShellConfigPaths | TrapCommandLengthThreshold | ParentProcessAnomalyThreshold",
   "detection_logic_en": "Detect unauthorized `trap` command registrations in shell startup files (e.g., .zprofile, .bash_profile, .zshrc) followed by execution chains during user terminal interaction. Use Unified Logs and EDR telemetry to correlate shell command parsing and process tree anomalies."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.006",
   "technique_ja": "LC_LOAD_DYLIBの追加",
   "technique_en": "LC_LOAD_DYLIB Addition",
   "analytic_id": "AN0607",
   "detection_strategy_id": "DET0216",
   "analytic_name": "Analytic 0607",
   "platforms": "macOS",
   "log_sources": "Module Load (macos:unifiedlog) | File Modification (macos:unifiedlog) | File Metadata (macos:unifiedlog)",
   "log_sources_ja": "モジュール読み込み (macos:unifiedlog) | ファイル変更 (macos:unifiedlog) | ファイルメタデータ (macos:unifiedlog)",
   "tuning": "TimeWindow | DylibPathRegex | UnsignedDylibThreshold | UserContext",
   "detection_logic_en": "Detection focuses on unauthorized modification of Mach-O binaries to include LC_LOAD_DYLIB headers pointing to malicious dylibs. Behavior is identified via a chain of file metadata changes, removal of code signatures, and subsequent anomalous dylib loads at runtime. Correlation of file changes with lack of authorized updates and process memory mapping of unrecognized or unsigned libraries is crucial."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.007",
   "technique_ja": "NetshヘルパDLL",
   "technique_en": "Netsh Helper DLL",
   "analytic_id": "AN1588",
   "detection_strategy_id": "DET0575",
   "analytic_name": "Analytic 1588",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | NetshChildProcessWhitelist | DLLLoadPath",
   "detection_logic_en": "Detection focuses on monitoring registry modifications under HKLM\\SOFTWARE\\Microsoft\\Netsh that indicate the addition of helper DLLs, followed by anomalous child process activity or module load behavior initiated by netsh.exe. These behaviors are rarely legitimate and may represent an adversary establishing persistence."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.008",
   "technique_ja": "アクセシビリティ機能",
   "technique_en": "Accessibility Features",
   "analytic_id": "AN0094",
   "detection_strategy_id": "DET0033",
   "analytic_name": "Analytic 0094",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | TargetBinaryNames | ParentProcess | UserContext | CommandLineContains",
   "detection_logic_en": "Defenders can observe suspicious replacement or tampering of system accessibility binaries (e.g., utilman.exe, sethc.exe, osk.exe) and anomalous modifications to registry keys used to redirect accessibility programs (such as IFEO keys). Additionally, execution of cmd.exe or other suspicious binaries triggered from the login screen by SYSTEM can be correlated as part of a behavior chain."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.009",
   "technique_ja": "AppCert DLL",
   "technique_en": "AppCert DLLs",
   "analytic_id": "AN1029",
   "detection_strategy_id": "DET0362",
   "analytic_name": "Analytic 1029",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "TargetObject | ImageLoaded | ParentImage | TimeWindow",
   "detection_logic_en": "Detection of AppCert DLL abuse involves correlating registry modifications to the AppCertDLLs key with subsequent unexpected DLL load behavior during process creation events. Specifically, defenders can observe abnormal DLLs being loaded into standard Windows processes after changes to the 'AppCertDLLs' registry value. Monitoring CreateProcess-family API executions with injected DLLs and linking those DLLs back to recent registry edits is key to identifying misuse. This is often accompanied by elevated privileges and potential lateral movement or discovery behavior."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.010",
   "technique_ja": "AppInit DLL",
   "technique_en": "AppInit DLLs",
   "analytic_id": "AN1536",
   "detection_strategy_id": "DET0557",
   "analytic_name": "Analytic 1536",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "ImagePathWhitelist | UserContext | TimeWindow | DLLSignatureStatus",
   "detection_logic_en": "Registry key modification to AppInit_DLLs value followed by anomalous DLL loading by processes importing user32.dll, especially unsigned or uncommon DLLs, suggesting unauthorized AppInit persistence or privilege escalation."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.011",
   "technique_ja": "アプリケーションシミング",
   "technique_en": "Application Shimming",
   "analytic_id": "AN0051",
   "detection_strategy_id": "DET0017",
   "analytic_name": "Analytic 0051",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "CustomShimPathAllowlist | TimeWindow | DLLInjectionTarget | UserContext | ShimCommandLinePattern",
   "detection_logic_en": "Correlated modification of AppCompat registry keys and execution of sdbinst.exe to install custom shim databases. Followed by DLL injection via shim behavior into target application processes."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.012",
   "technique_ja": "IFEOインジェクション",
   "technique_en": "Image File Execution Options Injection",
   "analytic_id": "AN1186",
   "detection_strategy_id": "DET0422",
   "analytic_name": "Analytic 1186",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Windows Registry Key Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | Windowsレジストリキー作成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | TargetBinary | ParentProcessAnomaly | TokenElevationContext",
   "detection_logic_en": "Registry key modifications under IFEO paths (e.g., Debugger value set under Image File Execution Options), especially for security-related or accessibility binaries, followed by anomalous process execution with debugger flags or SYSTEM-level access at login. Detectable by correlating registry modifications, process creation, and parent-child anomalies with unusual command-line usage or access tokens."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.013",
   "technique_ja": "PowerShellプロファイル",
   "technique_en": "PowerShell Profile",
   "analytic_id": "AN1245",
   "detection_strategy_id": "DET0451",
   "analytic_name": "Analytic 1245",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Modification (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "ProfilePathList | ExecutionContext | ModuleOrScriptName | TimeWindow",
   "detection_logic_en": "Defenders can identify PowerShell profile-based persistence by correlating file creation or modification in known profile locations with subsequent PowerShell process launches that do not use the `-NoProfile` flag. Profile scripts loading unusual modules or launching external programs, particularly under elevated contexts, are suspicious and may represent adversary persistence or privilege escalation."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.014",
   "technique_ja": "Emond",
   "technique_en": "Emond",
   "analytic_id": "AN1534",
   "detection_strategy_id": "DET0555",
   "analytic_name": "Analytic 1534",
   "platforms": "macOS",
   "log_sources": "File Creation (macos:unifiedlog) | Process Creation (macos:unifiedlog) | File Modification (macos:unifiedlog) | Command Execution (macos:unifiedlog)",
   "log_sources_ja": "ファイル作成 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog) | コマンド実行 (macos:unifiedlog)",
   "tuning": "PathPrefix | TimeWindow | ParentProcessFilter | CommandPatternList",
   "detection_logic_en": "Detection focuses on identifying unauthorized file creation or modification within `/etc/emond.d/rules/` or `/private/var/db/emondClients`, which indicate attempts to register a malicious emond rule. Correlate with process execution of `/sbin/emond` and any launched commands it invokes, especially during boot or login events. Anomalies may include rules created by non-root users or unexpected shell commands executed by emond."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.015",
   "technique_ja": "COMハイジャック",
   "technique_en": "Component Object Model Hijacking",
   "analytic_id": "AN1323",
   "detection_strategy_id": "DET0481",
   "analytic_name": "Analytic 1323",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "RegistryPathScope | BinaryPathAnomalyThreshold | TimeWindow | UserContextFilter",
   "detection_logic_en": "Correlate suspicious registry modifications to known COM object CLSIDs with subsequent DLL loads or unexpected binary execution paths. Detect placement of COM CLSID entries under HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\ overriding default HKLM paths. Flag anomalous DLL loads traced back to hijacked COM registry changes."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.016",
   "technique_ja": "インストーラパッケージ",
   "technique_en": "Installer Packages",
   "analytic_id": "AN0938",
   "detection_strategy_id": "DET0330",
   "analytic_name": "Analytic 0938",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:unifiedlog)",
   "tuning": "ScriptLocation | ParentProcessName",
   "detection_logic_en": "Correlation of package install event with execution of postinstall scripts containing unknown binaries or abnormal CLI usage. Look for `/usr/sbin/installer` execution followed by child processes originating from postinstall script."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.016",
   "technique_ja": "インストーラパッケージ",
   "technique_en": "Installer Packages",
   "analytic_id": "AN0939",
   "detection_strategy_id": "DET0330",
   "analytic_name": "Analytic 0939",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Creation (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル作成 (auditd:SYSCALL)",
   "tuning": "ScriptName | PackageManager",
   "detection_logic_en": "Detection of maintainer scripts (e.g., postinst, preinst) being modified or executed during dpkg or rpm operations. Watch for script content that spawns additional processes or writes outside package scope."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.016",
   "technique_ja": "インストーラパッケージ",
   "technique_en": "Installer Packages",
   "analytic_id": "AN0940",
   "detection_strategy_id": "DET0330",
   "analytic_name": "Analytic 0940",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "InstallerParent | ChildImagePath | ExecutionTimeWindow",
   "detection_logic_en": "Detection of msiexec.exe running installer packages that result in anomalous process creation. Look for unexpected binaries executed by msiexec or custom action DLLs in the temp directory."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.017",
   "technique_ja": "Udevルール",
   "technique_en": "Udev Rules",
   "analytic_id": "AN1056",
   "detection_strategy_id": "DET0375",
   "analytic_name": "Analytic 1056",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Command Execution (auditd:CONFIG_CHANGE)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | コマンド実行 (auditd:CONFIG_CHANGE)",
   "tuning": "UdevRulePath | SuspiciousRunPattern | TimeWindow | ParentProcess",
   "detection_logic_en": "Monitor for creation or modification of udev rules files in key directories (/etc/udev/rules.d/, /lib/udev/rules.d/, /usr/lib/udev/rules.d/). Look for RUN+= or IMPORT keys invoking suspicious binaries or scripts. Correlate this with process execution from systemd-udevd context, and file writes near udev reload/restart events. Combine this with unexpected background process spawning from udevd-related forks."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1546.018",
   "technique_ja": "Python起動フック",
   "technique_en": "Python Startup Hooks",
   "analytic_id": "AN0713",
   "detection_strategy_id": "DET0258",
   "analytic_name": "Analytic 0713",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Modification (auditd:PATH) | File Metadata (auditd:CONFIG_CHANGE) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル変更 (auditd:PATH) | ファイルメタデータ (auditd:CONFIG_CHANGE) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "HookFilePathPatterns | UserContext | TimeWindow | InterpreterWhitelist",
   "detection_logic_en": "Defender observes unauthorized modification or creation of Python hook files such as `.pth`, `sitecustomize.py`, or `usercustomize.py` in Python `site-packages`, `dist-packages`, or user paths. This is often correlated with subsequent unexpected interpreter execution (e.g., python3 running without user interaction), changes in interpreter behavior (e.g., malicious imports), and outbound connections initiated from Python. Defender links write/modify actions on hook files with execve of python process and/or anomalous child process or network activity."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1547",
   "technique_ja": "起動/ログオン時の自動実行",
   "technique_en": "Boot or Logon Autostart Execution",
   "analytic_id": "AN0764",
   "detection_strategy_id": "DET0274",
   "analytic_name": "Analytic 0764",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "ParentProcessName | StartupRegistryPath",
   "detection_logic_en": "Correlation of registry key modification for Run/RunOnce with abnormal parent-child process relationships and outlier execution at user logon or system startup"
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1547",
   "technique_ja": "起動/ログオン時の自動実行",
   "technique_en": "Boot or Logon Autostart Execution",
   "analytic_id": "AN0765",
   "detection_strategy_id": "DET0274",
   "analytic_name": "Analytic 0765",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:SYSCALL) | File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイル作成 (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "FilePath | UserContext",
   "detection_logic_en": "Correlates creation/modification of systemd service files or /etc/init.d scripts with outlier process behavior during boot"
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1547",
   "technique_ja": "起動/ログオン時の自動実行",
   "technique_en": "Boot or Logon Autostart Execution",
   "analytic_id": "AN0766",
   "detection_strategy_id": "DET0274",
   "analytic_name": "Analytic 0766",
   "platforms": "macOS",
   "log_sources": "Service Metadata (macos:unifiedlog) | File Modification (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "サービスメタデータ (macos:unifiedlog) | ファイル変更 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "PlistKey | TimeWindow",
   "detection_logic_en": "Observes creation or modification of LaunchAgent/LaunchDaemon property list files combined with anomalous plist payload execution after user logon"
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1547.001",
   "technique_ja": "レジストリRunキー/スタートアップフォルダ",
   "technique_en": "Registry Run Keys / Startup Folder",
   "analytic_id": "AN1032",
   "detection_strategy_id": "DET0365",
   "analytic_name": "Analytic 1032",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | File Creation (WinEventLog:Microsoft-Windows-Shell-Core)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Microsoft-Windows-Shell-Core)",
   "tuning": "ImagePath | RegistryKeyPath | TimeWindow | UserContext",
   "detection_logic_en": "Correlation of Registry key creation/modification events under known Run/Startup keys with new or unusual binary paths or script-based payloads. Multi-event detection includes registry modification followed by process execution from non-standard directories or abnormal parent-child process relationships."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1547.002",
   "technique_ja": "認証パッケージ",
   "technique_en": "Authentication Package",
   "analytic_id": "AN0583",
   "detection_strategy_id": "DET0207",
   "analytic_name": "Analytic 0583",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | ImageSignatureStatus | RegistryPathScope | UserContext | ParentProcess",
   "detection_logic_en": "Registry modification of the LSA Authentication Packages key followed by LSASS loading a non-standard or unsigned DLL. This includes unusual write access to `HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa`, especially during non-installation timeframes. Correlated with `lsass.exe` loading DLLs not present in baseline or lacking valid signatures."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1547.003",
   "technique_ja": "タイムプロバイダ",
   "technique_en": "Time Providers",
   "analytic_id": "AN0341",
   "detection_strategy_id": "DET0122",
   "analytic_name": "Analytic 0341",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "RegistryPathScope | UserContext | TimeWindow | DllPathEntropyThreshold",
   "detection_logic_en": "Behavioral correlation of privileged registry key creation under the W32Time TimeProviders path combined with a new DLL written to disk and potential process activity by LocalService. Indicates abuse of Time Providers for persistence."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1547.004",
   "technique_ja": "WinlogonヘルパDLL",
   "technique_en": "Winlogon Helper DLL",
   "analytic_id": "AN1133",
   "detection_strategy_id": "DET0404",
   "analytic_name": "Analytic 1133",
   "platforms": "Windows",
   "log_sources": "Module Load (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Security) | Windows Registry Key Access (Autoruns:RegistryScan)",
   "log_sources_ja": "モジュール読み込み (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Security) | Windowsレジストリキーアクセス (Autoruns:RegistryScan)",
   "tuning": "TimeWindow | UserContext | BinarySignatureValidation | ExecutablePathScope",
   "detection_logic_en": "Monitor Windows Registry modifications to Winlogon keys (Shell, Userinit, Notify) that introduce new executable or DLL paths. Correlate these changes with subsequent DLL loading, image loads, or process creation originating from winlogon.exe or userinit.exe. Abnormal child process lineage or unauthorized binaries in C:\\Windows\\System32 may indicate abuse."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1547.005",
   "technique_ja": "セキュリティサポートプロバイダ",
   "technique_en": "Security Support Provider",
   "analytic_id": "AN1495",
   "detection_strategy_id": "DET0542",
   "analytic_name": "Analytic 1495",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Module Load (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | DLLSignatureValidation | CustomSSPNameList | BootContextCorrelation",
   "detection_logic_en": "Monitor registry modifications to `HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\Security Packages` or `...\\OSConfig\\Security Packages`, especially insertions of new DLL entries. Correlate this with subsequent DLL module loads into `lsass.exe`. Track unsigned or anomalous DLLs loading into LSASS using image load auditing. LSASS loads unsigned DLL due to AuditLevel=8 registry configuration or System reboot followed by DLL load into lsass.exe"
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1547.006",
   "technique_ja": "カーネルモジュールと拡張",
   "technique_en": "Kernel Modules and Extensions",
   "analytic_id": "AN1243",
   "detection_strategy_id": "DET0450",
   "analytic_name": "Analytic 1243",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | File Creation (auditd:SYSCALL) | File Modification (linux:osquery)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ファイル作成 (auditd:SYSCALL) | ファイル変更 (linux:osquery)",
   "tuning": "UserContext | TimeWindow | FilePathRegex",
   "detection_logic_en": "Monitor kernel module load/unload activity via modprobe, insmod, rmmod, or direct manipulation of /lib/modules. Correlate with installation of kernel headers, compilation commands, or downloads of .ko files. Detect anomalies in unsigned module loading or repeated module load attempts under non-root users."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1547.006",
   "technique_ja": "カーネルモジュールと拡張",
   "technique_en": "Kernel Modules and Extensions",
   "analytic_id": "AN1244",
   "detection_strategy_id": "DET0450",
   "analytic_name": "Analytic 1244",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Process Creation (macos:osquery) | Kernel Module Load (macos:osquery) | File Modification (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | プロセス生成 (macos:osquery) | カーネルモジュール読み込み (macos:osquery) | ファイル変更 (macos:osquery)",
   "tuning": "DeveloperIDAllowlist | KextLoadTimeWindow | SignatureCheckFlag",
   "detection_logic_en": "Detect user-initiated kextload commands or modifications to /Library/Extensions. Correlate with changes to KextPolicy database or unauthorized developer signing identities. Alert on attempts to disable SIP or load legacy extensions from unsigned sources."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1547.007",
   "technique_ja": "再オープンアプリケーション",
   "technique_en": "Re-opened Applications",
   "analytic_id": "AN0349",
   "detection_strategy_id": "DET0125",
   "analytic_name": "Analytic 0349",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (fs:filesystem) | Logon Session Metadata (macos:unifiedlog) | File Metadata (macos:endpointsecurity)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (fs:filesystem) | ログオンセッションメタデータ (macos:unifiedlog) | ファイルメタデータ (macos:endpointsecurity)",
   "tuning": "UserContext | FilePathPattern | TimeWindow | BinaryAnomalyScore",
   "detection_logic_en": "Unusual modification or creation of loginwindow-related plist files in '~/Library/Preferences/ByHost' correlated with unauthorized application paths and execution upon login."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1547.008",
   "technique_ja": "LSASSドライバ",
   "technique_en": "LSASS Driver",
   "analytic_id": "AN0629",
   "detection_strategy_id": "DET0225",
   "analytic_name": "Analytic 0629",
   "platforms": "Windows",
   "log_sources": "Module Load (WinEventLog:Security) | Driver Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | File Modification (WinEventLog:Sysmon) | Windows Registry Key Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "モジュール読み込み (WinEventLog:Security) | ドライバ読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Sysmon) | Windowsレジストリキー作成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | ImagePathPattern | SignatureValidation | RegistryKeyScope | FileHashAllowList",
   "detection_logic_en": "Unauthorized creation or modification of DLLs loaded by LSASS, abnormal registry values under LSA extensions, and anomalous DLL load activity into the lsass.exe process context—correlated during boot or logon events."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1547.009",
   "technique_ja": "ショートカットの変更",
   "technique_en": "Shortcut Modification",
   "analytic_id": "AN0510",
   "detection_strategy_id": "DET0180",
   "analytic_name": "Analytic 0510",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Modification (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon)",
   "tuning": "TargetPathRegex | TimeWindow | UserContextScope | ZoneIdentifierThreshold",
   "detection_logic_en": "Detection correlates file creation or modification of `.lnk` (shortcut) files in autostart locations with anomalous parent-child process lineage or unsigned binaries. Defenders should watch for LNK creation/modification events outside of known software installations, patch events, or OS updates. Flag shortcut targets pointing to suspicious locations or unknown binaries, particularly those written by script interpreters or spawned from phishing delivery chains."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1547.010",
   "technique_ja": "ポートモニタ",
   "technique_en": "Port Monitors",
   "analytic_id": "AN0580",
   "detection_strategy_id": "DET0204",
   "analytic_name": "Analytic 0580",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | OS API Execution (WinEventLog:Application)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | OS API実行 (WinEventLog:Application)",
   "tuning": "TargetDLLDirectory | SignedImageValidation | UserContextScope | TimeWindow | AddMonitorCallContext",
   "detection_logic_en": "Detects suspicious registry modifications under `HKLM\\SYSTEM\\CurrentControlSet\\Control\\Print\\Monitors\\*\\Driver`, DLL loads by `spoolsv.exe` of non-standard or unsigned modules, and abnormal usage of the `AddMonitor` API by non-installation processes. This pattern often indicates an attempt to persist a malicious DLL via the print monitor mechanism, particularly when correlated with creation of files in `C:\\Windows\\System32` not tied to known patches or installations."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1547.012",
   "technique_ja": "プリントプロセッサ",
   "technique_en": "Print Processors",
   "analytic_id": "AN0074",
   "detection_strategy_id": "DET0026",
   "analytic_name": "Analytic 0074",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | PrintProcessorDirectory | DLLNamePattern | SignedImageValidation | ServiceRestartTrigger",
   "detection_logic_en": "Correlated registry modifications under Print Processors path, followed by DLL file creation within the system print processor directory, and DLL load by spoolsv.exe. Malicious execution often occurs during service restart or system boot, with SYSTEM-level privileges."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1547.013",
   "technique_ja": "XDG自動起動エントリ",
   "technique_en": "XDG Autostart Entries",
   "analytic_id": "AN1096",
   "detection_strategy_id": "DET0390",
   "analytic_name": "Analytic 1096",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:SYSCALL) | File Access (auditd:SYSCALL) | Process Creation (auditd:EXECVE) | File Metadata (linux:osquery) | Logon Session Creation (linux:auth)",
   "log_sources_ja": "ファイル作成 (auditd:SYSCALL) | ファイルアクセス (auditd:SYSCALL) | プロセス生成 (auditd:EXECVE) | ファイルメタデータ (linux:osquery) | ログオンセッション作成 (linux:auth)",
   "tuning": "ExecCommandPattern | AutostartDirectory | TimeWindow | UserContext | PackageOriginBaseline",
   "detection_logic_en": "Correlation of file creation/modification of `.desktop` files within XDG autostart directories, followed by execution of processes at user login initiated by the desktop environment. Malicious entries typically include suspicious Exec paths or anomalous names and are not associated with installed packages."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1547.014",
   "technique_ja": "Active Setup",
   "technique_en": "Active Setup",
   "analytic_id": "AN0871",
   "detection_strategy_id": "DET0312",
   "analytic_name": "Analytic 0871",
   "platforms": "Windows",
   "log_sources": "Logon Session Metadata (WinEventLog:Security) | Process Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon) | Windows Registry Key Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッションメタデータ (WinEventLog:Security) | プロセス生成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | Windowsレジストリキー作成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | ParentProcessName | StubPathValueEntropy | SignedBinaryStatus | RegistryKeyOwner",
   "detection_logic_en": "Multi-event correlation of Registry creation under Active Setup with anomalous execution of processes at user logon. Behavioral patterns include creation/modification of HKLM Active Setup keys with non-standard StubPath values, followed by process execution from uncommon paths, unsigned binaries, or unusual parent-child lineage post-user login."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1547.015",
   "technique_ja": "ログインアイテム",
   "technique_en": "Login Items",
   "analytic_id": "AN0340",
   "detection_strategy_id": "DET0121",
   "analytic_name": "Analytic 0340",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:unifiedlog) | OS API Execution (macos:unifiedlog) | Script Execution (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog) | OS API実行 (macos:unifiedlog) | スクリプト実行 (macos:unifiedlog)",
   "tuning": "TimeWindow | UserContext | ExecutableAllowlist | PathRegexExclusion",
   "detection_logic_en": "Creation or modification of Login Items using AppleScript or Service Management Framework. Detection focuses on file creation/modification of `backgrounditems.btm`, new executables in `Contents/Library/LoginItems/`, use of `SMLoginItemSetEnabled` API, or suspicious processes triggered post-login without user interaction. Behavioral pivot includes anomalous AppleEvents, suspicious parent-child process pairs, and login-triggered execution chains."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1554",
   "technique_ja": "ホストソフトウェアバイナリの侵害",
   "technique_en": "Compromise Host Software Binary",
   "analytic_id": "AN0949",
   "detection_strategy_id": "DET0336",
   "analytic_name": "Analytic 0949",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Modification (WinEventLog:Sysmon) | Process Creation (WinEventLog:Security)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Security)",
   "tuning": "MonitoredPaths | SignatureValidation | TimeWindow",
   "detection_logic_en": "Monitors for unexpected modifications of system or application binaries, particularly signed executables. Correlates file write events with subsequent unsigned or anomalously signed process execution, and checks for tampered binaries outside normal patch cycles."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1554",
   "technique_ja": "ホストソフトウェアバイナリの侵害",
   "technique_en": "Compromise Host Software Binary",
   "analytic_id": "AN0950",
   "detection_strategy_id": "DET0336",
   "analytic_name": "Analytic 0950",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:EXECVE)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:EXECVE)",
   "tuning": "WatchedDirectories | BaselineHashes",
   "detection_logic_en": "Detects modification of system or application binaries by monitoring /usr/bin, /bin, and other privileged directories. Correlates file integrity monitoring (FIM) events with unexpected process executions or service restarts."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1554",
   "technique_ja": "ホストソフトウェアバイナリの侵害",
   "technique_en": "Compromise Host Software Binary",
   "analytic_id": "AN0951",
   "detection_strategy_id": "DET0336",
   "analytic_name": "Analytic 0951",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "ApplicationPaths | SignatureVerificationDepth",
   "detection_logic_en": "Monitors binary modification in /Applications and system library paths. Detects unsigned or improperly signed binaries executed after modification. Tracks Gatekeeper or notarization bypass attempts tied to modified binaries."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1554",
   "technique_ja": "ホストソフトウェアバイナリの侵害",
   "technique_en": "Compromise Host Software Binary",
   "analytic_id": "AN0952",
   "detection_strategy_id": "DET0336",
   "analytic_name": "Analytic 0952",
   "platforms": "ESXi",
   "log_sources": "File Modification (esxi:hostd) | Module Load (esxi:vmkernel)",
   "log_sources_ja": "ファイル変更 (esxi:hostd) | モジュール読み込み (esxi:vmkernel)",
   "tuning": "MonitoredModules | CorrelationWindow",
   "detection_logic_en": "Detects unauthorized modification of host binaries, modules, or services within ESXi. Correlates tampered files with subsequent unexpected service behavior or malicious module load attempts."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556",
   "technique_ja": "認証プロセスの変更",
   "technique_en": "Modify Authentication Process",
   "analytic_id": "AN0287",
   "detection_strategy_id": "DET0104",
   "analytic_name": "Analytic 0287",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Process Access (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "MonitoredRegistryKeys | TimeWindow",
   "detection_logic_en": "Detects modification of LSASS and authentication DLLs, suspicious registry changes to password filter packages, and abnormal process access to lsass.exe. Correlates registry modifications, DLL loads, and process handle access events."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556",
   "technique_ja": "認証プロセスの変更",
   "technique_en": "Modify Authentication Process",
   "analytic_id": "AN0288",
   "detection_strategy_id": "DET0104",
   "analytic_name": "Analytic 0288",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "WatchedPaths",
   "detection_logic_en": "Detects modification of PAM configuration files, unauthorized new PAM modules, and suspicious process execution accessing PAM-related binaries. Correlates file modification events in /etc/pam.d/ with process execution of unauthorized binaries."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556",
   "technique_ja": "認証プロセスの変更",
   "technique_en": "Modify Authentication Process",
   "analytic_id": "AN0289",
   "detection_strategy_id": "DET0104",
   "analytic_name": "Analytic 0289",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | Process Access (macos:osquery)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | プロセスアクセス (macos:osquery)",
   "tuning": "PluginPaths",
   "detection_logic_en": "Detects unauthorized additions or changes to /Library/Security/SecurityAgentPlugins and suspicious process activity attempting to hook authentication APIs. Correlates file modifications with abnormal plugin loads in authentication flows."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556",
   "technique_ja": "認証プロセスの変更",
   "technique_en": "Modify Authentication Process",
   "analytic_id": "AN0290",
   "detection_strategy_id": "DET0104",
   "analytic_name": "Analytic 0290",
   "platforms": "Identity Provider",
   "log_sources": "Cloud Service Modification (azure:policy) | User Account Modification (m365:unified)",
   "log_sources_ja": "クラウドサービス変更 (azure:policy) | ユーザーアカウント変更 (m365:unified)",
   "tuning": "PolicyBaseline",
   "detection_logic_en": "Detects suspicious configuration changes in IdP authentication flows such as enabling reversible password encryption, MFA bypass, or policy weakening. Correlates policy modification events with unusual administrative activity."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556",
   "technique_ja": "認証プロセスの変更",
   "technique_en": "Modify Authentication Process",
   "analytic_id": "AN0291",
   "detection_strategy_id": "DET0104",
   "analytic_name": "Analytic 0291",
   "platforms": "IaaS",
   "log_sources": "User Account Modification (AWS:CloudTrail) | Cloud Service Modification (AWS:CloudTrail)",
   "log_sources_ja": "ユーザーアカウント変更 (AWS:CloudTrail) | クラウドサービス変更 (AWS:CloudTrail)",
   "tuning": "ApprovedAccounts",
   "detection_logic_en": "Detects unauthorized changes to IAM authentication configurations such as disabling MFA, creating backdoor access keys, or altering trust policies. Correlates identity policy updates with unusual login behavior."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.001",
   "technique_ja": "ドメインコントローラ認証",
   "technique_en": "Domain Controller Authentication",
   "analytic_id": "AN0757",
   "detection_strategy_id": "DET0271",
   "analytic_name": "Analytic 0757",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Logon Session Creation (WinEventLog:Security) | File Modification (WinEventLog:System)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ログオンセッション作成 (WinEventLog:Security) | ファイル変更 (WinEventLog:System)",
   "tuning": "MonitoredDLLs | TimeWindow | UserContext",
   "detection_logic_en": "Detects anomalous process access to LSASS on domain controllers, suspicious module loads of authentication DLLs, and registry or file modifications indicative of Skeleton Key–style patching. Correlates LSASS access attempts with subsequent abnormal logon activity patterns."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.002",
   "technique_ja": "パスワードフィルタDLL",
   "technique_en": "Password Filter DLL",
   "analytic_id": "AN1303",
   "detection_strategy_id": "DET0472",
   "analytic_name": "Analytic 1303",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "RegistryPath | AllowedDLLs | TimeWindow | FilePathPatterns",
   "detection_logic_en": "Detects suspicious registration of new password filter DLLs into the authentication process. Correlates registry modifications to LSASS Notification Packages with subsequent DLL creation and loading events. Observes anomalous file placement of DLLs in system directories followed by LSASS loading the new filter during logon/password change activity."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.003",
   "technique_ja": "プラガブル認証モジュール(PAM)",
   "technique_en": "Pluggable Authentication Modules",
   "analytic_id": "AN1250",
   "detection_strategy_id": "DET0454",
   "analytic_name": "Analytic 1250",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Logon Session Creation (NSM:Connections)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | ログオンセッション作成 (NSM:Connections)",
   "tuning": "MonitoredPaths | TimeWindow | BaselineAccounts",
   "detection_logic_en": "Detects unauthorized modifications to PAM configuration files or shared object modules. Correlates file modification events under /etc/pam.d/ or /lib/security/ with unusual authentication activity such as multiple simultaneous logins, off-hours logins, or logons without corresponding physical/VPN access."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.003",
   "technique_ja": "プラガブル認証モジュール(PAM)",
   "technique_en": "Pluggable Authentication Modules",
   "analytic_id": "AN1251",
   "detection_strategy_id": "DET0454",
   "analytic_name": "Analytic 1251",
   "platforms": "macOS",
   "log_sources": "Logon Session Creation (macos:unifiedlog) | File Modification (macos:osquery)",
   "log_sources_ja": "ログオンセッション作成 (macos:unifiedlog) | ファイル変更 (macos:osquery)",
   "tuning": "WatchedPlugins | CorrelatedSources",
   "detection_logic_en": "Detects suspicious changes to macOS authorization and PAM plugin files. Correlates file modifications under /etc/pam.d/ or /Library/Security/SecurityAgentPlugins with unexpected authentication attempts or anomalous account usage."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.004",
   "technique_ja": "ネットワークデバイス認証",
   "technique_en": "Network Device Authentication",
   "analytic_id": "AN0758",
   "detection_strategy_id": "DET0272",
   "analytic_name": "Analytic 0758",
   "platforms": "Network Devices",
   "log_sources": "File Modification (networkconfig) | User Account Authentication (network:auth)",
   "log_sources_ja": "ファイル変更 (networkconfig) | ユーザーアカウント認証 (network:auth)",
   "tuning": "BaselineChecksums | AuthFailureThreshold | VerificationInterval",
   "detection_logic_en": "Detects unauthorized modification of network device authentication by correlating OS image file changes, checksum mismatches, or memory verification failures with anomalous authentication events. Focus is on behaviors where patched images introduce hardcoded passwords or bypass native authentication."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.005",
   "technique_ja": "可逆暗号化",
   "technique_en": "Reversible Encryption",
   "analytic_id": "AN1621",
   "detection_strategy_id": "DET0589",
   "analytic_name": "Analytic 1621",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "MonitoredOUs | TimeWindow | SuspiciousCmdletList",
   "detection_logic_en": "Detects enabling of reversible password encryption in Active Directory or Group Policy, suspicious PowerShell commands modifying AD user properties, and unusual account configuration changes correlated with policy modifications. Multi-event correlation links Group Policy edits, PowerShell command execution, and user account property changes to identify tampering with authentication encryption settings."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0543",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0543",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Modification (WinEventLog:Security) | Script Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (WinEventLog:Security) | スクリプト実行 (WinEventLog:PowerShell)",
   "tuning": "WatchedAttributes | TimeWindow",
   "detection_logic_en": "Detects registry and Group Policy modifications that disable or weaken MFA, suspicious PowerShell usage modifying MFA-related attributes, and anomalous login sessions succeeding without expected MFA challenge."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0544",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0544",
   "platforms": "Identity Provider",
   "log_sources": "Application Log Content (azure:signinlogs) | User Account Modification (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (azure:signinlogs) | ユーザーアカウント変更 (m365:unified)",
   "tuning": "PrivilegedRoles",
   "detection_logic_en": "Detects conditional access policy changes, exclusion of accounts from MFA enforcement, or registration of new MFA factors by non-admin or anomalous users."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0545",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0545",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Modification (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス変更 (AWS:CloudTrail)",
   "tuning": "MonitoredServices",
   "detection_logic_en": "Detects API calls to cloud secrets/MFA configurations where MFA enforcement policies are disabled or bypassed."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0546",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0546",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | User Account Authentication (NSM:Connections)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | ユーザーアカウント認証 (NSM:Connections)",
   "tuning": "MFAHooks",
   "detection_logic_en": "Detects PAM module modifications or removal of MFA hooks in /etc/pam.d/ configurations, correlated with successful authentications lacking MFA prompts."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0547",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0547",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | User Account Authentication (macos:unifiedlog)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | ユーザーアカウント認証 (macos:unifiedlog)",
   "tuning": "WatchedPluginPaths",
   "detection_logic_en": "Detects modifications to authorization plugins responsible for MFA enforcement and correlates with suspicious login sessions missing MFA prompts."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0548",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0548",
   "platforms": "SaaS",
   "log_sources": "User Account Modification (saas:zoom)",
   "log_sources_ja": "ユーザーアカウント変更 (saas:zoom)",
   "tuning": "AcceptedFactors",
   "detection_logic_en": "Detects suspicious MFA method changes, such as registration of weaker factors (e.g., SMS), or removal of MFA requirements for specific accounts or groups."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0549",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0549",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified)",
   "tuning": "MonitoredPolicies",
   "detection_logic_en": "Detects MFA bypass attempts by modifying tenant-wide authentication policies or excluding high-value accounts from MFA enforcement."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.007",
   "technique_ja": "ハイブリッドID",
   "technique_en": "Hybrid Identity",
   "analytic_id": "AN0814",
   "detection_strategy_id": "DET0293",
   "analytic_name": "Analytic 0814",
   "platforms": "Windows",
   "log_sources": "Module Load (WinEventLog:Sysmon) | Active Directory Object Modification (WinEventLog:Security) | Logon Session Creation (WinEventLog:Security)",
   "log_sources_ja": "モジュール読み込み (WinEventLog:Sysmon) | Active Directoryオブジェクト変更 (WinEventLog:Security) | ログオンセッション作成 (WinEventLog:Security)",
   "tuning": "WatchedServices | TimeWindow",
   "detection_logic_en": "Detects injection or tampering of DLLs in hybrid identity agents (e.g., AzureADConnectAuthenticationAgentService), registry or configuration changes tied to PTA/AD FS, and anomalous LSASS or AD FS module loads correlated with authentication anomalies."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.007",
   "technique_ja": "ハイブリッドID",
   "technique_en": "Hybrid Identity",
   "analytic_id": "AN0815",
   "detection_strategy_id": "DET0293",
   "analytic_name": "Analytic 0815",
   "platforms": "Identity Provider",
   "log_sources": "Application Log Content (azure:signinlogs) | User Account Modification (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (azure:signinlogs) | ユーザーアカウント変更 (m365:unified)",
   "tuning": "PrivilegedRoles",
   "detection_logic_en": "Detects registration of new PTA agents, conditional access changes disabling hybrid MFA enforcement, or suspicious updates to AD FS token-signing configurations."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.007",
   "technique_ja": "ハイブリッドID",
   "technique_en": "Hybrid Identity",
   "analytic_id": "AN0816",
   "detection_strategy_id": "DET0293",
   "analytic_name": "Analytic 0816",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Modification (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス変更 (AWS:CloudTrail)",
   "tuning": "MonitoredFederations",
   "detection_logic_en": "Detects API calls registering or updating hybrid identity connectors, modification of cloud-to-on-premises federation trust, and unusual token issuance logs."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.007",
   "technique_ja": "ハイブリッドID",
   "technique_en": "Hybrid Identity",
   "analytic_id": "AN0817",
   "detection_strategy_id": "DET0293",
   "analytic_name": "Analytic 0817",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified)",
   "tuning": "PolicyScope",
   "detection_logic_en": "Detects tenant-wide authentication or conditional access changes that weaken hybrid identity enforcement, including disabling AD FS or bypassing hybrid MFA policies."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.007",
   "technique_ja": "ハイブリッドID",
   "technique_en": "Hybrid Identity",
   "analytic_id": "AN0818",
   "detection_strategy_id": "DET0293",
   "analytic_name": "Analytic 0818",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (saas:okta)",
   "log_sources_ja": "アプリケーションログ内容 (saas:okta)",
   "tuning": "FederationEndpoints",
   "detection_logic_en": "Detects suspicious changes to SAML/OAuth federation configurations, such as new signing certificates, altered endpoints, or claims issuance rules granting elevated privileges."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.008",
   "technique_ja": "ネットワークプロバイダDLL",
   "technique_en": "Network Provider DLL",
   "analytic_id": "AN1598",
   "detection_strategy_id": "DET0580",
   "analytic_name": "Analytic 1598",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "MonitoredRegistryKeys | SuspiciousDLLPaths | TimeWindow",
   "detection_logic_en": "Detects registration of new or modified network provider DLLs via registry changes, anomalous file creation of DLLs in system directories, and suspicious process activity (mpnotify.exe interacting with non-standard DLLs). Multi-event correlation ties registry modification events to subsequent DLL loads during user logon activity."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.009",
   "technique_ja": "条件付きアクセスポリシー",
   "technique_en": "Conditional Access Policies",
   "analytic_id": "AN0087",
   "detection_strategy_id": "DET0030",
   "analytic_name": "Analytic 0087",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Modification (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス変更 (AWS:CloudTrail)",
   "tuning": "MonitoredIAMConditions | TimeWindow | PrivilegedAccounts",
   "detection_logic_en": "Detects modifications to IAM conditions or policies that alter authentication behavior, such as adding permissive trusted IPs, removing MFA requirements, or changing regional access restrictions. Behavioral detection focuses on anomalous policy updates tied to privileged accounts and subsequent suspicious logon activity from previously blocked regions or devices."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1556.009",
   "technique_ja": "条件付きアクセスポリシー",
   "technique_en": "Conditional Access Policies",
   "analytic_id": "AN0088",
   "detection_strategy_id": "DET0030",
   "analytic_name": "Analytic 0088",
   "platforms": "Identity Provider",
   "log_sources": "Active Directory Object Modification (azure:activity) | Application Log Content (saas:okta)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (azure:activity) | アプリケーションログ内容 (saas:okta)",
   "tuning": "TargetedApplications | RiskThresholds | UserContext",
   "detection_logic_en": "Detects suspicious updates to conditional access or MFA enforcement policies in identity providers such as Entra ID, Okta, or JumpCloud. Focus is on removal of policy blocks, addition of broad exclusions, or registration of adversary-controlled MFA methods, followed by anomalous login activity that takes advantage of the modified policies."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1653",
   "technique_ja": "電源設定",
   "technique_en": "Power Settings",
   "analytic_id": "AN1174",
   "detection_strategy_id": "DET0417",
   "analytic_name": "Analytic 1174",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security)",
   "tuning": "AllowedAdminTools | TimeWindow",
   "detection_logic_en": "Monitor command execution of powercfg.exe with arguments modifying sleep, hibernate, or display timeouts. Abnormal or repeated modifications to power settings outside administrative baselines may indicate persistence attempts. Correlate process creation with registry and system configuration changes to build behavioral chains."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1653",
   "technique_ja": "電源設定",
   "technique_en": "Power Settings",
   "analytic_id": "AN1175",
   "detection_strategy_id": "DET0417",
   "analytic_name": "Analytic 1175",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | File Modification (auditd:PATH)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ファイル変更 (auditd:PATH)",
   "tuning": "KnownMaintenanceWindows",
   "detection_logic_en": "Detect execution of system utilities (systemctl, systemd-inhibit, systemdsleep) modifying sleep or hibernate behavior. Abnormal edits to system configuration files (e.g., /etc/systemd/sleep.conf) should be correlated with process execution to identify persistence techniques."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1653",
   "technique_ja": "電源設定",
   "technique_en": "Power Settings",
   "analytic_id": "AN1176",
   "detection_strategy_id": "DET0417",
   "analytic_name": "Analytic 1176",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog)",
   "tuning": "AdminWhitelists",
   "detection_logic_en": "Monitor pmset command executions altering sleep/hibernate/standby parameters. Unexpected modifications to /Library/Preferences/SystemConfiguration/com.apple.PowerManagement.plist or similar files should be correlated with process activity."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1668",
   "technique_ja": "排他的制御",
   "technique_en": "Exclusive Control",
   "analytic_id": "AN0045",
   "detection_strategy_id": "DET0015",
   "analytic_name": "Analytic 0045",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Process Termination (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | プロセス終了 (WinEventLog:Sysmon)",
   "tuning": "ServiceList | TimeWindow",
   "detection_logic_en": "Detects unusual command executions and service modifications that indicate self-patching or disabling of vulnerable services post-compromise. Defenders should monitor for service stop commands, suspicious process termination, and execution of binaries or scripts aligned with known patching or service management tools outside of expected admin contexts."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1668",
   "technique_ja": "排他的制御",
   "technique_en": "Exclusive Control",
   "analytic_id": "AN0046",
   "detection_strategy_id": "DET0015",
   "analytic_name": "Analytic 0046",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | Process Termination (linux:syslog)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | プロセス終了 (linux:syslog)",
   "tuning": "CriticalProcessList | AdminUserContext",
   "detection_logic_en": "Detects adversary attempts to monopolize control of compromised systems by issuing service stop commands, unloading vulnerable modules, or forcefully killing competing processes. Defenders should monitor audit logs and syslog for administrative utilities (systemctl, service, kill) being invoked outside of normal change management."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1668",
   "technique_ja": "排他的制御",
   "technique_en": "Exclusive Control",
   "analytic_id": "AN0047",
   "detection_strategy_id": "DET0015",
   "analytic_name": "Analytic 0047",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Process Termination (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | プロセス終了 (macos:osquery)",
   "tuning": "ProtectedServiceList",
   "detection_logic_en": "Detects unauthorized termination of system daemons or commands issued through launchctl or kill to stop competing services or malware processes. Defenders should monitor unified logs and EDR telemetry for unusual service modifications or terminations."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1671",
   "technique_ja": "クラウドアプリ統合",
   "technique_en": "Cloud Application Integration",
   "analytic_id": "AN1487",
   "detection_strategy_id": "DET0539",
   "analytic_name": "Analytic 1487",
   "platforms": "Office Suite",
   "log_sources": "Active Directory Object Modification (m365:unified) | Cloud Service Modification (azure:audit)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (m365:unified) | クラウドサービス変更 (azure:audit)",
   "tuning": "PrivilegedUserList | ApplicationScopeThreshold",
   "detection_logic_en": "Detects suspicious OAuth application integrations within Office 365 or Google Workspace environments, such as new app registrations, unexpected consent grants, or privilege assignments. Defenders should correlate between application creation/modification events and associated user or service principal activity to identify persistence via app integrations."
  },
  {
   "tactic_id": "TA0003",
   "tactic_ja": "永続化",
   "technique_id": "T1671",
   "technique_ja": "クラウドアプリ統合",
   "technique_en": "Cloud Application Integration",
   "analytic_id": "AN1488",
   "detection_strategy_id": "DET0539",
   "analytic_name": "Analytic 1488",
   "platforms": "SaaS",
   "log_sources": "Cloud Service Modification (saas:integration) | Application Log Content (saas:audit)",
   "log_sources_ja": "クラウドサービス変更 (saas:integration) | アプリケーションログ内容 (saas:audit)",
   "tuning": "AppWhitelist | ConsentDelegationPolicy",
   "detection_logic_en": "Detects anomalous SaaS application integration activity across environments such as Slack, Salesforce, or other enterprise SaaS services. Focus is on unauthorized app additions, unusual permission grants, and persistence through service principal tokens."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1037",
   "technique_ja": "起動/ログオン初期化スクリプト",
   "technique_en": "Boot or Logon Initialization Scripts",
   "analytic_id": "AN0311",
   "detection_strategy_id": "DET0112",
   "analytic_name": "Analytic 0311",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Security) | Scheduled Job Creation (WinEventLog:TaskScheduler)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Security) | スケジュールジョブ作成 (WinEventLog:TaskScheduler)",
   "tuning": "TargetObject | ParentProcessName | TimeWindow",
   "detection_logic_en": "Monitoring modification and execution of user or system logon scripts such as in registry Run keys or startup folders."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1037",
   "technique_ja": "起動/ログオン初期化スクリプト",
   "technique_en": "Boot or Logon Initialization Scripts",
   "analytic_id": "AN0312",
   "detection_strategy_id": "DET0112",
   "analytic_name": "Analytic 0312",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Metadata (auditd:PATH) | File Modification (linux:osquery)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルメタデータ (auditd:PATH) | ファイル変更 (linux:osquery)",
   "tuning": "FilePath | UserContext | TimeWindow",
   "detection_logic_en": "Detection of changes or execution of shell initialization scripts like .bashrc, .profile, or /etc/profile for persistence."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1037",
   "technique_ja": "起動/ログオン初期化スクリプト",
   "technique_en": "Boot or Logon Initialization Scripts",
   "analytic_id": "AN0313",
   "detection_strategy_id": "DET0112",
   "analytic_name": "Analytic 0313",
   "platforms": "macOS",
   "log_sources": "Script Execution (macos:unifiedlog) | File Access (fs:fsusage) | Service Metadata (macos:osquery)",
   "log_sources_ja": "スクリプト実行 (macos:unifiedlog) | ファイルアクセス (fs:fsusage) | サービスメタデータ (macos:osquery)",
   "tuning": "Label | ProgramArguments | UserContext",
   "detection_logic_en": "Monitoring for modification and execution of login hook scripts or LaunchAgents/LaunchDaemons used for persistence."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1037",
   "technique_ja": "起動/ログオン初期化スクリプト",
   "technique_en": "Boot or Logon Initialization Scripts",
   "analytic_id": "AN0314",
   "detection_strategy_id": "DET0112",
   "analytic_name": "Analytic 0314",
   "platforms": "ESXi",
   "log_sources": "Script Execution (esxi:vmkernel) | File Modification (esxi:hostd)",
   "log_sources_ja": "スクリプト実行 (esxi:vmkernel) | ファイル変更 (esxi:hostd)",
   "tuning": "ScriptName | LogSeverity",
   "detection_logic_en": "Detection of modification to ESXi rc.local.d or rc scripts that are used to execute on boot."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1037",
   "technique_ja": "起動/ログオン初期化スクリプト",
   "technique_en": "Boot or Logon Initialization Scripts",
   "analytic_id": "AN0315",
   "detection_strategy_id": "DET0112",
   "analytic_name": "Analytic 0315",
   "platforms": "Network Devices",
   "log_sources": "File Modification (networkdevice:syslog)",
   "log_sources_ja": "ファイル変更 (networkdevice:syslog)",
   "tuning": "Interface | CommandPattern",
   "detection_logic_en": "Detection of changes to device startup-config files that include boot scripts or scheduled execution routines."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1037.001",
   "technique_ja": "ログオンスクリプト(Windows)",
   "technique_en": "Logon Script (Windows)",
   "analytic_id": "AN0199",
   "detection_strategy_id": "DET0072",
   "analytic_name": "Analytic 0199",
   "platforms": "Windows",
   "log_sources": "File Access (WinEventLog:Security) | Script Execution (WinEventLog:System) | Logon Session Creation (WinEventLog:Security) | Process Creation (WinEventLog:Security)",
   "log_sources_ja": "ファイルアクセス (WinEventLog:Security) | スクリプト実行 (WinEventLog:System) | ログオンセッション作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Security)",
   "tuning": "script_path_keywords | execution_time_window | user_context",
   "detection_logic_en": "Detects adversary use of logon script configuration via Group Policy or user object attributes, followed by script execution post-authentication. Behavior includes modification of script path or file, then process execution under user logon context."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1037.002",
   "technique_ja": "ログインフック",
   "technique_en": "Login Hook",
   "analytic_id": "AN0682",
   "detection_strategy_id": "DET0244",
   "analytic_name": "Analytic 0682",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (fs:plist)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (fs:plist)",
   "tuning": "login_hook_path | user_context | time_window | parent_process_name",
   "detection_logic_en": "Detection of persistent login hooks configured via defaults or plist modifications that result in execution of scripts or binaries at user login, breaking expected parent-child process lineage."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1037.003",
   "technique_ja": "ネットワークログオンスクリプト",
   "technique_en": "Network Logon Script",
   "analytic_id": "AN1034",
   "detection_strategy_id": "DET0367",
   "analytic_name": "Analytic 1034",
   "platforms": "Windows",
   "log_sources": "Network Share Access (WinEventLog:Security) | Process Creation (WinEventLog:Security) | Script Execution (WinEventLog:System)",
   "log_sources_ja": "ネットワーク共有アクセス (WinEventLog:Security) | プロセス生成 (WinEventLog:Security) | スクリプト実行 (WinEventLog:System)",
   "tuning": "TargetObject | ParentProcessName | TimeWindow | UserContext",
   "detection_logic_en": "Correlates Group Policy updates that configure network logon scripts with subsequent remote file execution behaviors triggered by user logons to identify potential persistence or execution chains tied to adversarial manipulation of logon scripts."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1037.004",
   "technique_ja": "RCスクリプト",
   "technique_en": "RC Scripts",
   "analytic_id": "AN0658",
   "detection_strategy_id": "DET0237",
   "analytic_name": "Analytic 0658",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Script Execution (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | スクリプト実行 (linux:syslog)",
   "tuning": "script_path | user_context | time_window",
   "detection_logic_en": "Detection of modified or newly created /etc/rc.local or /etc/init.d scripts followed by suspicious execution during system startup."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1037.004",
   "technique_ja": "RCスクリプト",
   "technique_en": "RC Scripts",
   "analytic_id": "AN0659",
   "detection_strategy_id": "DET0237",
   "analytic_name": "Analytic 0659",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (fs:fsusage)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (fs:fsusage)",
   "tuning": "script_name | event_interval | file_permission",
   "detection_logic_en": "Detection of edits or additions to /etc/rc.common, /Library/StartupItems, or /System/Library/StartupItems and associated script execution during login or reboot."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1037.004",
   "technique_ja": "RCスクリプト",
   "technique_en": "RC Scripts",
   "analytic_id": "AN0660",
   "detection_strategy_id": "DET0237",
   "analytic_name": "Analytic 0660",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:syslog) | File Modification (esxi:shell)",
   "log_sources_ja": "コマンド実行 (esxi:syslog) | ファイル変更 (esxi:shell)",
   "tuning": "script_section | command_type | execution_trigger",
   "detection_logic_en": "Detection of changes to /etc/rc.local.d/local.sh or rc.local during post-boot script execution with abnormal commands or additions."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1037.004",
   "technique_ja": "RCスクリプト",
   "technique_en": "RC Scripts",
   "analytic_id": "AN0661",
   "detection_strategy_id": "DET0237",
   "analytic_name": "Analytic 0661",
   "platforms": "Network Devices",
   "log_sources": "File Modification (networkdevice:syslog) | Command Execution (networkdevice:syslog)",
   "log_sources_ja": "ファイル変更 (networkdevice:syslog) | コマンド実行 (networkdevice:syslog)",
   "tuning": "firmware_family | config_line_pattern | reboot_time_window",
   "detection_logic_en": "Detection of modified boot-time configuration scripts that persist malicious CLI commands across reboots."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1037.005",
   "technique_ja": "スタートアップアイテム",
   "technique_en": "Startup Items",
   "analytic_id": "AN1197",
   "detection_strategy_id": "DET0429",
   "analytic_name": "Analytic 1197",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (macos:fsevents)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:fsevents)",
   "tuning": "directory_path | user_context | time_window | process_name",
   "detection_logic_en": "Detects the modification or addition of Launch Agents or Startup Items to establish persistence. Adversaries may write plist or executable files to ~/Library/LaunchAgents/, /Library/StartupItems/, or similar directories and configure them to run at user or system boot. Detection requires correlating file creation or modification events with subsequent user logon or boot-time process execution."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1053",
   "technique_ja": "スケジュールされたタスク/ジョブ",
   "technique_en": "Scheduled Task/Job",
   "analytic_id": "AN0258",
   "detection_strategy_id": "DET0094",
   "analytic_name": "Analytic 0258",
   "platforms": "Windows",
   "log_sources": "Scheduled Job Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | File Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "スケジュールジョブ作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Sysmon)",
   "tuning": "TaskAuthor | CommandLineRegex | ExecutionWindow",
   "detection_logic_en": "Detects creation or modification of scheduled tasks using schtasks.exe, at.exe, or COM objects followed by execution of outlier processes tied to the scheduled job."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1053",
   "technique_ja": "スケジュールされたタスク/ジョブ",
   "technique_en": "Scheduled Task/Job",
   "analytic_id": "AN0259",
   "detection_strategy_id": "DET0094",
   "analytic_name": "Analytic 0259",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Scheduled Job Creation (linux:osquery)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | スケジュールジョブ作成 (linux:osquery)",
   "tuning": "CronSchedulePattern | ServiceUser | BinaryEntropy",
   "detection_logic_en": "Detects creation or modification of cron jobs via crontab, /etc/cron.* directories, or systemd timer units with execution by unusual users or non-standard intervals."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1053",
   "technique_ja": "スケジュールされたタスク/ジョブ",
   "technique_en": "Scheduled Task/Job",
   "analytic_id": "AN0260",
   "detection_strategy_id": "DET0094",
   "analytic_name": "Analytic 0260",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (fs:fsusage) | Scheduled Job Creation (macos:osquery)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (fs:fsusage) | スケジュールジョブ作成 (macos:osquery)",
   "tuning": "PlistLabel | LaunchPath | JobRunInterval",
   "detection_logic_en": "Detects creation or alteration of LaunchAgents or LaunchDaemons with corresponding plist modification followed by execution of associated binaries."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1053",
   "technique_ja": "スケジュールされたタスク/ジョブ",
   "technique_en": "Scheduled Task/Job",
   "analytic_id": "AN0261",
   "detection_strategy_id": "DET0094",
   "analytic_name": "Analytic 0261",
   "platforms": "Containers",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Modification (containerd:runtime)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル変更 (containerd:runtime)",
   "tuning": "ContainerLabel | ScriptFrequency | ImageSource",
   "detection_logic_en": "Detects unusual use of `cron` or `sleep` loops inside containers executing unfamiliar scripts or binaries repeatedly."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1053",
   "technique_ja": "スケジュールされたタスク/ジョブ",
   "technique_en": "Scheduled Task/Job",
   "analytic_id": "AN0262",
   "detection_strategy_id": "DET0094",
   "analytic_name": "Analytic 0262",
   "platforms": "ESXi",
   "log_sources": "Scheduled Job Creation (esxi:vmkernel) | Command Execution (esxi:hostd) | File Modification (esxi:cron)",
   "log_sources_ja": "スケジュールジョブ作成 (esxi:vmkernel) | コマンド実行 (esxi:hostd) | ファイル変更 (esxi:cron)",
   "tuning": "StartupScriptName | ExecutionContext | PersistenceInterval",
   "detection_logic_en": "Detects modification of ESXi cron jobs, local.sh scripts, or scheduled API calls to persist custom binaries or shell scripts."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1053.002",
   "technique_ja": "At",
   "technique_en": "At",
   "analytic_id": "AN0943",
   "detection_strategy_id": "DET0333",
   "analytic_name": "Analytic 0943",
   "platforms": "Windows",
   "log_sources": "Scheduled Job Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "スケジュールジョブ作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TaskUser | ExecutionTimeWindow | CommandLinePattern",
   "detection_logic_en": "Detects creation of scheduled tasks via `at.exe` or WMI `Win32_ScheduledJob` class, followed by execution of anomalous processes by svchost.exe or taskeng.exe."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1053.002",
   "technique_ja": "At",
   "technique_en": "At",
   "analytic_id": "AN0944",
   "detection_strategy_id": "DET0333",
   "analytic_name": "Analytic 0944",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Modification (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL)",
   "tuning": "AtJobPath | ScheduleLatency | JobScriptEntropy",
   "detection_logic_en": "Detects usage of `at` command to schedule jobs, followed by job execution and modification of job files under /var/spool/cron/atjobs."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1053.002",
   "technique_ja": "At",
   "technique_en": "At",
   "analytic_id": "AN0945",
   "detection_strategy_id": "DET0333",
   "analytic_name": "Analytic 0945",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Modification (fs:fsusage) | Process Creation (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル変更 (fs:fsusage) | プロセス生成 (macos:osquery)",
   "tuning": "AtPermissions | ExecutionCommand | RunUser",
   "detection_logic_en": "Detects user or root invocation of `at` command to schedule a job, followed by job execution using LaunchServices and activity in /usr/lib/cron/at."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1053.003",
   "technique_ja": "Cron",
   "technique_en": "Cron",
   "analytic_id": "AN0805",
   "detection_strategy_id": "DET0290",
   "analytic_name": "Analytic 0805",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "CronFilePath | RunUser | ExecutionFrequency",
   "detection_logic_en": "Detects creation or modification of crontab entries by non-root users or from abnormal parent processes, followed by the execution of uncommon binaries at scheduled intervals."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1053.003",
   "technique_ja": "Cron",
   "technique_en": "Cron",
   "analytic_id": "AN0806",
   "detection_strategy_id": "DET0290",
   "analytic_name": "Analytic 0806",
   "platforms": "macOS",
   "log_sources": "Scheduled Job Creation (macos:unifiedlog) | File Modification (fs:fsusage)",
   "log_sources_ja": "スケジュールジョブ作成 (macos:unifiedlog) | ファイル変更 (fs:fsusage)",
   "tuning": "ScriptPath | CronScheduleSyntax | InteractiveUserContext",
   "detection_logic_en": "Detects crontab job additions or modifications via `crontab` utility or direct edits, especially those created by interactive users executing hidden or renamed scripts."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1053.003",
   "technique_ja": "Cron",
   "technique_en": "Cron",
   "analytic_id": "AN0807",
   "detection_strategy_id": "DET0290",
   "analytic_name": "Analytic 0807",
   "platforms": "ESXi",
   "log_sources": "File Modification (esxi:hostd) | Scheduled Job Creation (esxi:cron) | Process Creation (esxi:vmkernel)",
   "log_sources_ja": "ファイル変更 (esxi:hostd) | スケジュールジョブ作成 (esxi:cron) | プロセス生成 (esxi:vmkernel)",
   "tuning": "CrontabFileMonitored | ShellCommandPayload | JobInterval",
   "detection_logic_en": "Detects direct modification of crontab entries in /var/spool/cron/crontabs/root or /etc/rc.local.d/local.sh followed by execution of scripts linked to lateral movement or malware persistence."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1053.005",
   "technique_ja": "スケジュールされたタスク",
   "technique_en": "Scheduled Task",
   "analytic_id": "AN1221",
   "detection_strategy_id": "DET0441",
   "analytic_name": "Analytic 1221",
   "platforms": "Windows",
   "log_sources": "Scheduled Job Creation (WinEventLog:Security) | Scheduled Job Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "スケジュールジョブ作成 (WinEventLog:Security) | スケジュールジョブ変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext | TaskNamePattern | CommandLineEntropyThreshold",
   "detection_logic_en": "Detects the creation, modification, or deletion of scheduled tasks through Task Scheduler, WMI, PowerShell, or API-based methods followed by execution from svchost.exe or taskeng.exe. Includes detection of hidden or anomalous scheduled tasks, especially those created under SYSTEM or suspicious user contexts."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1053.006",
   "technique_ja": "systemdタイマー",
   "technique_en": "Systemd Timers",
   "analytic_id": "AN0645",
   "detection_strategy_id": "DET0231",
   "analytic_name": "Analytic 0645",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Scheduled Job Creation (linux:osquery)",
   "log_sources_ja": "ファイル作成 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | スケジュールジョブ作成 (linux:osquery)",
   "tuning": "TimerIntervalThreshold | ParentProcessID | UserContext | TimerCreationPath",
   "detection_logic_en": "Detects adversarial abuse of systemd timers by correlating file creation/modification of .timer and .service units in system directories with the execution of abnormal child processes launched by 'systemd' (PID 1), especially as root."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1053.007",
   "technique_ja": "コンテナオーケストレーションジョブ",
   "technique_en": "Container Orchestration Job",
   "analytic_id": "AN0582",
   "detection_strategy_id": "DET0206",
   "analytic_name": "Analytic 0582",
   "platforms": "Containers",
   "log_sources": "Scheduled Job Creation (kubernetes:apiserver) | Container Creation (kubernetes:events) | Network Traffic Content (container:proxy)",
   "log_sources_ja": "スケジュールジョブ作成 (kubernetes:apiserver) | コンテナ作成 (kubernetes:events) | ネットワークトラフィック内容 (container:proxy)",
   "tuning": "NamespaceScope | ImageRepository | ScheduleWindow | ExecutionCommand",
   "detection_logic_en": "Detects abuse of container orchestration platforms (e.g., Kubernetes) where adversaries create CronJobs to maintain persistence or execute malicious Jobs across the cluster."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1055",
   "technique_ja": "プロセスインジェクション",
   "technique_en": "Process Injection",
   "analytic_id": "AN1399",
   "detection_strategy_id": "DET0508",
   "analytic_name": "Analytic 1399",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Kernel-Process)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Kernel-Process)",
   "tuning": "AccessMask | TimeWindow | InjectedProcessList",
   "detection_logic_en": "Detects process injection by correlating memory manipulation API calls (e.g., VirtualAllocEx, WriteProcessMemory), suspicious thread creation (e.g., CreateRemoteThread), and unusual DLL loads within another process's context."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1055",
   "technique_ja": "プロセスインジェクション",
   "technique_en": "Process Injection",
   "analytic_id": "AN1400",
   "detection_strategy_id": "DET0508",
   "analytic_name": "Analytic 1400",
   "platforms": "Linux",
   "log_sources": "OS API Execution (auditd:SYSCALL) | File Access (auditd:SYSCALL) | Process Modification (linux:procfs)",
   "log_sources_ja": "OS API実行 (auditd:SYSCALL) | ファイルアクセス (auditd:SYSCALL) | プロセス変更 (linux:procfs)",
   "tuning": "TargetPIDThreshold | TimeWindow",
   "detection_logic_en": "Detects ptrace- or memfd-based process injection through audit logs capturing system calls (e.g., ptrace, mmap) targeting running processes along with suspicious file descriptors or memory writes."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1055",
   "technique_ja": "プロセスインジェクション",
   "technique_en": "Process Injection",
   "analytic_id": "AN1401",
   "detection_strategy_id": "DET0508",
   "analytic_name": "Analytic 1401",
   "platforms": "macOS",
   "log_sources": "Process Access (macos:unifiedlog) | Process Metadata (macos:endpointsecurity) | Module Load (macos:syslog)",
   "log_sources_ja": "プロセスアクセス (macos:unifiedlog) | プロセスメタデータ (macos:endpointsecurity) | モジュール読み込み (macos:syslog)",
   "tuning": "TargetProcessSignature | MachSyscallContext",
   "detection_logic_en": "Detects memory-based injection by monitoring `task_for_pid`, `mach_vm_write`, and dylib injection patterns through `DYLD_INSERT_LIBRARIES` or manual memory mapping."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1055.001",
   "technique_ja": "DLLインジェクション",
   "technique_en": "Dynamic-link Library Injection",
   "analytic_id": "AN1095",
   "detection_strategy_id": "DET0389",
   "analytic_name": "Analytic 1095",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Named Pipe Metadata (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | 名前付きパイプメタデータ (WinEventLog:Sysmon)",
   "tuning": "InjectedDLLSignatureStatus | TimeWindow | TargetProcessList | ParentProcessAnomalyThreshold",
   "detection_logic_en": "Detects DLL injection through correlation of memory allocation and writing to remote process memory (e.g., VirtualAllocEx, WriteProcessMemory), followed by remote thread creation (e.g., CreateRemoteThread) that loads a suspicious or unsigned DLL using LoadLibrary or reflective loading."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1055.002",
   "technique_ja": "PEインジェクション",
   "technique_en": "Portable Executable Injection",
   "analytic_id": "AN0297",
   "detection_strategy_id": "DET0106",
   "analytic_name": "Analytic 0297",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Process Modification (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | プロセス変更 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "PayloadEntropyThreshold | TargetProcessList | TimeWindow | ParentProcessAnomalyThreshold",
   "detection_logic_en": "Detects PE injection through a behavioral sequence where one process opens (OpenProcess) a handle to another, allocates remote memory (VirtualAllocEx), writes a PE header (MZ) or shellcode (WriteProcessMemory), then initiates a new thread (CreateRemoteThread or NtCreateThreadEx) in that process—executing injected code in memory without touching disk. Optional: injects a trampoline or shellcode that unpacks/reflectively maps the payload."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1055.003",
   "technique_ja": "スレッド実行ハイジャック",
   "technique_en": "Thread Execution Hijacking",
   "analytic_id": "AN0822",
   "detection_strategy_id": "DET0295",
   "analytic_name": "Analytic 0822",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Process Modification (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Kernel-Process) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | プロセス変更 (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Kernel-Process) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TargetProcessList | TimeWindow | SuspiciousThreadContextRegions | ParentProcessAnomalyThreshold",
   "detection_logic_en": "Detects hijacking of an existing thread (OpenThread) through a behavioral chain involving thread suspension (SuspendThread), memory modification (VirtualAllocEx + WriteProcessMemory), context manipulation (SetThreadContext), and thread resumption—all within another live process's address space (ResumeThread)."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1055.004",
   "technique_ja": "非同期プロシージャコール(APC)",
   "technique_en": "Asynchronous Procedure Call",
   "analytic_id": "AN0277",
   "detection_strategy_id": "DET0100",
   "analytic_name": "Analytic 0277",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Process Modification (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Kernel-Process) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | プロセス変更 (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Kernel-Process) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "APCTargetProcessList | ThreadQueueDepthThreshold | TimeWindow | UserContextSensitivity",
   "detection_logic_en": "Detects malicious injection behavior involving memory allocation, remote thread queuing via APC (e.g., QueueUserAPC), and altered thread context within another live process to execute unauthorized code under legitimate context."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1055.005",
   "technique_ja": "スレッドローカルストレージ",
   "technique_en": "Thread Local Storage",
   "analytic_id": "AN1289",
   "detection_strategy_id": "DET0467",
   "analytic_name": "Analytic 1289",
   "platforms": "Windows",
   "log_sources": "Module Load (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Process Modification (WinEventLog:Sysmon) | OS API Execution (EDR:memory)",
   "log_sources_ja": "モジュール読み込み (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | プロセス変更 (WinEventLog:Sysmon) | OS API実行 (EDR:memory)",
   "tuning": "TargetProcessFilter | TimeWindowBetweenLoadAndTLSModification | AnomalousThreadStartThreshold | PayloadEntropyThreshold",
   "detection_logic_en": "Detects thread local storage (TLS) callback injection by monitoring memory modifications to PE headers and TLS directory structures during or after process hollowing events, followed by anomalous thread behavior prior to main entry point execution."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1055.008",
   "technique_ja": "ptraceシステムコール",
   "technique_en": "Ptrace System Calls",
   "analytic_id": "AN0579",
   "detection_strategy_id": "DET0203",
   "analytic_name": "Analytic 0579",
   "platforms": "Linux",
   "log_sources": "OS API Execution (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Process Metadata (linux:osquery)",
   "log_sources_ja": "OS API実行 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | プロセスメタデータ (linux:osquery)",
   "tuning": "TargetProcessNameFilter | TimeWindowBetweenPtraceAndMemoryWrite | UserContextMismatch | ProcessRelationshipConstraint",
   "detection_logic_en": "Detects ptrace-based process injection by correlating audit logs of ptrace syscalls, memory modifications (e.g., poketext, pokedata), and suspicious register manipulation on a target process not normally debugged by the originator. Alerts on processes attempting to ptrace non-child or privileged processes, especially those followed by abnormal memory or execution behavior."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1055.009",
   "technique_ja": "Procメモリ",
   "technique_en": "Proc Memory",
   "analytic_id": "AN1494",
   "detection_strategy_id": "DET0541",
   "analytic_name": "Analytic 1494",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | OS API Execution (auditd:SYSCALL) | File Access (linux:osquery)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | OS API実行 (auditd:SYSCALL) | ファイルアクセス (linux:osquery)",
   "tuning": "TargetProcNameRegex | TimeWindowBetweenMapAccessAndMemWrite | InvokerBinaryAllowlist | FileWriteThreshold",
   "detection_logic_en": "Detects adversary behavior where a process enumerates and modifies another process's memory using /proc/[pid]/maps and /proc/[pid]/mem files. This includes identifying gadgets via memory mappings and overwriting process memory via low-level file modification or dd usage."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1055.011",
   "technique_ja": "Extra Window Memoryインジェクション",
   "technique_en": "Extra Window Memory Injection",
   "analytic_id": "AN0608",
   "detection_strategy_id": "DET0217",
   "analytic_name": "Analytic 0608",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Win32k) | Process Creation (WinEventLog:Security)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Win32k) | プロセス生成 (WinEventLog:Security)",
   "tuning": "TargetWindowClassRegex | ExecutionTriggerWindowMessage | SharedSectionWriteThreshold | TimeWindowSetWindowLongToMessageTrigger",
   "detection_logic_en": "Detects adversary manipulation of Extra Window Memory (EWM) in a GUI process, where the attacker uses SetWindowLong or SetClassLong to redirect function pointers to injected shellcode stored in shared memory, then triggers execution via a window message like SendNotifyMessage."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1055.012",
   "technique_ja": "プロセスハロウィング",
   "technique_en": "Process Hollowing",
   "analytic_id": "AN1076",
   "detection_strategy_id": "DET0382",
   "analytic_name": "Analytic 1076",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Process Modification (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Kernel-Process)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | プロセス変更 (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Kernel-Process)",
   "tuning": "HollowedImageNamePattern | TimeWindow_ProcessCreateToResume | SuspendedProcessStartFlag | MemoryWriteSizeThreshold",
   "detection_logic_en": "Detects adversary use of suspended process creation, using the CREATE_SUSPENDED flag via CreateProcess, followed by unmapping the memory of the child process (NtUnmapViewOfSection) and replacing it with malicious code via VirtualAllocEx/WriteProcessMemory, then SetThreadContext and ResumeThread to begin execution within the hollowed process."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1055.013",
   "technique_ja": "プロセスドッペルゲンギング",
   "technique_en": "Process Doppelgänging",
   "analytic_id": "AN1501",
   "detection_strategy_id": "DET0544",
   "analytic_name": "Analytic 1501",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Kernel-Process)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Kernel-Process)",
   "tuning": "TransactionExecutableNamePattern | TimeWindow_TransactionToExecution | ThreadStartEntropyThreshold | TxF API Call Frequency Threshold",
   "detection_logic_en": "Detects adversary abuse of Transactional NTFS (TxF) and undocumented process loading mechanisms (e.g., NtCreateProcessEx) to create a hollowed process from an uncommitted, maliciously tainted file image in memory, later executed via NtCreateThreadEx."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1055.014",
   "technique_ja": "VDSOハイジャック",
   "technique_en": "VDSO Hijacking",
   "analytic_id": "AN1241",
   "detection_strategy_id": "DET0448",
   "analytic_name": "Analytic 1241",
   "platforms": "Linux",
   "log_sources": "OS API Execution (auditd:SYSCALL) | Process Modification (auditd:memprotect) | Module Load (auditd:file-events) | Process Creation (linux:osquery)",
   "log_sources_ja": "OS API実行 (auditd:SYSCALL) | プロセス変更 (auditd:memprotect) | モジュール読み込み (auditd:file-events) | プロセス生成 (linux:osquery)",
   "tuning": "SuspiciousSharedObjectPathRegex | TimeWindow_PtraceToMmap | ExecMemoryProtectionThreshold | AnomalousParentProcessList",
   "detection_logic_en": "Detects the redirection of syscall execution flow via modification of VDSO code stubs or GOT entries to load and execute a malicious shared object through mmap and ptrace."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1055.015",
   "technique_ja": "ListPlanting",
   "technique_en": "ListPlanting",
   "analytic_id": "AN0941",
   "detection_strategy_id": "DET0331",
   "analytic_name": "Analytic 0941",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Process Modification (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Win32k)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | プロセス変更 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Win32k)",
   "tuning": "TimeWindow_PostMessage_to_LVM_SORTITEMS | TargetWindowClassName | UserContextAnomalyThreshold | InterprocessWindowMessagingFrequency",
   "detection_logic_en": "Detects the use of message-based injection by monitoring for sequences involving FindWindow (EnumWindows or EnumChildWindows), VirtualAllocEx or related API calls, combined with suspicious PostMessage/SendMessage (e.g., LVM_SETITEMPOSITION) use to SysListView32 controls, followed by LVM_SORTITEMS invocation instead of WriteProcessMemory."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1068",
   "technique_ja": "権限昇格のための脆弱性悪用",
   "technique_en": "Exploitation for Privilege Escalation",
   "analytic_id": "AN1419",
   "detection_strategy_id": "DET0514",
   "analytic_name": "Analytic 1419",
   "platforms": "Windows",
   "log_sources": "Driver Load (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Logon Session Metadata (WinEventLog:Security)",
   "log_sources_ja": "ドライバ読み込み (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ログオンセッションメタデータ (WinEventLog:Security)",
   "tuning": "DriverNamePattern | TimeWindow | ParentProcessPath",
   "detection_logic_en": "Detects exploitation attempts targeting vulnerable kernel drivers or OS components, often followed by unusual process or token behavior."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1068",
   "technique_ja": "権限昇格のための脆弱性悪用",
   "technique_en": "Exploitation for Privilege Escalation",
   "analytic_id": "AN1420",
   "detection_strategy_id": "DET0514",
   "analytic_name": "Analytic 1420",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Process Access (auditd:SYSCALL) | Module Load (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | プロセスアクセス (auditd:SYSCALL) | モジュール読み込み (auditd:SYSCALL)",
   "tuning": "SetUIDBinaryList | TimeWindow | EffectiveUIDThreshold",
   "detection_logic_en": "Detects escalation via vulnerable setuid binaries or kernel modules, often chained with unusual access to /proc/kallsyms or /dev/kmem."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1068",
   "technique_ja": "権限昇格のための脆弱性悪用",
   "technique_en": "Exploitation for Privilege Escalation",
   "analytic_id": "AN1421",
   "detection_strategy_id": "DET0514",
   "analytic_name": "Analytic 1421",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Module Load (macos:endpointsecurity)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | モジュール読み込み (macos:endpointsecurity)",
   "tuning": "EntitlementList | TimeWindow",
   "detection_logic_en": "Detects use of vulnerable kernel extensions or entitlements abused via setuid or AppleScript injection chains."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1068",
   "technique_ja": "権限昇格のための脆弱性悪用",
   "technique_en": "Exploitation for Privilege Escalation",
   "analytic_id": "AN1422",
   "detection_strategy_id": "DET0514",
   "analytic_name": "Analytic 1422",
   "platforms": "Containers",
   "log_sources": "Logon Session Creation (auditd:SYSCALL) | Container Enumeration (containerd:runtime)",
   "log_sources_ja": "ログオンセッション作成 (auditd:SYSCALL) | コンテナ列挙 (containerd:runtime)",
   "tuning": "NamespaceEscapePattern | TimeWindow",
   "detection_logic_en": "Detects container breakout behavior via exploitation (e.g., DirtyPipe, CVE-2022-0847), followed by host OS interaction or escalated capability assignment."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1543",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1543",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | User Account Authentication (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | ユーザーアカウント認証 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "LogonType | TimeWindow | GeoIPMismatch",
   "detection_logic_en": "Detection of compromised or misused valid accounts via anomalous logon patterns, abnormal logon types, and inconsistent geographic or time-based activity across Windows endpoints."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1544",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1544",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | User Account Authentication (NSM:Connections)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ユーザーアカウント認証 (NSM:Connections)",
   "tuning": "UserContext | HostDensityThreshold | LoginMethod",
   "detection_logic_en": "Detection of valid account misuse through SSH logins, sudo/su abuse, and service account anomalies outside expected patterns."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1545",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1545",
   "platforms": "macOS",
   "log_sources": "Logon Session Metadata (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ログオンセッションメタデータ (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "LoginOrigin | ProcessTreeDepth",
   "detection_logic_en": "Detection of interactive and remote logins by service accounts or users at unusual times, with unexpected child process activity."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1546",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1546",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (saas:okta)",
   "log_sources_ja": "ユーザーアカウント認証 (saas:okta)",
   "tuning": "MFAFailureCount | RiskScoreThreshold | IPGeoVelocity",
   "detection_logic_en": "Detection of valid account abuse in IdP logs via geographic anomalies, impossible travel, risky sign-ins, and multiple MFA attempts or failures."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1547",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1547",
   "platforms": "Containers",
   "log_sources": "User Account Authentication (kubernetes:audit)",
   "log_sources_ja": "ユーザーアカウント認証 (kubernetes:audit)",
   "tuning": "ServiceAccountScope | ClusterIPWhitelist",
   "detection_logic_en": "Detection of containerized service accounts or compromised kubeconfigs being used for cluster access from unexpected nodes or IPs."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1283",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1283",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security)",
   "tuning": "UserContext | TimeWindow",
   "detection_logic_en": "Detection of default account usage such as Guest or Administrator performing interactive or remote logons on systems outside of installation or maintenance windows."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1284",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1284",
   "platforms": "Linux",
   "log_sources": "Logon Session Metadata (auditd:USER_LOGIN)",
   "log_sources_ja": "ログオンセッションメタデータ (auditd:USER_LOGIN)",
   "tuning": "SSHMethod | RemoteIPWhitelist",
   "detection_logic_en": "Monitoring for SSH logins from default accounts such as 'root', especially when login is via password and not key-based authentication."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1285",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1285",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (AWS:CloudTrail)",
   "log_sources_ja": "ユーザーアカウント認証 (AWS:CloudTrail)",
   "tuning": "AccountList | GeoLocation",
   "detection_logic_en": "Use of known default service accounts or root-level cloud accounts performing authentication or changes to IAM policy."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1286",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1286",
   "platforms": "ESXi",
   "log_sources": "User Account Authentication (esxi:auth)",
   "log_sources_ja": "ユーザーアカウント認証 (esxi:auth)",
   "tuning": "AccountName | IPRange",
   "detection_logic_en": "Abuse of system-generated or default privileged accounts such as 'root' or 'vpxuser' logging into ESXi hosts."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1287",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1287",
   "platforms": "Network Devices",
   "log_sources": "User Account Authentication (networkdevice:syslog)",
   "log_sources_ja": "ユーザーアカウント認証 (networkdevice:syslog)",
   "tuning": "Username | InterfaceType",
   "detection_logic_en": "Login activity from default admin credentials (e.g., 'admin', 'cisco') on routers, firewalls, and switches."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Accounts",
   "analytic_id": "AN0590",
   "detection_strategy_id": "DET0210",
   "analytic_name": "Analytic 0590",
   "platforms": "Windows",
   "log_sources": "Logon Session Metadata (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッションメタデータ (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext | LogonType",
   "detection_logic_en": "Detection of suspicious logon behavior using valid domain accounts across multiple hosts, off-hours, or simultaneous sessions from geographically distant locations."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Accounts",
   "analytic_id": "AN0591",
   "detection_strategy_id": "DET0210",
   "analytic_name": "Analytic 0591",
   "platforms": "Linux",
   "log_sources": "User Account Authentication (auditd:SYSCALL) | Logon Session Metadata (linux:syslog)",
   "log_sources_ja": "ユーザーアカウント認証 (auditd:SYSCALL) | ログオンセッションメタデータ (linux:syslog)",
   "tuning": "HostnameScope | AccountDomain",
   "detection_logic_en": "Use of domain accounts via sssd or winbind for logon activity outside of typical patterns, especially on sensitive systems or with lateral movement tools."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Accounts",
   "analytic_id": "AN0592",
   "detection_strategy_id": "DET0210",
   "analytic_name": "Analytic 0592",
   "platforms": "macOS",
   "log_sources": "User Account Authentication (macos:unifiedlog)",
   "log_sources_ja": "ユーザーアカウント認証 (macos:unifiedlog)",
   "tuning": "UserLocation | LogonMethod",
   "detection_logic_en": "Domain logins using network accounts or mobile accounts via Open Directory or Active Directory plugins, especially outside business hours or on atypical endpoints."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Accounts",
   "analytic_id": "AN0593",
   "detection_strategy_id": "DET0210",
   "analytic_name": "Analytic 0593",
   "platforms": "ESXi",
   "log_sources": "User Account Authentication (esxi:vpxd) | Logon Session Metadata (esxi:hostd)",
   "log_sources_ja": "ユーザーアカウント認証 (esxi:vpxd) | ログオンセッションメタデータ (esxi:hostd)",
   "tuning": "AccountType | LoginInterface",
   "detection_logic_en": "Login to vSphere or ESXi hosts using domain accounts, especially those associated with vpxuser or unexpected group memberships."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078.003",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Accounts",
   "analytic_id": "AN1137",
   "detection_strategy_id": "DET0407",
   "analytic_name": "Analytic 1137",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Logon Session Metadata (WinEventLog:Security)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | ログオンセッションメタデータ (WinEventLog:Security)",
   "tuning": "TimeWindow | UserContext",
   "detection_logic_en": "Detects anomalous usage of local accounts to log into a system, especially accounts not typically used interactively or outside business hours."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078.003",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Accounts",
   "analytic_id": "AN1138",
   "detection_strategy_id": "DET0407",
   "analytic_name": "Analytic 1138",
   "platforms": "Linux",
   "log_sources": "Logon Session Metadata (auditd:USER_LOGIN) | User Account Authentication (linux:auth)",
   "log_sources_ja": "ログオンセッションメタデータ (auditd:USER_LOGIN) | ユーザーアカウント認証 (linux:auth)",
   "tuning": "TimeWindow | HostRole",
   "detection_logic_en": "Detects interactive or service logins from local accounts outside expected operational context or at anomalous times."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078.003",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Accounts",
   "analytic_id": "AN1139",
   "detection_strategy_id": "DET0407",
   "analytic_name": "Analytic 1139",
   "platforms": "macOS",
   "log_sources": "Logon Session Metadata (macos:unifiedlog)",
   "log_sources_ja": "ログオンセッションメタデータ (macos:unifiedlog)",
   "tuning": "UserContext | TimeWindow",
   "detection_logic_en": "Detects abnormal or rare logins via local accounts through system or remote mechanisms such as SSH."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Accounts",
   "analytic_id": "AN1503",
   "detection_strategy_id": "DET0546",
   "analytic_name": "Analytic 1503",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (azure:signinlogs) | Logon Session Metadata (saas:okta)",
   "log_sources_ja": "ユーザーアカウント認証 (azure:signinlogs) | ログオンセッションメタデータ (saas:okta)",
   "tuning": "AnomalousLocationThreshold | ProtocolType",
   "detection_logic_en": "Detects anomalous authentication activity such as sign-ins from impossible geolocations or legacy protocols from high-privileged accounts."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Accounts",
   "analytic_id": "AN1504",
   "detection_strategy_id": "DET0546",
   "analytic_name": "Analytic 1504",
   "platforms": "IaaS",
   "log_sources": "User Account Authentication (AWS:CloudTrail) | Logon Session Creation (gcp:audit)",
   "log_sources_ja": "ユーザーアカウント認証 (AWS:CloudTrail) | ログオンセッション作成 (gcp:audit)",
   "tuning": "ServiceInteractionBaseline | RoleSwitchRateThreshold",
   "detection_logic_en": "Detects cloud account use for API calls that exceed normal scope, such as IAM changes or access to services never used before."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Accounts",
   "analytic_id": "AN1505",
   "detection_strategy_id": "DET0546",
   "analytic_name": "Analytic 1505",
   "platforms": "SaaS",
   "log_sources": "Logon Session Metadata (m365:unified) | User Account Authentication (gcp:audit)",
   "log_sources_ja": "ログオンセッションメタデータ (m365:unified) | ユーザーアカウント認証 (gcp:audit)",
   "tuning": "FileDownloadThreshold | SharingPolicyViolationThreshold",
   "detection_logic_en": "Detects unexpected access or usage of cloud productivity tools (e.g., downloading large numbers of files, creating external shares) by internal users."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1078.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Accounts",
   "analytic_id": "AN1506",
   "detection_strategy_id": "DET0546",
   "analytic_name": "Analytic 1506",
   "platforms": "Office Suite",
   "log_sources": "Logon Session Metadata (m365:signinlogs) | User Account Authentication (gcp:audit)",
   "log_sources_ja": "ログオンセッションメタデータ (m365:signinlogs) | ユーザーアカウント認証 (gcp:audit)",
   "tuning": "BusinessHours | OfficeProductivityToolBaseline",
   "detection_logic_en": "Detects login and usage patterns deviating from typical Microsoft 365 or Google Workspace user profiles."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098",
   "technique_ja": "アカウント操作",
   "technique_en": "Account Manipulation",
   "analytic_id": "AN0265",
   "detection_strategy_id": "DET0096",
   "analytic_name": "Analytic 0265",
   "platforms": "Windows",
   "log_sources": "User Account Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ユーザーアカウント変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | HighPrivilegeGroupList | SubjectTargetMismatch",
   "detection_logic_en": "Account attribute changes (e.g., password set, group membership, servicePrincipalName, logon hours) correlated with unusual process lineage or timing, indicating privilege escalation or persistence via valid accounts."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098",
   "technique_ja": "アカウント操作",
   "technique_en": "Account Manipulation",
   "analytic_id": "AN0266",
   "detection_strategy_id": "DET0096",
   "analytic_name": "Analytic 0266",
   "platforms": "Linux",
   "log_sources": "User Account Modification (auditd:SYSCALL) | File Modification (auditd:PATH)",
   "log_sources_ja": "ユーザーアカウント変更 (auditd:SYSCALL) | ファイル変更 (auditd:PATH)",
   "tuning": "SudoPath | ModifiedShellList",
   "detection_logic_en": "Use of native tools or scripting (e.g., `usermod`, `passwd`, `groupmod`) to escalate permissions or persist access on existing users, correlated with login or process events."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098",
   "technique_ja": "アカウント操作",
   "technique_en": "Account Manipulation",
   "analytic_id": "AN0267",
   "detection_strategy_id": "DET0096",
   "analytic_name": "Analytic 0267",
   "platforms": "macOS",
   "log_sources": "User Account Modification (macos:unifiedlog)",
   "log_sources_ja": "ユーザーアカウント変更 (macos:unifiedlog)",
   "tuning": "ModifiedUserList | GroupMembershipChanges",
   "detection_logic_en": "Modifications to user accounts via `dscl`, `pwpolicy`, or System Preferences CLI (`sysadminctl`) that alter user groups, enable root, or bypass MDM restrictions."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098",
   "technique_ja": "アカウント操作",
   "technique_en": "Account Manipulation",
   "analytic_id": "AN0268",
   "detection_strategy_id": "DET0096",
   "analytic_name": "Analytic 0268",
   "platforms": "Identity Provider",
   "log_sources": "User Account Modification (saas:okta)",
   "log_sources_ja": "ユーザーアカウント変更 (saas:okta)",
   "tuning": "RoleAssignmentBaseline | APIUsageContext",
   "detection_logic_en": "Modifications to SSO/SAML user attributes (e.g., `isAdmin`, `role`, MFA bypass, App assignments) often through CLI, API, or rogue IdP apps."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098",
   "technique_ja": "アカウント操作",
   "technique_en": "Account Manipulation",
   "analytic_id": "AN0269",
   "detection_strategy_id": "DET0096",
   "analytic_name": "Analytic 0269",
   "platforms": "ESXi",
   "log_sources": "Active Directory Object Modification (esxi:vpxa)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (esxi:vpxa)",
   "tuning": "VMAdminAccountName | NetworkAccessLocation",
   "detection_logic_en": "Addition of new users or changes to role permissions (e.g., ReadOnly -> Admin) via API or vSphere Client, particularly from non-jumpbox IPs."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098",
   "technique_ja": "アカウント操作",
   "technique_en": "Account Manipulation",
   "analytic_id": "AN0270",
   "detection_strategy_id": "DET0096",
   "analytic_name": "Analytic 0270",
   "platforms": "SaaS",
   "log_sources": "User Account Modification (m365:unified)",
   "log_sources_ja": "ユーザーアカウント変更 (m365:unified)",
   "tuning": "SharingSensitivityLabel | CrossOrgChanges",
   "detection_logic_en": "Role escalation (e.g., Editor → Owner) in cloud collaboration tools (Google Workspace, O365) or file sharing apps to maintain elevated access."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.001",
   "technique_ja": "追加のクラウド認証情報",
   "technique_en": "Additional Cloud Credentials",
   "analytic_id": "AN1469",
   "detection_strategy_id": "DET0531",
   "analytic_name": "Analytic 1469",
   "platforms": "Identity Provider",
   "log_sources": "User Account Modification (azure:audit)",
   "log_sources_ja": "ユーザーアカウント変更 (azure:audit)",
   "tuning": "MFABypassMechanism | SourceIPAllowlist | ApplicationCredentialType",
   "detection_logic_en": "Addition of credentials (keys, app passwords, x.509 certs) to existing cloud accounts, service principals, or OAuth apps via portal or API by non-standard identities or IP ranges."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.001",
   "technique_ja": "追加のクラウド認証情報",
   "technique_en": "Additional Cloud Credentials",
   "analytic_id": "AN1470",
   "detection_strategy_id": "DET0531",
   "analytic_name": "Analytic 1470",
   "platforms": "IaaS",
   "log_sources": "Active Directory Object Creation (AWS:CloudTrail) | User Account Modification (gcp:audit)",
   "log_sources_ja": "Active Directoryオブジェクト作成 (AWS:CloudTrail) | ユーザーアカウント変更 (gcp:audit)",
   "tuning": "CallerIdentityContext | NewCredentialUsageWindow | IAMRoleBaseline",
   "detection_logic_en": "Cloud API usage to create/import SSH keys or generate new access keys (CreateAccessKey, ImportKeyPair, CreateLoginProfile) from non-console access or unusual principals."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.001",
   "technique_ja": "追加のクラウド認証情報",
   "technique_en": "Additional Cloud Credentials",
   "analytic_id": "AN1471",
   "detection_strategy_id": "DET0531",
   "analytic_name": "Analytic 1471",
   "platforms": "SaaS",
   "log_sources": "User Account Modification (gcp:audit) | Active Directory Object Modification (m365:unified)",
   "log_sources_ja": "ユーザーアカウント変更 (gcp:audit) | Active Directoryオブジェクト変更 (m365:unified)",
   "tuning": "OAuthClientRedirectURIBaseline | TokenScopeSensitivity",
   "detection_logic_en": "Credential-related configuration changes in productivity apps, such as API key creation in Google Workspace, app tokens in Slack, or user-level OAuth credentials in M365."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.002",
   "technique_ja": "追加のメール委任権限",
   "technique_en": "Additional Email Delegate Permissions",
   "analytic_id": "AN1051",
   "detection_strategy_id": "DET0373",
   "analytic_name": "Analytic 1051",
   "platforms": "Office Suite",
   "log_sources": "User Account Modification (m365:unified)",
   "log_sources_ja": "ユーザーアカウント変更 (m365:unified)",
   "tuning": "DelegatePermissionLevel | FolderTargetScope | DelegatorToDelegatePairing | MailflowAnomalyThreshold",
   "detection_logic_en": "Detection of anomalous or unauthorized mailbox delegation activity (e.g., Add-MailboxPermission, Default/Anonymous mailbox permissions, Gmail delegation setup)."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.002",
   "technique_ja": "追加のメール委任権限",
   "technique_en": "Additional Email Delegate Permissions",
   "analytic_id": "AN1052",
   "detection_strategy_id": "DET0373",
   "analytic_name": "Analytic 1052",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Application Log Content (m365:unified)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | アプリケーションログ内容 (m365:unified)",
   "tuning": "PowerShellCmdletFilter | ExecutionParent | TimeWindow",
   "detection_logic_en": "Execution of PowerShell commands that modify mailbox permissions using Exchange cmdlets (e.g., Add-MailboxPermission), often tied to BEC or post-compromise persistence."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.003",
   "technique_ja": "追加のクラウドロール",
   "technique_en": "Additional Cloud Roles",
   "analytic_id": "AN0771",
   "detection_strategy_id": "DET0277",
   "analytic_name": "Analytic 0771",
   "platforms": "IaaS",
   "log_sources": "User Account Modification (AWS:CloudTrail)",
   "log_sources_ja": "ユーザーアカウント変更 (AWS:CloudTrail)",
   "tuning": "RoleScope | UserContext | PolicyChangeTimeWindow | ExternalRoleOrigin",
   "detection_logic_en": "Detection of new IAM roles or policies attached to a user/service in AWS/GCP/Azure outside normal patterns or hours, often following account compromise."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.003",
   "technique_ja": "追加のクラウドロール",
   "technique_en": "Additional Cloud Roles",
   "analytic_id": "AN0772",
   "detection_strategy_id": "DET0277",
   "analytic_name": "Analytic 0772",
   "platforms": "Identity Provider",
   "log_sources": "User Account Modification (m365:audit)",
   "log_sources_ja": "ユーザーアカウント変更 (m365:audit)",
   "tuning": "AdminRoleThreshold | RoleAssignmentMethod | GrantContext",
   "detection_logic_en": "Behavioral chain of a user being granted elevated privileges or roles in Entra ID or Okta following suspicious login or account creation activity."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.003",
   "technique_ja": "追加のクラウドロール",
   "technique_en": "Additional Cloud Roles",
   "analytic_id": "AN0773",
   "detection_strategy_id": "DET0277",
   "analytic_name": "Analytic 0773",
   "platforms": "Office Suite",
   "log_sources": "User Account Modification (m365:unified)",
   "log_sources_ja": "ユーザーアカウント変更 (m365:unified)",
   "tuning": "OfficeRoleType | TimeWindow | ActionOrigin",
   "detection_logic_en": "Detection of new admin or role assignment actions within Microsoft 365/O365 environments to elevate access for persistence or lateral movement."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.004",
   "technique_ja": "SSH認証鍵",
   "technique_en": "SSH Authorized Keys",
   "analytic_id": "AN0350",
   "detection_strategy_id": "DET0126",
   "analytic_name": "Analytic 0350",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "TimeWindow | UserContext | TargetPath",
   "detection_logic_en": "Adversary attempts to gain persistence by modifying ~/.ssh/authorized_keys via shell, text editor, echo or redirected output."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.004",
   "technique_ja": "SSH認証鍵",
   "technique_en": "SSH Authorized Keys",
   "analytic_id": "AN0351",
   "detection_strategy_id": "DET0126",
   "analytic_name": "Analytic 0351",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:auth)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:auth)",
   "tuning": "ParentProcess | InteractiveSessionFlag",
   "detection_logic_en": "Insertion of public keys into authorized_keys using bash/zsh or editor tools, correlated with suspicious process ancestry."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.004",
   "technique_ja": "SSH認証鍵",
   "technique_en": "SSH Authorized Keys",
   "analytic_id": "AN0352",
   "detection_strategy_id": "DET0126",
   "analytic_name": "Analytic 0352",
   "platforms": "IaaS",
   "log_sources": "File Modification (gcp:audit)",
   "log_sources_ja": "ファイル変更 (gcp:audit)",
   "tuning": "MetadataFieldName | AccountType | TargetRoleEscalation",
   "detection_logic_en": "Abuse of cloud metadata APIs or CLI to push SSH public keys to authorized_keys of virtual machines."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.004",
   "technique_ja": "SSH認証鍵",
   "technique_en": "SSH Authorized Keys",
   "analytic_id": "AN0353",
   "detection_strategy_id": "DET0126",
   "analytic_name": "Analytic 0353",
   "platforms": "ESXi",
   "log_sources": "File Modification (esxi:shell)",
   "log_sources_ja": "ファイル変更 (esxi:shell)",
   "tuning": "SSHConfigPath | ESXiShellActivity",
   "detection_logic_en": "Direct modification of /etc/ssh/keys-<user>/authorized_keys or enabling SSH in sshd_config to support public key auth."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.004",
   "technique_ja": "SSH認証鍵",
   "technique_en": "SSH Authorized Keys",
   "analytic_id": "AN0354",
   "detection_strategy_id": "DET0126",
   "analytic_name": "Analytic 0354",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:cli)",
   "log_sources_ja": "コマンド実行 (networkdevice:cli)",
   "tuning": "CLIUserRole | DeviceModel",
   "detection_logic_en": "Use of command-line like `ip ssh pubkey-chain` to bind SSH keys to privileged accounts on routers or switches."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.005",
   "technique_ja": "デバイス登録",
   "technique_en": "Device Registration",
   "analytic_id": "AN0103",
   "detection_strategy_id": "DET0036",
   "analytic_name": "Analytic 0103",
   "platforms": "Identity Provider",
   "log_sources": "User Account Modification (azure:audit) | Application Log Content (ApplicationLog:EntraIDPortal) | Active Directory Object Creation (azure:audit)",
   "log_sources_ja": "ユーザーアカウント変更 (azure:audit) | アプリケーションログ内容 (ApplicationLog:EntraIDPortal) | Active Directoryオブジェクト作成 (azure:audit)",
   "tuning": "ActorUserPrincipalName | IP Address | TimeWindow",
   "detection_logic_en": "Adversary registers new devices to compromised user accounts to bypass MFA or conditional access policies via Azure Entra ID, Okta, or Duo self-enrollment portals."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.005",
   "technique_ja": "デバイス登録",
   "technique_en": "Device Registration",
   "analytic_id": "AN0104",
   "detection_strategy_id": "DET0036",
   "analytic_name": "Analytic 0104",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Creation (WinEventLog:Security) | Application Log Content (ApplicationLog:Intune/MDM Logs)",
   "log_sources_ja": "Active Directoryオブジェクト作成 (WinEventLog:Security) | アプリケーションログ内容 (ApplicationLog:Intune/MDM Logs)",
   "tuning": "DeviceNamePattern | UserContext | EnrollmentMethod",
   "detection_logic_en": "Adversary registers a Windows device to Entra ID or bypasses conditional access by adding device via Intune registration pipeline using stolen credentials."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.006",
   "technique_ja": "追加のコンテナクラスタロール",
   "technique_en": "Additional Container Cluster Roles",
   "analytic_id": "AN1579",
   "detection_strategy_id": "DET0572",
   "analytic_name": "Analytic 1579",
   "platforms": "Containers",
   "log_sources": "User Account Modification (kubernetes:audit)",
   "log_sources_ja": "ユーザーアカウント変更 (kubernetes:audit)",
   "tuning": "UserAgent | RoleName | TimeWindow | UserContext",
   "detection_logic_en": "Detects assignment of high-privilege roles to user or service accounts via Kubernetes RoleBinding or ClusterRoleBinding objects, especially outside of CI/CD automation or from unknown IPs."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.007",
   "technique_ja": "追加のローカル/ドメイングループ",
   "technique_en": "Additional Local or Domain Groups",
   "analytic_id": "AN0865",
   "detection_strategy_id": "DET0310",
   "analytic_name": "Analytic 0865",
   "platforms": "Windows",
   "log_sources": "User Account Modification (WinEventLog:Security)",
   "log_sources_ja": "ユーザーアカウント変更 (WinEventLog:Security)",
   "tuning": "TargetGroup | TimeWindow | UserContext",
   "detection_logic_en": "Detects unauthorized additions of users or machine accounts to privileged local or domain groups (e.g., Administrators, Remote Desktop Users)."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.007",
   "technique_ja": "追加のローカル/ドメイングループ",
   "technique_en": "Additional Local or Domain Groups",
   "analytic_id": "AN0866",
   "detection_strategy_id": "DET0310",
   "analytic_name": "Analytic 0866",
   "platforms": "Linux",
   "log_sources": "User Account Modification (auditd:SYSCALL)",
   "log_sources_ja": "ユーザーアカウント変更 (auditd:SYSCALL)",
   "tuning": "GroupName | UserContext | TimeWindow",
   "detection_logic_en": "Detects unexpected use of usermod, gpasswd, or direct modification of /etc/group to elevate user group membership."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1098.007",
   "technique_ja": "追加のローカル/ドメイングループ",
   "technique_en": "Additional Local or Domain Groups",
   "analytic_id": "AN0867",
   "detection_strategy_id": "DET0310",
   "analytic_name": "Analytic 0867",
   "platforms": "macOS",
   "log_sources": "User Account Modification (macos:unifiedlog)",
   "log_sources_ja": "ユーザーアカウント変更 (macos:unifiedlog)",
   "tuning": "GroupName | UserContext | TimeWindow",
   "detection_logic_en": "Detects use of `dseditgroup` or `dscl` to add users to privileged macOS groups (e.g., admin)."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1134",
   "technique_ja": "アクセストークン操作",
   "technique_en": "Access Token Manipulation",
   "analytic_id": "AN0786",
   "detection_strategy_id": "DET0283",
   "analytic_name": "Analytic 0786",
   "platforms": "Windows",
   "log_sources": "Logon Session Metadata (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | OS API Execution (ETW:Token) | Active Directory Object Modification (WinEventLog:Security)",
   "log_sources_ja": "ログオンセッションメタデータ (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | OS API実行 (ETW:Token) | Active Directoryオブジェクト変更 (WinEventLog:Security)",
   "tuning": "TimeWindow | AllowedServiceAccounts | KnownAdminTools | ParentProcessAnomalyThreshold",
   "detection_logic_en": "Detection of suspicious token manipulation chains: use of token-related APIs (e.g., LogonUser, DuplicateTokenEx) or commands (runas) → spawning of a new process under a different security context (e.g., SYSTEM) → mismatched parent-child process lineage or anomalies in Event Tracing for Windows (ETW) token/PPID data → abnormal lateral or privilege escalation activity."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1134.001",
   "technique_ja": "トークンの偽装/窃取",
   "technique_en": "Token Impersonation/Theft",
   "analytic_id": "AN1324",
   "detection_strategy_id": "DET0482",
   "analytic_name": "Analytic 1324",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Process Access (WinEventLog:Sysmon) | OS API Execution (ETW:Token)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon) | OS API実行 (ETW:Token)",
   "tuning": "AllowedSystemProcesses | TimeWindow | UserContextFilter | ParentProcessAnomalyThreshold",
   "detection_logic_en": "Detection of token duplication and impersonation attempts by correlating suspicious command-line executions (e.g., runas) with API calls to DuplicateToken, DuplicateTokenEx, ImpersonateLoggedOnUser, or SetThreadToken. The chain includes the initial command execution or in-memory API invocation → token handle duplication or thread token assignment → a new or existing process assuming the impersonated user's context."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1134.002",
   "technique_ja": "トークンを用いたプロセス作成",
   "technique_en": "Create Process with Token",
   "analytic_id": "AN1253",
   "detection_strategy_id": "DET0456",
   "analytic_name": "Analytic 1253",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Process Access (WinEventLog:Sysmon) | OS API Execution (ETW:ProcThread) | Logon Session Metadata (WinEventLog:Security) | Active Directory Object Modification (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon) | OS API実行 (ETW:ProcThread) | ログオンセッションメタデータ (WinEventLog:Security) | Active Directoryオブジェクト変更 (WinEventLog:Security)",
   "tuning": "TimeWindow | AllowedImpersonators | IntegrityEscalationDelta | ParentChildUserMismatch | SensitiveTargets",
   "detection_logic_en": "A process (often after stealing/creating a token) calls CreateProcessWithTokenW/CreateProcessAsUserW or uses runas to spawn a **new** process whose security context (SID/LogonId/IntegrityLevel) differs from its parent. Chain: (1) suspicious command/API → (2) privileged handle or token duplication/open → (3) new child process running as another user / higher integrity → (4) optional follow‑on privileged/lateral actions."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1134.003",
   "technique_ja": "トークンの作成と偽装",
   "technique_en": "Make and Impersonate Token",
   "analytic_id": "AN1375",
   "detection_strategy_id": "DET0498",
   "analytic_name": "Analytic 1375",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Logon Session Metadata (WinEventLog:Security) | OS API Execution (etw:Microsoft-Windows-Security-Auditing)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ログオンセッションメタデータ (WinEventLog:Security) | OS API実行 (etw:Microsoft-Windows-Security-Auditing)",
   "tuning": "TimeWindow | SuspiciousLogonTypes | AllowedImpersonators | ParentChildUserMismatch | IntegrityEscalationDelta",
   "detection_logic_en": "A process creates a brand‑new logon session/token (LogonUser*/LsaLogonUser) and then assigns/impersonates it (SetThreadToken/ImpersonateLoggedOnUser) to run actions under that freshly created security context. Chain: (1) suspicious command or script block (e.g., runas /netonly, PowerShell P/Invoke of LogonUser) → (2) ETW/API evidence of LogonUser*/SetThreadToken → (3) Security 4624 New Logon (often LogonType=9 NewCredentials or 2/3 from a non‑interactive parent) with no interactive desktop → (4) sysmon 1 process(es) executing with the new LogonId/SID different from the parent process → (5) optional privileged ops/lateral movement."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1134.004",
   "technique_ja": "親PIDスプーフィング",
   "technique_en": "Parent PID Spoofing",
   "analytic_id": "AN1351",
   "detection_strategy_id": "DET0489",
   "analytic_name": "Analytic 1351",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | OS API Execution (etw:Microsoft-Windows-Kernel-Process) | Process Metadata (etw:Microsoft-Windows-Kernel-Process)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | OS API実行 (etw:Microsoft-Windows-Kernel-Process) | プロセスメタデータ (etw:Microsoft-Windows-Kernel-Process)",
   "tuning": "TimeWindow | AllowedSpoofers | ParentPrivilegeDeltaThreshold | LineageMismatchTolerance | SensitiveParents",
   "detection_logic_en": "A process explicitly forges its parent using EXTENDED_STARTUPINFO + PROC_THREAD_ATTRIBUTE_PARENT_PROCESS (UpdateProcThreadAttribute → CreateProcess[A/W]/CreateProcessAsUserW) or other Native API paths, resulting in **mismatched/implausible lineage** across ETW EventHeader ProcessId, Security 4688 Creator Process ID/Name, and sysmon ParentProcessGuid. Often paired with privilege escalation when the chosen parent runs as SYSTEM."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1134.005",
   "technique_ja": "SID履歴インジェクション",
   "technique_en": "SID-History Injection",
   "analytic_id": "AN0383",
   "detection_strategy_id": "DET0136",
   "analytic_name": "Analytic 0383",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Modification (WinEventLog:Security) | User Account Metadata (WinEventLog:Security) | OS API Execution (etw:Microsoft-Windows-Directory-Services-SAM)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (WinEventLog:Security) | ユーザーアカウントメタデータ (WinEventLog:Security) | OS API実行 (etw:Microsoft-Windows-Directory-Services-SAM)",
   "tuning": "AllowedSIDHistoryChanges | TimeWindow | PrivilegedSIDList | UserContextFilter | AnomalousSIDCountThreshold",
   "detection_logic_en": "Detection of unauthorized modification of Active Directory SID-History attributes to escalate privileges. This chain involves: (1) privileged operations or API calls to DsAddSidHistory or related AD modification functions, (2) observed attribute changes in SID-History (Event ID 5136), (3) new logon sessions where the token includes unexpected or privileged SID-History values, and (4) follow-on resource access using elevated privileges derived from SID-History injection."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1484",
   "technique_ja": "ドメイン/テナントポリシーの変更",
   "technique_en": "Domain or Tenant Policy Modification",
   "analytic_id": "AN0755",
   "detection_strategy_id": "DET0270",
   "analytic_name": "Analytic 0755",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Modification (WinEventLog:Security) | File Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (WinEventLog:Security) | ファイル変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "ObjectDN | AttributeModified | TimeWindow | UserContext",
   "detection_logic_en": "Adversary modifies Group Policy Objects (GPOs), domain trust, or directory service objects via GUI, CLI, or programmatic APIs. Behavior includes creation/modification of GPOs, delegation permissions, trust objects, or rogue domain controller registration."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1484",
   "technique_ja": "ドメイン/テナントポリシーの変更",
   "technique_en": "Domain or Tenant Policy Modification",
   "analytic_id": "AN0756",
   "detection_strategy_id": "DET0270",
   "analytic_name": "Analytic 0756",
   "platforms": "Identity Provider",
   "log_sources": "Application Log Content (m365:unified) | User Account Authentication (azure:signinlogs)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | ユーザーアカウント認証 (azure:signinlogs)",
   "tuning": "OperationName | InitiatedBy | UserAgent | TimeWindow",
   "detection_logic_en": "Adversary modifies tenant policy through changes to federation configuration, trust settings, or identity provider additions in Microsoft 365/AzureAD via Portal, PowerShell, or Graph API. Includes setting authentication to federated or updating federated domains."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1484.001",
   "technique_ja": "グループポリシーの変更",
   "technique_en": "Group Policy Modification",
   "analytic_id": "AN0854",
   "detection_strategy_id": "DET0305",
   "analytic_name": "Analytic 0854",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Modification (WinEventLog:Security) | File Modification (WinEventLog:Security) | User Account Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (WinEventLog:Security) | ファイル変更 (WinEventLog:Security) | ユーザーアカウント変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "ObjectDN | TargetFilename | TimeWindow | UserContext | CommandLine",
   "detection_logic_en": "Adversary modifies GPO containers or files under SYSVOL using LDAP, ADSI, PowerShell (e.g., New-GPOImmediateTask) or GUI tools. This includes directory object changes (e.g., gPCFileSysPath), delegation assignments (SeEnableDelegationPrivilege), and SYSVOL file writes (ScheduledTasks.xml, GptTmpl.inf)."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1484.002",
   "technique_ja": "信頼関係の変更",
   "technique_en": "Trust Modification",
   "analytic_id": "AN1259",
   "detection_strategy_id": "DET0458",
   "analytic_name": "Analytic 1259",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Modification (WinEventLog:Security) | User Account Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (WinEventLog:Security) | ユーザーアカウント変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "ObjectType | AttributeModified | TimeWindow | UserContext",
   "detection_logic_en": "Adversary modifies Active Directory domain trust settings via `netdom`, `nltest`, or PowerShell to add new domain trust or alter federation. Modifications occur in AD object attributes like trustDirection, trustType, trustAttributes, often paired with SeEnableDelegationPrivilege or certificate injection."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1484.002",
   "technique_ja": "信頼関係の変更",
   "technique_en": "Trust Modification",
   "analytic_id": "AN1260",
   "detection_strategy_id": "DET0458",
   "analytic_name": "Analytic 1260",
   "platforms": "Identity Provider",
   "log_sources": "Application Log Content (m365:unified) | Command Execution (azure:signinlogs)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | コマンド実行 (azure:signinlogs)",
   "tuning": "OperationName | InitiatedBy | UserAgent | TimeWindow",
   "detection_logic_en": "Adversary adds federated identity provider (IdP) or modifies tenant domain authentication from Managed to Federated. Detected via API, PowerShell, or Admin Portal through federation events like `Set domain authentication`, `Add federated identity provider`, or `Update-MsolFederatedDomain`."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1543",
   "technique_ja": "システムプロセスの作成/変更",
   "technique_en": "Create or Modify System Process",
   "analytic_id": "AN1575",
   "detection_strategy_id": "DET0571",
   "analytic_name": "Analytic 1575",
   "platforms": "Windows",
   "log_sources": "Service Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "サービス作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "ServiceNamePattern | ParentProcessFilter | RegistryPathList",
   "detection_logic_en": "Detects command-line or API-based creation/modification of Windows Services via `sc.exe`, `powershell.exe`, `services.exe`, or `ChangeServiceConfig`. Looks for creation/modification of autostart services via registry changes, file drops to `System32\\services`, and anomalous parent-child process trees."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1543",
   "technique_ja": "システムプロセスの作成/変更",
   "technique_en": "Create or Modify System Process",
   "analytic_id": "AN1576",
   "detection_strategy_id": "DET0571",
   "analytic_name": "Analytic 1576",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Command Execution (auditd:SYSCALL)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | コマンド実行 (auditd:SYSCALL)",
   "tuning": "ServicePathRegex | UserContextList | CommandNameList",
   "detection_logic_en": "Detects creation or modification of `systemd` service units, addition of cron jobs that invoke binaries on boot, or suspicious writes to `/etc/init.d/`. Monitors `chmod +x` and `systemctl` execution paths, especially from non-root parent processes."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1543",
   "technique_ja": "システムプロセスの作成/変更",
   "technique_en": "Create or Modify System Process",
   "analytic_id": "AN1577",
   "detection_strategy_id": "DET0571",
   "analytic_name": "Analytic 1577",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Modification (fs:fsusage)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル変更 (fs:fsusage)",
   "tuning": "PlistPathList | PlistKeyMonitor | UnsignedBinaryAlert",
   "detection_logic_en": "Detects creation or modification of `LaunchDaemon` or `LaunchAgent` plist files under `/Library/LaunchDaemons/`, `~/Library/LaunchAgents/`, or similar. Monitors execution of `launchctl`, property list edits, and file permission changes."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1543",
   "technique_ja": "システムプロセスの作成/変更",
   "technique_en": "Create or Modify System Process",
   "analytic_id": "AN1578",
   "detection_strategy_id": "DET0571",
   "analytic_name": "Analytic 1578",
   "platforms": "Containers",
   "log_sources": "Container Creation (docker:events) | File Modification (auditd:SYSCALL)",
   "log_sources_ja": "コンテナ作成 (docker:events) | ファイル変更 (auditd:SYSCALL)",
   "tuning": "EntrypointOverridePattern | RestartPolicyMatch | KubeInitModPath",
   "detection_logic_en": "Detects creation of new container system processes via `docker run --restart`, `kubectl exec` to init containers, or modification of container init specs. Flags container images that override entrypoints to embed persistence behaviors."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1543.001",
   "technique_ja": "Launch Agent",
   "technique_en": "Launch Agent",
   "analytic_id": "AN1208",
   "detection_strategy_id": "DET0434",
   "analytic_name": "Analytic 1208",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Creation (fs:fsusage) | File Modification (fs:fsusage) | Service Creation (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル作成 (fs:fsusage) | ファイル変更 (fs:fsusage) | サービス作成 (macos:osquery)",
   "tuning": "PlistDirectoryList | PlistKeyMonitor | ExecutablePathPattern | UnsignedBinaryAlert | UserContextScope",
   "detection_logic_en": "Detects creation or modification of user-level Launch Agents in monitored directories using `.plist` files with suspicious `ProgramArguments` or `RunAtLoad` keys. Correlates file write activity with execution of `launchctl` or unsigned binaries invoked at login."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1543.002",
   "technique_ja": "systemdサービス",
   "technique_en": "Systemd Service",
   "analytic_id": "AN0701",
   "detection_strategy_id": "DET0253",
   "analytic_name": "Analytic 0701",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:SYSCALL) | File Modification (auditd:SYSCALL) | Command Execution (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Service Creation (linux:osquery)",
   "log_sources_ja": "ファイル作成 (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL) | コマンド実行 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | サービス作成 (linux:osquery)",
   "tuning": "ServicePathRegex | ExecStartPathAllowlist | UserContextFilter | FileEntropyThreshold | SystemctlOperationSet",
   "detection_logic_en": "Detects the creation or modification of `.service` unit files in system/user-level directories, combined with execution of `systemctl`, `service`, or dynamically created drop-ins via systemd generators. Detects persistence by analyzing the `ExecStart` path, file entropy, and symlink usage, especially when paired with execution from `/tmp`, `/dev/shm`, or unmounted volumes."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1543.003",
   "technique_ja": "Windowsサービス",
   "technique_en": "Windows Service",
   "analytic_id": "AN1527",
   "detection_strategy_id": "DET0552",
   "analytic_name": "Analytic 1527",
   "platforms": "Windows",
   "log_sources": "Service Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | Driver Load (WinEventLog:Sysmon)",
   "log_sources_ja": "サービス作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ドライバ読み込み (WinEventLog:Sysmon)",
   "tuning": "ServiceNamePattern | ImagePathFilter | DriverExtensionList | StartupTypeChangeWindow | UnsignedBinaryAlert",
   "detection_logic_en": "Detects creation or modification of Windows Services through command-line tools (e.g., `sc.exe`, `powershell.exe`), Registry key changes under `HKLM\\System\\CurrentControlSet\\Services`, and service execution under SYSTEM with unsigned or anomalous binary paths. Detects privilege escalation via driver installation or `CreateServiceW` usage. Correlates parent-child lineage, startup behavior, and rare service names."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1543.004",
   "technique_ja": "Launch Daemon",
   "technique_en": "Launch Daemon",
   "analytic_id": "AN1126",
   "detection_strategy_id": "DET0401",
   "analytic_name": "Analytic 1126",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (fs:launchdaemons) | File Modification (fs:launchdaemons) | Service Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (fs:launchdaemons) | ファイル変更 (fs:launchdaemons) | サービス作成 (macos:unifiedlog)",
   "tuning": "ProgramPathRegex | TimeWindow | UserContext | UnsignedBinaryFlag",
   "detection_logic_en": "Creation or modification of `.plist` files in /Library/LaunchDaemons/, especially those with suspicious Program or ProgramArguments paths, combined with execution activity under launchd with elevated privileges. Detectable through correlated Unified Logs, file monitoring, and process telemetry."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1543.005",
   "technique_ja": "コンテナサービス",
   "technique_en": "Container Service",
   "analytic_id": "AN1304",
   "detection_strategy_id": "DET0473",
   "analytic_name": "Analytic 1304",
   "platforms": "Containers",
   "log_sources": "Process Creation (auditd:SYSCALL) | Container Creation (systemd:unit) | Pod Creation (kubernetes:audit) | Service Creation (kubernetes:audit)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | コンテナ作成 (systemd:unit) | Pod作成 (kubernetes:audit) | サービス作成 (kubernetes:audit)",
   "tuning": "restartPolicy | targetNamespace | nodeSelector|nodeName | unitFilePath | TimeWindow",
   "detection_logic_en": "Correlate the creation or modification of containers using restart policies (e.g., 'always') or DaemonSets with elevated host access, service account misuse, or privileged container contexts. Watch for manipulation of systemd units involving containers or pod scheduling targeting specific nodes or namespaces."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546",
   "technique_ja": "イベントトリガー実行",
   "technique_en": "Event Triggered Execution",
   "analytic_id": "AN0024",
   "detection_strategy_id": "DET0010",
   "analytic_name": "Analytic 0024",
   "platforms": "Windows",
   "log_sources": "Scheduled Job Creation (WinEventLog:Security) | WMI Creation (WinEventLog:WMI) | Windows Registry Key Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "スケジュールジョブ作成 (WinEventLog:Security) | WMI作成 (WinEventLog:WMI) | Windowsレジストリキー変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "UserContext | TimeWindow | PathAnomalyThreshold",
   "detection_logic_en": "Correlates unexpected modifications to WMI event filters, scheduled task triggers, or registry autorun keys with subsequent execution of non-standard binaries by SYSTEM-level processes."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546",
   "technique_ja": "イベントトリガー実行",
   "technique_en": "Event Triggered Execution",
   "analytic_id": "AN0025",
   "detection_strategy_id": "DET0010",
   "analytic_name": "Analytic 0025",
   "platforms": "Linux",
   "log_sources": "File Metadata (auditd:SYSCALL) | Scheduled Job Creation (linux:syslog) | Command Execution (auditd:SYSCALL)",
   "log_sources_ja": "ファイルメタデータ (auditd:SYSCALL) | スケジュールジョブ作成 (linux:syslog) | コマンド実行 (auditd:SYSCALL)",
   "tuning": "ExecutablePathRegex | WatchTargetPaths",
   "detection_logic_en": "Detects inotify or auditd configuration changes that monitor system files coupled with execution of script interpreters or binaries by cron or systemd timers."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546",
   "technique_ja": "イベントトリガー実行",
   "technique_en": "Event Triggered Execution",
   "analytic_id": "AN0026",
   "detection_strategy_id": "DET0010",
   "analytic_name": "Analytic 0026",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "PlistNamePattern | ParentProcessBaseline",
   "detection_logic_en": "Correlates launchd plist modifications with subsequent unauthorized script execution or anomalous parent-child process trees involving user agents."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546",
   "technique_ja": "イベントトリガー実行",
   "technique_en": "Event Triggered Execution",
   "analytic_id": "AN0027",
   "detection_strategy_id": "DET0010",
   "analytic_name": "Analytic 0027",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Modification (AWS:CloudTrail) | Command Execution (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス変更 (AWS:CloudTrail) | コマンド実行 (AWS:CloudTrail)",
   "tuning": "TriggerEventType | ServiceAccountRole",
   "detection_logic_en": "Monitors cloud function creation triggered by specific audit log events (e.g., IAM changes, object creation), followed by anomalous behavior from new service accounts."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546",
   "technique_ja": "イベントトリガー実行",
   "technique_en": "Event Triggered Execution",
   "analytic_id": "AN0028",
   "detection_strategy_id": "DET0010",
   "analytic_name": "Analytic 0028",
   "platforms": "SaaS",
   "log_sources": "Cloud Service Modification (m365:unified) | Command Execution (m365:unified)",
   "log_sources_ja": "クラウドサービス変更 (m365:unified) | コマンド実行 (m365:unified)",
   "tuning": "TriggerCondition | AppIdentityScope",
   "detection_logic_en": "Correlates Power Automate or similar logic app workflows triggered by SaaS file uploads or email rules with data forwarding or anomalous access patterns."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546",
   "technique_ja": "イベントトリガー実行",
   "technique_en": "Event Triggered Execution",
   "analytic_id": "AN0029",
   "detection_strategy_id": "DET0010",
   "analytic_name": "Analytic 0029",
   "platforms": "Office Suite",
   "log_sources": "Script Execution (m365:office) | Network Traffic Content (m365:office)",
   "log_sources_ja": "スクリプト実行 (m365:office) | ネットワークトラフィック内容 (m365:office)",
   "tuning": "MacroFunctionNames | TimeDeltaMacroToC2",
   "detection_logic_en": "Detects macros or VBA triggers set to execute on document open or close events, often correlating with embedded payloads or C2 traffic shortly after execution."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.001",
   "technique_ja": "既定のファイル関連付けの変更",
   "technique_en": "Change Default File Association",
   "analytic_id": "AN0170",
   "detection_strategy_id": "DET0061",
   "analytic_name": "Analytic 0170",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Logon Session Metadata (WinEventLog:Security)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ログオンセッションメタデータ (WinEventLog:Security)",
   "tuning": "TimeWindow | UserContext | SuspiciousHandlerPathRegex",
   "detection_logic_en": "Detects modification of registry keys used for default file handlers, followed by anomalous process execution from user-initiated file opens. This includes tracking changes under HKCU and HKCR for file extension mappings, and correlating them with new or suspicious handler paths launching unusual child processes (e.g., PowerShell, cmd, wscript)."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.002",
   "technique_ja": "スクリーンセーバー",
   "technique_en": "Screensaver",
   "analytic_id": "AN0441",
   "detection_strategy_id": "DET0154",
   "analytic_name": "Analytic 0441",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | SuspiciousPathRegex | ParentProcessAllowList | RegistryEditorProcessName",
   "detection_logic_en": "Unusual screensaver (.scr) executions correlated with recent registry modifications to HKCU\\Control Panel\\Desktop values such as SCRNSAVE.exe, ScreenSaveTimeout, and ScreenSaveActive. Detection focuses on PE image paths not consistent with known legitimate screensavers and triggered after user inactivity timeout."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.003",
   "technique_ja": "WMIイベントサブスクリプション",
   "technique_en": "Windows Management Instrumentation Event Subscription",
   "analytic_id": "AN0236",
   "detection_strategy_id": "DET0086",
   "analytic_name": "Analytic 0236",
   "platforms": "Windows",
   "log_sources": "WMI Creation (WinEventLog:WMI) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "WMI作成 (WinEventLog:WMI) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext | ProcessNameAllowlist | ParentProcessAnomalyThreshold",
   "detection_logic_en": "Monitor for creation of WMI EventFilter, EventConsumer, and FilterToConsumerBinding objects through WMI or MOF file execution. Detect command-line execution of `mofcomp.exe`, usage of `Register-WmiEvent` via PowerShell, and anomalous child processes of `WmiPrvSE.exe` that indicate triggered execution. Look for lateral anomalies in process lineage and WMI logging channels."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.004",
   "technique_ja": "Unixシェル構成の変更",
   "technique_en": "Unix Shell Configuration Modification",
   "analytic_id": "AN0059",
   "detection_strategy_id": "DET0020",
   "analytic_name": "Analytic 0059",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:EXECVE) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:EXECVE) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TimeWindow | TargetUser | FilePathRegex",
   "detection_logic_en": "Detects modification of shell startup/logout scripts such as ~/.bashrc, ~/.bash_profile, or /etc/profile, followed by anomalous process execution or network connections upon interactive or remote shell login."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.004",
   "technique_ja": "Unixシェル構成の変更",
   "technique_en": "Unix Shell Configuration Modification",
   "analytic_id": "AN0060",
   "detection_strategy_id": "DET0020",
   "analytic_name": "Analytic 0060",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:endpointsecurity)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:endpointsecurity)",
   "tuning": "FileTargetList | PayloadEntropyThreshold | UserContext",
   "detection_logic_en": "Correlates zsh shell configuration file changes (e.g., ~/.zshrc, ~/.zlogin, /etc/zprofile) with execution of unauthorized binaries or unexpected network activity triggered on Terminal.app launch."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.005",
   "technique_ja": "Trap",
   "technique_en": "Trap",
   "analytic_id": "AN1038",
   "detection_strategy_id": "DET0369",
   "analytic_name": "Analytic 1038",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Modification (auditd:SYSCALL) | File Access (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL) | ファイルアクセス (auditd:SYSCALL)",
   "tuning": "TargetShellFilePath | SignalTrapName | TimeWindow",
   "detection_logic_en": "Correlate file modifications in shell startup scripts (e.g., .bashrc, .profile) with embedded `trap` commands and observe if those changes are followed by the unexpected execution of child processes when terminal signals (e.g., SIGINT) are triggered. Use contextual linking with user session activity to detect privilege misuse."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.005",
   "technique_ja": "Trap",
   "technique_en": "Trap",
   "analytic_id": "AN1039",
   "detection_strategy_id": "DET0369",
   "analytic_name": "Analytic 1039",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog)",
   "tuning": "LoginShellConfigPaths | TrapCommandLengthThreshold | ParentProcessAnomalyThreshold",
   "detection_logic_en": "Detect unauthorized `trap` command registrations in shell startup files (e.g., .zprofile, .bash_profile, .zshrc) followed by execution chains during user terminal interaction. Use Unified Logs and EDR telemetry to correlate shell command parsing and process tree anomalies."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.006",
   "technique_ja": "LC_LOAD_DYLIBの追加",
   "technique_en": "LC_LOAD_DYLIB Addition",
   "analytic_id": "AN0607",
   "detection_strategy_id": "DET0216",
   "analytic_name": "Analytic 0607",
   "platforms": "macOS",
   "log_sources": "Module Load (macos:unifiedlog) | File Modification (macos:unifiedlog) | File Metadata (macos:unifiedlog)",
   "log_sources_ja": "モジュール読み込み (macos:unifiedlog) | ファイル変更 (macos:unifiedlog) | ファイルメタデータ (macos:unifiedlog)",
   "tuning": "TimeWindow | DylibPathRegex | UnsignedDylibThreshold | UserContext",
   "detection_logic_en": "Detection focuses on unauthorized modification of Mach-O binaries to include LC_LOAD_DYLIB headers pointing to malicious dylibs. Behavior is identified via a chain of file metadata changes, removal of code signatures, and subsequent anomalous dylib loads at runtime. Correlation of file changes with lack of authorized updates and process memory mapping of unrecognized or unsigned libraries is crucial."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.007",
   "technique_ja": "NetshヘルパDLL",
   "technique_en": "Netsh Helper DLL",
   "analytic_id": "AN1588",
   "detection_strategy_id": "DET0575",
   "analytic_name": "Analytic 1588",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | NetshChildProcessWhitelist | DLLLoadPath",
   "detection_logic_en": "Detection focuses on monitoring registry modifications under HKLM\\SOFTWARE\\Microsoft\\Netsh that indicate the addition of helper DLLs, followed by anomalous child process activity or module load behavior initiated by netsh.exe. These behaviors are rarely legitimate and may represent an adversary establishing persistence."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.008",
   "technique_ja": "アクセシビリティ機能",
   "technique_en": "Accessibility Features",
   "analytic_id": "AN0094",
   "detection_strategy_id": "DET0033",
   "analytic_name": "Analytic 0094",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | TargetBinaryNames | ParentProcess | UserContext | CommandLineContains",
   "detection_logic_en": "Defenders can observe suspicious replacement or tampering of system accessibility binaries (e.g., utilman.exe, sethc.exe, osk.exe) and anomalous modifications to registry keys used to redirect accessibility programs (such as IFEO keys). Additionally, execution of cmd.exe or other suspicious binaries triggered from the login screen by SYSTEM can be correlated as part of a behavior chain."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.009",
   "technique_ja": "AppCert DLL",
   "technique_en": "AppCert DLLs",
   "analytic_id": "AN1029",
   "detection_strategy_id": "DET0362",
   "analytic_name": "Analytic 1029",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "TargetObject | ImageLoaded | ParentImage | TimeWindow",
   "detection_logic_en": "Detection of AppCert DLL abuse involves correlating registry modifications to the AppCertDLLs key with subsequent unexpected DLL load behavior during process creation events. Specifically, defenders can observe abnormal DLLs being loaded into standard Windows processes after changes to the 'AppCertDLLs' registry value. Monitoring CreateProcess-family API executions with injected DLLs and linking those DLLs back to recent registry edits is key to identifying misuse. This is often accompanied by elevated privileges and potential lateral movement or discovery behavior."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.010",
   "technique_ja": "AppInit DLL",
   "technique_en": "AppInit DLLs",
   "analytic_id": "AN1536",
   "detection_strategy_id": "DET0557",
   "analytic_name": "Analytic 1536",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "ImagePathWhitelist | UserContext | TimeWindow | DLLSignatureStatus",
   "detection_logic_en": "Registry key modification to AppInit_DLLs value followed by anomalous DLL loading by processes importing user32.dll, especially unsigned or uncommon DLLs, suggesting unauthorized AppInit persistence or privilege escalation."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.011",
   "technique_ja": "アプリケーションシミング",
   "technique_en": "Application Shimming",
   "analytic_id": "AN0051",
   "detection_strategy_id": "DET0017",
   "analytic_name": "Analytic 0051",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "CustomShimPathAllowlist | TimeWindow | DLLInjectionTarget | UserContext | ShimCommandLinePattern",
   "detection_logic_en": "Correlated modification of AppCompat registry keys and execution of sdbinst.exe to install custom shim databases. Followed by DLL injection via shim behavior into target application processes."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.012",
   "technique_ja": "IFEOインジェクション",
   "technique_en": "Image File Execution Options Injection",
   "analytic_id": "AN1186",
   "detection_strategy_id": "DET0422",
   "analytic_name": "Analytic 1186",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Windows Registry Key Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | Windowsレジストリキー作成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | TargetBinary | ParentProcessAnomaly | TokenElevationContext",
   "detection_logic_en": "Registry key modifications under IFEO paths (e.g., Debugger value set under Image File Execution Options), especially for security-related or accessibility binaries, followed by anomalous process execution with debugger flags or SYSTEM-level access at login. Detectable by correlating registry modifications, process creation, and parent-child anomalies with unusual command-line usage or access tokens."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.013",
   "technique_ja": "PowerShellプロファイル",
   "technique_en": "PowerShell Profile",
   "analytic_id": "AN1245",
   "detection_strategy_id": "DET0451",
   "analytic_name": "Analytic 1245",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Modification (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "ProfilePathList | ExecutionContext | ModuleOrScriptName | TimeWindow",
   "detection_logic_en": "Defenders can identify PowerShell profile-based persistence by correlating file creation or modification in known profile locations with subsequent PowerShell process launches that do not use the `-NoProfile` flag. Profile scripts loading unusual modules or launching external programs, particularly under elevated contexts, are suspicious and may represent adversary persistence or privilege escalation."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.014",
   "technique_ja": "Emond",
   "technique_en": "Emond",
   "analytic_id": "AN1534",
   "detection_strategy_id": "DET0555",
   "analytic_name": "Analytic 1534",
   "platforms": "macOS",
   "log_sources": "File Creation (macos:unifiedlog) | Process Creation (macos:unifiedlog) | File Modification (macos:unifiedlog) | Command Execution (macos:unifiedlog)",
   "log_sources_ja": "ファイル作成 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog) | コマンド実行 (macos:unifiedlog)",
   "tuning": "PathPrefix | TimeWindow | ParentProcessFilter | CommandPatternList",
   "detection_logic_en": "Detection focuses on identifying unauthorized file creation or modification within `/etc/emond.d/rules/` or `/private/var/db/emondClients`, which indicate attempts to register a malicious emond rule. Correlate with process execution of `/sbin/emond` and any launched commands it invokes, especially during boot or login events. Anomalies may include rules created by non-root users or unexpected shell commands executed by emond."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.015",
   "technique_ja": "COMハイジャック",
   "technique_en": "Component Object Model Hijacking",
   "analytic_id": "AN1323",
   "detection_strategy_id": "DET0481",
   "analytic_name": "Analytic 1323",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "RegistryPathScope | BinaryPathAnomalyThreshold | TimeWindow | UserContextFilter",
   "detection_logic_en": "Correlate suspicious registry modifications to known COM object CLSIDs with subsequent DLL loads or unexpected binary execution paths. Detect placement of COM CLSID entries under HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\ overriding default HKLM paths. Flag anomalous DLL loads traced back to hijacked COM registry changes."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.016",
   "technique_ja": "インストーラパッケージ",
   "technique_en": "Installer Packages",
   "analytic_id": "AN0938",
   "detection_strategy_id": "DET0330",
   "analytic_name": "Analytic 0938",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:unifiedlog)",
   "tuning": "ScriptLocation | ParentProcessName",
   "detection_logic_en": "Correlation of package install event with execution of postinstall scripts containing unknown binaries or abnormal CLI usage. Look for `/usr/sbin/installer` execution followed by child processes originating from postinstall script."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.016",
   "technique_ja": "インストーラパッケージ",
   "technique_en": "Installer Packages",
   "analytic_id": "AN0939",
   "detection_strategy_id": "DET0330",
   "analytic_name": "Analytic 0939",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Creation (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル作成 (auditd:SYSCALL)",
   "tuning": "ScriptName | PackageManager",
   "detection_logic_en": "Detection of maintainer scripts (e.g., postinst, preinst) being modified or executed during dpkg or rpm operations. Watch for script content that spawns additional processes or writes outside package scope."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.016",
   "technique_ja": "インストーラパッケージ",
   "technique_en": "Installer Packages",
   "analytic_id": "AN0940",
   "detection_strategy_id": "DET0330",
   "analytic_name": "Analytic 0940",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "InstallerParent | ChildImagePath | ExecutionTimeWindow",
   "detection_logic_en": "Detection of msiexec.exe running installer packages that result in anomalous process creation. Look for unexpected binaries executed by msiexec or custom action DLLs in the temp directory."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.017",
   "technique_ja": "Udevルール",
   "technique_en": "Udev Rules",
   "analytic_id": "AN1056",
   "detection_strategy_id": "DET0375",
   "analytic_name": "Analytic 1056",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Command Execution (auditd:CONFIG_CHANGE)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | コマンド実行 (auditd:CONFIG_CHANGE)",
   "tuning": "UdevRulePath | SuspiciousRunPattern | TimeWindow | ParentProcess",
   "detection_logic_en": "Monitor for creation or modification of udev rules files in key directories (/etc/udev/rules.d/, /lib/udev/rules.d/, /usr/lib/udev/rules.d/). Look for RUN+= or IMPORT keys invoking suspicious binaries or scripts. Correlate this with process execution from systemd-udevd context, and file writes near udev reload/restart events. Combine this with unexpected background process spawning from udevd-related forks."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1546.018",
   "technique_ja": "Python起動フック",
   "technique_en": "Python Startup Hooks",
   "analytic_id": "AN0713",
   "detection_strategy_id": "DET0258",
   "analytic_name": "Analytic 0713",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Modification (auditd:PATH) | File Metadata (auditd:CONFIG_CHANGE) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル変更 (auditd:PATH) | ファイルメタデータ (auditd:CONFIG_CHANGE) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "HookFilePathPatterns | UserContext | TimeWindow | InterpreterWhitelist",
   "detection_logic_en": "Defender observes unauthorized modification or creation of Python hook files such as `.pth`, `sitecustomize.py`, or `usercustomize.py` in Python `site-packages`, `dist-packages`, or user paths. This is often correlated with subsequent unexpected interpreter execution (e.g., python3 running without user interaction), changes in interpreter behavior (e.g., malicious imports), and outbound connections initiated from Python. Defender links write/modify actions on hook files with execve of python process and/or anomalous child process or network activity."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1547",
   "technique_ja": "起動/ログオン時の自動実行",
   "technique_en": "Boot or Logon Autostart Execution",
   "analytic_id": "AN0764",
   "detection_strategy_id": "DET0274",
   "analytic_name": "Analytic 0764",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "ParentProcessName | StartupRegistryPath",
   "detection_logic_en": "Correlation of registry key modification for Run/RunOnce with abnormal parent-child process relationships and outlier execution at user logon or system startup"
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1547",
   "technique_ja": "起動/ログオン時の自動実行",
   "technique_en": "Boot or Logon Autostart Execution",
   "analytic_id": "AN0765",
   "detection_strategy_id": "DET0274",
   "analytic_name": "Analytic 0765",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:SYSCALL) | File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイル作成 (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "FilePath | UserContext",
   "detection_logic_en": "Correlates creation/modification of systemd service files or /etc/init.d scripts with outlier process behavior during boot"
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1547",
   "technique_ja": "起動/ログオン時の自動実行",
   "technique_en": "Boot or Logon Autostart Execution",
   "analytic_id": "AN0766",
   "detection_strategy_id": "DET0274",
   "analytic_name": "Analytic 0766",
   "platforms": "macOS",
   "log_sources": "Service Metadata (macos:unifiedlog) | File Modification (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "サービスメタデータ (macos:unifiedlog) | ファイル変更 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "PlistKey | TimeWindow",
   "detection_logic_en": "Observes creation or modification of LaunchAgent/LaunchDaemon property list files combined with anomalous plist payload execution after user logon"
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1547.001",
   "technique_ja": "レジストリRunキー/スタートアップフォルダ",
   "technique_en": "Registry Run Keys / Startup Folder",
   "analytic_id": "AN1032",
   "detection_strategy_id": "DET0365",
   "analytic_name": "Analytic 1032",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | File Creation (WinEventLog:Microsoft-Windows-Shell-Core)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Microsoft-Windows-Shell-Core)",
   "tuning": "ImagePath | RegistryKeyPath | TimeWindow | UserContext",
   "detection_logic_en": "Correlation of Registry key creation/modification events under known Run/Startup keys with new or unusual binary paths or script-based payloads. Multi-event detection includes registry modification followed by process execution from non-standard directories or abnormal parent-child process relationships."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1547.002",
   "technique_ja": "認証パッケージ",
   "technique_en": "Authentication Package",
   "analytic_id": "AN0583",
   "detection_strategy_id": "DET0207",
   "analytic_name": "Analytic 0583",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | ImageSignatureStatus | RegistryPathScope | UserContext | ParentProcess",
   "detection_logic_en": "Registry modification of the LSA Authentication Packages key followed by LSASS loading a non-standard or unsigned DLL. This includes unusual write access to `HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa`, especially during non-installation timeframes. Correlated with `lsass.exe` loading DLLs not present in baseline or lacking valid signatures."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1547.003",
   "technique_ja": "タイムプロバイダ",
   "technique_en": "Time Providers",
   "analytic_id": "AN0341",
   "detection_strategy_id": "DET0122",
   "analytic_name": "Analytic 0341",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "RegistryPathScope | UserContext | TimeWindow | DllPathEntropyThreshold",
   "detection_logic_en": "Behavioral correlation of privileged registry key creation under the W32Time TimeProviders path combined with a new DLL written to disk and potential process activity by LocalService. Indicates abuse of Time Providers for persistence."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1547.004",
   "technique_ja": "WinlogonヘルパDLL",
   "technique_en": "Winlogon Helper DLL",
   "analytic_id": "AN1133",
   "detection_strategy_id": "DET0404",
   "analytic_name": "Analytic 1133",
   "platforms": "Windows",
   "log_sources": "Module Load (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Security) | Windows Registry Key Access (Autoruns:RegistryScan)",
   "log_sources_ja": "モジュール読み込み (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Security) | Windowsレジストリキーアクセス (Autoruns:RegistryScan)",
   "tuning": "TimeWindow | UserContext | BinarySignatureValidation | ExecutablePathScope",
   "detection_logic_en": "Monitor Windows Registry modifications to Winlogon keys (Shell, Userinit, Notify) that introduce new executable or DLL paths. Correlate these changes with subsequent DLL loading, image loads, or process creation originating from winlogon.exe or userinit.exe. Abnormal child process lineage or unauthorized binaries in C:\\Windows\\System32 may indicate abuse."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1547.005",
   "technique_ja": "セキュリティサポートプロバイダ",
   "technique_en": "Security Support Provider",
   "analytic_id": "AN1495",
   "detection_strategy_id": "DET0542",
   "analytic_name": "Analytic 1495",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Module Load (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | DLLSignatureValidation | CustomSSPNameList | BootContextCorrelation",
   "detection_logic_en": "Monitor registry modifications to `HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\Security Packages` or `...\\OSConfig\\Security Packages`, especially insertions of new DLL entries. Correlate this with subsequent DLL module loads into `lsass.exe`. Track unsigned or anomalous DLLs loading into LSASS using image load auditing. LSASS loads unsigned DLL due to AuditLevel=8 registry configuration or System reboot followed by DLL load into lsass.exe"
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1547.006",
   "technique_ja": "カーネルモジュールと拡張",
   "technique_en": "Kernel Modules and Extensions",
   "analytic_id": "AN1243",
   "detection_strategy_id": "DET0450",
   "analytic_name": "Analytic 1243",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | File Creation (auditd:SYSCALL) | File Modification (linux:osquery)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ファイル作成 (auditd:SYSCALL) | ファイル変更 (linux:osquery)",
   "tuning": "UserContext | TimeWindow | FilePathRegex",
   "detection_logic_en": "Monitor kernel module load/unload activity via modprobe, insmod, rmmod, or direct manipulation of /lib/modules. Correlate with installation of kernel headers, compilation commands, or downloads of .ko files. Detect anomalies in unsigned module loading or repeated module load attempts under non-root users."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1547.006",
   "technique_ja": "カーネルモジュールと拡張",
   "technique_en": "Kernel Modules and Extensions",
   "analytic_id": "AN1244",
   "detection_strategy_id": "DET0450",
   "analytic_name": "Analytic 1244",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Process Creation (macos:osquery) | Kernel Module Load (macos:osquery) | File Modification (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | プロセス生成 (macos:osquery) | カーネルモジュール読み込み (macos:osquery) | ファイル変更 (macos:osquery)",
   "tuning": "DeveloperIDAllowlist | KextLoadTimeWindow | SignatureCheckFlag",
   "detection_logic_en": "Detect user-initiated kextload commands or modifications to /Library/Extensions. Correlate with changes to KextPolicy database or unauthorized developer signing identities. Alert on attempts to disable SIP or load legacy extensions from unsigned sources."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1547.007",
   "technique_ja": "再オープンアプリケーション",
   "technique_en": "Re-opened Applications",
   "analytic_id": "AN0349",
   "detection_strategy_id": "DET0125",
   "analytic_name": "Analytic 0349",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (fs:filesystem) | Logon Session Metadata (macos:unifiedlog) | File Metadata (macos:endpointsecurity)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (fs:filesystem) | ログオンセッションメタデータ (macos:unifiedlog) | ファイルメタデータ (macos:endpointsecurity)",
   "tuning": "UserContext | FilePathPattern | TimeWindow | BinaryAnomalyScore",
   "detection_logic_en": "Unusual modification or creation of loginwindow-related plist files in '~/Library/Preferences/ByHost' correlated with unauthorized application paths and execution upon login."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1547.008",
   "technique_ja": "LSASSドライバ",
   "technique_en": "LSASS Driver",
   "analytic_id": "AN0629",
   "detection_strategy_id": "DET0225",
   "analytic_name": "Analytic 0629",
   "platforms": "Windows",
   "log_sources": "Module Load (WinEventLog:Security) | Driver Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | File Modification (WinEventLog:Sysmon) | Windows Registry Key Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "モジュール読み込み (WinEventLog:Security) | ドライバ読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Sysmon) | Windowsレジストリキー作成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | ImagePathPattern | SignatureValidation | RegistryKeyScope | FileHashAllowList",
   "detection_logic_en": "Unauthorized creation or modification of DLLs loaded by LSASS, abnormal registry values under LSA extensions, and anomalous DLL load activity into the lsass.exe process context—correlated during boot or logon events."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1547.009",
   "technique_ja": "ショートカットの変更",
   "technique_en": "Shortcut Modification",
   "analytic_id": "AN0510",
   "detection_strategy_id": "DET0180",
   "analytic_name": "Analytic 0510",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Modification (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon)",
   "tuning": "TargetPathRegex | TimeWindow | UserContextScope | ZoneIdentifierThreshold",
   "detection_logic_en": "Detection correlates file creation or modification of `.lnk` (shortcut) files in autostart locations with anomalous parent-child process lineage or unsigned binaries. Defenders should watch for LNK creation/modification events outside of known software installations, patch events, or OS updates. Flag shortcut targets pointing to suspicious locations or unknown binaries, particularly those written by script interpreters or spawned from phishing delivery chains."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1547.010",
   "technique_ja": "ポートモニタ",
   "technique_en": "Port Monitors",
   "analytic_id": "AN0580",
   "detection_strategy_id": "DET0204",
   "analytic_name": "Analytic 0580",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | OS API Execution (WinEventLog:Application)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | OS API実行 (WinEventLog:Application)",
   "tuning": "TargetDLLDirectory | SignedImageValidation | UserContextScope | TimeWindow | AddMonitorCallContext",
   "detection_logic_en": "Detects suspicious registry modifications under `HKLM\\SYSTEM\\CurrentControlSet\\Control\\Print\\Monitors\\*\\Driver`, DLL loads by `spoolsv.exe` of non-standard or unsigned modules, and abnormal usage of the `AddMonitor` API by non-installation processes. This pattern often indicates an attempt to persist a malicious DLL via the print monitor mechanism, particularly when correlated with creation of files in `C:\\Windows\\System32` not tied to known patches or installations."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1547.012",
   "technique_ja": "プリントプロセッサ",
   "technique_en": "Print Processors",
   "analytic_id": "AN0074",
   "detection_strategy_id": "DET0026",
   "analytic_name": "Analytic 0074",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | PrintProcessorDirectory | DLLNamePattern | SignedImageValidation | ServiceRestartTrigger",
   "detection_logic_en": "Correlated registry modifications under Print Processors path, followed by DLL file creation within the system print processor directory, and DLL load by spoolsv.exe. Malicious execution often occurs during service restart or system boot, with SYSTEM-level privileges."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1547.013",
   "technique_ja": "XDG自動起動エントリ",
   "technique_en": "XDG Autostart Entries",
   "analytic_id": "AN1096",
   "detection_strategy_id": "DET0390",
   "analytic_name": "Analytic 1096",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:SYSCALL) | File Access (auditd:SYSCALL) | Process Creation (auditd:EXECVE) | File Metadata (linux:osquery) | Logon Session Creation (linux:auth)",
   "log_sources_ja": "ファイル作成 (auditd:SYSCALL) | ファイルアクセス (auditd:SYSCALL) | プロセス生成 (auditd:EXECVE) | ファイルメタデータ (linux:osquery) | ログオンセッション作成 (linux:auth)",
   "tuning": "ExecCommandPattern | AutostartDirectory | TimeWindow | UserContext | PackageOriginBaseline",
   "detection_logic_en": "Correlation of file creation/modification of `.desktop` files within XDG autostart directories, followed by execution of processes at user login initiated by the desktop environment. Malicious entries typically include suspicious Exec paths or anomalous names and are not associated with installed packages."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1547.014",
   "technique_ja": "Active Setup",
   "technique_en": "Active Setup",
   "analytic_id": "AN0871",
   "detection_strategy_id": "DET0312",
   "analytic_name": "Analytic 0871",
   "platforms": "Windows",
   "log_sources": "Logon Session Metadata (WinEventLog:Security) | Process Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon) | Windows Registry Key Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッションメタデータ (WinEventLog:Security) | プロセス生成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | Windowsレジストリキー作成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | ParentProcessName | StubPathValueEntropy | SignedBinaryStatus | RegistryKeyOwner",
   "detection_logic_en": "Multi-event correlation of Registry creation under Active Setup with anomalous execution of processes at user logon. Behavioral patterns include creation/modification of HKLM Active Setup keys with non-standard StubPath values, followed by process execution from uncommon paths, unsigned binaries, or unusual parent-child lineage post-user login."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1547.015",
   "technique_ja": "ログインアイテム",
   "technique_en": "Login Items",
   "analytic_id": "AN0340",
   "detection_strategy_id": "DET0121",
   "analytic_name": "Analytic 0340",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:unifiedlog) | OS API Execution (macos:unifiedlog) | Script Execution (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog) | OS API実行 (macos:unifiedlog) | スクリプト実行 (macos:unifiedlog)",
   "tuning": "TimeWindow | UserContext | ExecutableAllowlist | PathRegexExclusion",
   "detection_logic_en": "Creation or modification of Login Items using AppleScript or Service Management Framework. Detection focuses on file creation/modification of `backgrounditems.btm`, new executables in `Contents/Library/LoginItems/`, use of `SMLoginItemSetEnabled` API, or suspicious processes triggered post-login without user interaction. Behavioral pivot includes anomalous AppleEvents, suspicious parent-child process pairs, and login-triggered execution chains."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1548",
   "technique_ja": "昇格制御メカニズムの悪用",
   "technique_en": "Abuse Elevation Control Mechanism",
   "analytic_id": "AN0975",
   "detection_strategy_id": "DET0345",
   "analytic_name": "Analytic 0975",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Logon Session Metadata (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ログオンセッションメタデータ (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "ElevatedProcessPath | ParentProcessName | TimeWindow",
   "detection_logic_en": "Correlate registry modifications (e.g., UAC bypass registry keys), unusual parent-child process relationships (e.g., control.exe spawning cmd.exe), and unsigned elevated process executions with non-standard tokens or elevation flags."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1548",
   "technique_ja": "昇格制御メカニズムの悪用",
   "technique_en": "Abuse Elevation Control Mechanism",
   "analytic_id": "AN0976",
   "detection_strategy_id": "DET0345",
   "analytic_name": "Analytic 0976",
   "platforms": "Linux",
   "log_sources": "File Metadata (auditd:SYSCALL) | Process Metadata (auditd:SYSCALL) | OS API Execution (auditd:SYSCALL)",
   "log_sources_ja": "ファイルメタデータ (auditd:SYSCALL) | プロセスメタデータ (auditd:SYSCALL) | OS API実行 (auditd:SYSCALL)",
   "tuning": "WatchedDirectories | UserContext | TimeWindow",
   "detection_logic_en": "Monitor audit logs for setuid/setgid bit changes, executions where UID ≠ EUID (indicative of sudo or privilege escalation), and high-integrity binaries launched by unprivileged users."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1548",
   "technique_ja": "昇格制御メカニズムの悪用",
   "technique_en": "Abuse Elevation Control Mechanism",
   "analytic_id": "AN0977",
   "detection_strategy_id": "DET0345",
   "analytic_name": "Analytic 0977",
   "platforms": "macOS",
   "log_sources": "OS API Execution (macos:unifiedlog) | Process Metadata (auditd:SYSCALL) | Process Creation (fs:fsusage)",
   "log_sources_ja": "OS API実行 (macos:unifiedlog) | プロセスメタデータ (auditd:SYSCALL) | プロセス生成 (fs:fsusage)",
   "tuning": "WatchedBinaries | ExecutionParent",
   "detection_logic_en": "Detect execution of `/usr/libexec/security_authtrampoline` or use of AuthorizationExecuteWithPrivileges API, and monitor process lineage for unusual launches of GUI apps with escalated privileges."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1548",
   "technique_ja": "昇格制御メカニズムの悪用",
   "technique_en": "Abuse Elevation Control Mechanism",
   "analytic_id": "AN0978",
   "detection_strategy_id": "DET0345",
   "analytic_name": "Analytic 0978",
   "platforms": "Identity Provider",
   "log_sources": "User Account Modification (azure:signinlogs)",
   "log_sources_ja": "ユーザーアカウント変更 (azure:signinlogs)",
   "tuning": "AuthorizedRoleMappings | TimeWindow",
   "detection_logic_en": "Monitor for unexpected privilege elevation operations via SAML assertion manipulation, role injection, or changes to identity mappings that result in access escalation."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1548",
   "technique_ja": "昇格制御メカニズムの悪用",
   "technique_en": "Abuse Elevation Control Mechanism",
   "analytic_id": "AN0979",
   "detection_strategy_id": "DET0345",
   "analytic_name": "Analytic 0979",
   "platforms": "IaaS",
   "log_sources": "User Account Modification (AWS:CloudTrail) | Process Metadata (AWS:CloudTrail)",
   "log_sources_ja": "ユーザーアカウント変更 (AWS:CloudTrail) | プロセスメタデータ (AWS:CloudTrail)",
   "tuning": "PermittedRoleTransitions | CrossAccountBoundary",
   "detection_logic_en": "Detect sudden privilege escalations such as IAM role changes, user-assigned privilege boundaries, or elevation via assumed roles beyond normal behavior."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1548.001",
   "technique_ja": "Setuidとsetgid",
   "technique_en": "Setuid and Setgid",
   "analytic_id": "AN0307",
   "detection_strategy_id": "DET0110",
   "analytic_name": "Analytic 0307",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "UserContext | FilePathScope | TimeWindow",
   "detection_logic_en": "Correlation of chmod operations setting setuid/setgid bits followed by privileged process execution (EUID != UID), especially from user-writable or abnormal paths."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1548.001",
   "technique_ja": "Setuidとsetgid",
   "technique_en": "Setuid and Setgid",
   "analytic_id": "AN0308",
   "detection_strategy_id": "DET0110",
   "analytic_name": "Analytic 0308",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Process Metadata (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | プロセスメタデータ (macos:unifiedlog)",
   "tuning": "UserContext | ExecutionPath | ChmodPattern",
   "detection_logic_en": "Observation of chmod commands setting setuid/setgid bits, paired with launch of binaries under elevated execution context (e.g., root-owned binaries launched by unprivileged users)."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1548.002",
   "technique_ja": "ユーザーアカウント制御(UAC)のバイパス",
   "technique_en": "Bypass User Account Control",
   "analytic_id": "AN1094",
   "detection_strategy_id": "DET0388",
   "analytic_name": "Analytic 1094",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Logon Session Metadata (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ログオンセッションメタデータ (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | ElevatedProcessNameList | ParentProcessAnomalyThreshold",
   "detection_logic_en": "Detects a multi-event behavior chain involving UAC bypass attempts via known auto-elevated binaries (e.g., eventvwr.exe, sdclt.exe), unauthorized Registry changes to UAC-related keys, and anomalous process execution with elevated privileges but lacking standard parent-child lineage. Suspicious patterns include invocation of auto-elevated COM objects or manipulation of isolatedCommand Registry entries without consent prompts."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1548.003",
   "technique_ja": "Sudoとsudoキャッシュ",
   "technique_en": "Sudo and Sudo Caching",
   "analytic_id": "AN0142",
   "detection_strategy_id": "DET0052",
   "analytic_name": "Analytic 0142",
   "platforms": "Linux",
   "log_sources": "Process Metadata (auditd:SYSCALL) | File Modification (auditd:SYSCALL)",
   "log_sources_ja": "プロセスメタデータ (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL)",
   "tuning": "timestamp_timeout_threshold | command_allowlist",
   "detection_logic_en": "Correlate command executions involving 'sudo' with elevated effective user ID (euid=0), especially when tty_tickets is disabled or timestamp_timeout is actively abused."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1548.003",
   "technique_ja": "Sudoとsudoキャッシュ",
   "technique_en": "Sudo and Sudo Caching",
   "analytic_id": "AN0143",
   "detection_strategy_id": "DET0052",
   "analytic_name": "Analytic 0143",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Process Termination (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | プロセス終了 (macos:unifiedlog)",
   "tuning": "admin_user_context | terminal_restart_window",
   "detection_logic_en": "Detect sudo activity with NOPASSWD in /etc/sudoers or disabling tty_tickets, followed by immediate privileged commands (e.g., echo 'Defaults !tty_tickets' >> /etc/sudoers)."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1548.004",
   "technique_ja": "プロンプト付き昇格実行",
   "technique_en": "Elevated Execution with Prompt",
   "analytic_id": "AN1111",
   "detection_strategy_id": "DET0395",
   "analytic_name": "Analytic 1111",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | OS API Execution (macos:unifiedlog) | User Account Authentication (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | OS API実行 (macos:unifiedlog) | ユーザーアカウント認証 (macos:unifiedlog)",
   "tuning": "BinaryReputationList | TimeWindow | PromptContextValidation",
   "detection_logic_en": "Detects abuse of AuthorizationExecuteWithPrivileges API to gain elevated privileges via user credential prompts, typically through invocation of /usr/libexec/security_authtrampoline. Detection involves correlation of API usage, binary reputation, and prompt context."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1548.005",
   "technique_ja": "一時的な昇格クラウドアクセス",
   "technique_en": "Temporary Elevated Cloud Access",
   "analytic_id": "AN1105",
   "detection_strategy_id": "DET0393",
   "analytic_name": "Analytic 1105",
   "platforms": "IaaS",
   "log_sources": "User Account Metadata (AWS:CloudTrail)",
   "log_sources_ja": "ユーザーアカウントメタデータ (AWS:CloudTrail)",
   "tuning": "targetRoleName | TimeWindow | invokingService",
   "detection_logic_en": "Multiple AWS CloudTrail events indicating temporary privilege escalation via PassRole and AssumeRole targeting newly created services or non-interactive infrastructure."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1548.005",
   "technique_ja": "一時的な昇格クラウドアクセス",
   "technique_en": "Temporary Elevated Cloud Access",
   "analytic_id": "AN1106",
   "detection_strategy_id": "DET0393",
   "analytic_name": "Analytic 1106",
   "platforms": "Identity Provider",
   "log_sources": "User Account Metadata (gcp:iam) | User Account Authentication (gcp:workspaceaudit)",
   "log_sources_ja": "ユーザーアカウントメタデータ (gcp:iam) | ユーザーアカウント認証 (gcp:workspaceaudit)",
   "tuning": "userEmailFilter | delegatedScope",
   "detection_logic_en": "Token creation or access delegation where a user impersonates a higher-privileged service account or performs domain-wide delegation actions, such as GCP's serviceAccountTokenCreator or Workspace impersonation."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1548.005",
   "technique_ja": "一時的な昇格クラウドアクセス",
   "technique_en": "Temporary Elevated Cloud Access",
   "analytic_id": "AN1107",
   "detection_strategy_id": "DET0393",
   "analytic_name": "Analytic 1107",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified) | User Account Authentication (m365:signinlogs)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | ユーザーアカウント認証 (m365:signinlogs)",
   "tuning": "TargetMailbox | UserAgent | GeoLocation",
   "detection_logic_en": "Detection of ApplicationImpersonation role assignment or delegated mailbox access to service principals or rarely used users, especially outside of normal hours or geographic norms."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1548.006",
   "technique_ja": "TCC操作",
   "technique_en": "TCC Manipulation",
   "analytic_id": "AN1474",
   "detection_strategy_id": "DET0534",
   "analytic_name": "Analytic 1474",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:unifiedlog) | Command Execution (macos:unifiedlog) | Host Status (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog) | コマンド実行 (macos:unifiedlog) | ホスト状態 (macos:unifiedlog)",
   "tuning": "ParentProcessName | TCCModificationPath | TimeWindow | SIPStateCheckInterval",
   "detection_logic_en": "Unauthorized modification of TCC.db followed by elevated process execution under a trusted parent (e.g., Finder, SystemUIServer) or via launchctl environment override. Also includes identification of SIP being disabled, which is highly uncommon and a prerequisite for this abuse path."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1611",
   "technique_ja": "ホストへのエスケープ",
   "technique_en": "Escape to Host",
   "analytic_id": "AN0612",
   "detection_strategy_id": "DET0219",
   "analytic_name": "Analytic 0612",
   "platforms": "Containers",
   "log_sources": "Container Creation (docker:daemon) | Volume Modification (kubernetes:apiserver)",
   "log_sources_ja": "コンテナ作成 (docker:daemon) | ボリューム変更 (kubernetes:apiserver)",
   "tuning": "AllowedHostPaths | PrivilegedContainerThreshold",
   "detection_logic_en": "Detection of container escape attempts via bind mounts, privileged containers, or abuse of docker.sock. Defenders may observe anomalous volume mount configurations (e.g., hostPath to / or /proc), unexpected privileged container launches, or use of container administration commands to access host resources. These events typically correlate with subsequent process execution on the host outside of normal container isolation."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1611",
   "technique_ja": "ホストへのエスケープ",
   "technique_en": "Escape to Host",
   "analytic_id": "AN0613",
   "detection_strategy_id": "DET0219",
   "analytic_name": "Analytic 0613",
   "platforms": "Linux",
   "log_sources": "OS API Execution (auditd:SYSCALL) | Process Creation (linux:Sysmon)",
   "log_sources_ja": "OS API実行 (auditd:SYSCALL) | プロセス生成 (linux:Sysmon)",
   "tuning": "SyscallWhitelist | TimeWindow",
   "detection_logic_en": "Detection of Linux container escape attempts via syscalls (`unshare`, `keyctl`, `mount`) or process execution outside container namespaces. Defenders may correlate unusual system calls from containerized processes with subsequent process creation on the host or modification of host resources."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1611",
   "technique_ja": "ホストへのエスケープ",
   "technique_en": "Escape to Host",
   "analytic_id": "AN0614",
   "detection_strategy_id": "DET0219",
   "analytic_name": "Analytic 0614",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "RestrictedHostDirs",
   "detection_logic_en": "Detection of Windows container escape attempts by observing processes accessing host directories, symbolic link abuse, or privilege escalation attempts. Defenders may detect anomalous process execution with access to system-level directories outside of container boundaries."
  },
  {
   "tactic_id": "TA0004",
   "tactic_ja": "権限昇格",
   "technique_id": "T1611",
   "technique_ja": "ホストへのエスケープ",
   "technique_en": "Escape to Host",
   "analytic_id": "AN0615",
   "detection_strategy_id": "DET0219",
   "analytic_name": "Analytic 0615",
   "platforms": "ESXi",
   "log_sources": "Kernel Module Load (esxi:vmkernel)",
   "log_sources_ja": "カーネルモジュール読み込み (esxi:vmkernel)",
   "tuning": "AllowedKernelModules",
   "detection_logic_en": "Detection of ESXi escape attempts by monitoring for anomalies in hypervisor logs such as unexpected VM operations, privilege escalation events, or attempts to load malicious kernel modules within the hypervisor environment."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1006",
   "technique_ja": "ボリュームへの直接アクセス",
   "technique_en": "Direct Volume Access",
   "analytic_id": "AN1193",
   "detection_strategy_id": "DET0426",
   "analytic_name": "Analytic 1193",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Process Creation (WinEventLog:Security)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Security)",
   "tuning": "TargetObjectPattern | ParentProcess | TimeWindow",
   "detection_logic_en": "Processes accessing raw logical drives (e.g., \\.\\C:) to bypass file system protections or directly manipulate data structures."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1006",
   "technique_ja": "ボリュームへの直接アクセス",
   "technique_en": "Direct Volume Access",
   "analytic_id": "AN1194",
   "detection_strategy_id": "DET0426",
   "analytic_name": "Analytic 1194",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:cli)",
   "log_sources_ja": "コマンド実行 (networkdevice:cli)",
   "tuning": "CommandScope | DeviceTypeFilter",
   "detection_logic_en": "CLI or automated utilities accessing raw device volumes or flash storage directly (e.g., via `copy flash:`, `format`, or `partition` commands)."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1014",
   "technique_ja": "ルートキット",
   "technique_en": "Rootkit",
   "analytic_id": "AN1061",
   "detection_strategy_id": "DET0377",
   "analytic_name": "Analytic 1061",
   "platforms": "Windows",
   "log_sources": "Driver Load (WinEventLog:Sysmon) | Service Creation (WinEventLog:System) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ドライバ読み込み (WinEventLog:Sysmon) | サービス作成 (WinEventLog:System) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "DriverSignatureStatus | TargetDirectory | UserContext",
   "detection_logic_en": "Unauthorized or anomalous loading of kernel-mode drivers or DLLs, concealed services, or abnormal modification of boot components indicative of rootkit activity."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1014",
   "technique_ja": "ルートキット",
   "technique_en": "Rootkit",
   "analytic_id": "AN1062",
   "detection_strategy_id": "DET0377",
   "analytic_name": "Analytic 1062",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:EXECVE) | File Modification (linux:osquery) | Module Load (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:EXECVE) | ファイル変更 (linux:osquery) | モジュール読み込み (linux:syslog)",
   "tuning": "MonitoredDirectories | ModuleNamePattern | LD_PRELOAD",
   "detection_logic_en": "Abnormal loading of kernel modules, direct tampering with /dev, /proc, or LD_PRELOAD behaviors hiding processes or files."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1014",
   "technique_ja": "ルートキット",
   "technique_en": "Rootkit",
   "analytic_id": "AN1063",
   "detection_strategy_id": "DET0377",
   "analytic_name": "Analytic 1063",
   "platforms": "macOS",
   "log_sources": "Module Load (macos:unifiedlog) | Service Creation (macos:osquery) | File Modification (fs:fsevents)",
   "log_sources_ja": "モジュール読み込み (macos:unifiedlog) | サービス作成 (macos:osquery) | ファイル変更 (fs:fsevents)",
   "tuning": "KextSignatureStatus | KextLoadOrigin | AnomalousLaunchAgent",
   "detection_logic_en": "Execution of unsigned kernel extensions (KEXTs), tampering with LaunchDaemons, or userspace hooks into system libraries."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027",
   "technique_ja": "難読化されたファイル/情報",
   "technique_en": "Obfuscated Files or Information",
   "analytic_id": "AN1064",
   "detection_strategy_id": "DET0378",
   "analytic_name": "Analytic 1064",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "PayloadEntropyThreshold | TimeWindow | SuspiciousParentProcessList",
   "detection_logic_en": "Correlates script execution or suspicious parent processes with creation or modification of encoded, compressed, or encrypted file formats (e.g., .zip, .7z, .enc) and abnormal command-line syntax or PowerShell obfuscation."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027",
   "technique_ja": "難読化されたファイル/情報",
   "technique_en": "Obfuscated Files or Information",
   "analytic_id": "AN1065",
   "detection_strategy_id": "DET0378",
   "analytic_name": "Analytic 1065",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Modification (auditd:SYSCALL) | Command Execution (linux:cli)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL) | コマンド実行 (linux:cli)",
   "tuning": "CommandRegex | SensitivePathList",
   "detection_logic_en": "Detects use of gzip, base64, tar, or openssl in scripts or commands that encode/encrypt files after file staging or system enumeration."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027",
   "technique_ja": "難読化されたファイル/情報",
   "technique_en": "Obfuscated Files or Information",
   "analytic_id": "AN1066",
   "detection_strategy_id": "DET0378",
   "analytic_name": "Analytic 1066",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Creation (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル作成 (macos:osquery)",
   "tuning": "FilenameExtensionList | UserContext",
   "detection_logic_en": "Monitors use of archive or encryption tools (zip, openssl) tied to user-scripted activity or binaries writing encoded payloads under /Users or /Volumes."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027",
   "technique_ja": "難読化されたファイル/情報",
   "technique_en": "Obfuscated Files or Information",
   "analytic_id": "AN1067",
   "detection_strategy_id": "DET0378",
   "analytic_name": "Analytic 1067",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Content (networkdevice:IDS)",
   "log_sources_ja": "ネットワークトラフィック内容 (networkdevice:IDS)",
   "tuning": "EntropyThreshold | ProtocolScope",
   "detection_logic_en": "Identifies transfer of base64, uuencoded, or high-entropy files over HTTP, FTP, or custom protocols in lateral movement or exfiltration streams."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027",
   "technique_ja": "難読化されたファイル/情報",
   "technique_en": "Obfuscated Files or Information",
   "analytic_id": "AN1068",
   "detection_strategy_id": "DET0378",
   "analytic_name": "Analytic 1068",
   "platforms": "ESXi",
   "log_sources": "File Metadata (esxi:vmkernel) | OS API Execution (esxi:hostd)",
   "log_sources_ja": "ファイルメタデータ (esxi:vmkernel) | OS API実行 (esxi:hostd)",
   "tuning": "StagingLocation | EncodedLengthThreshold",
   "detection_logic_en": "Detects encoded PowerCLI or Base64-encoded payloads staged via datastore uploads or shell access (e.g., ESXi Shell or backdoored VIBs)."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.001",
   "technique_ja": "バイナリパディング",
   "technique_en": "Binary Padding",
   "analytic_id": "AN1528",
   "detection_strategy_id": "DET0553",
   "analytic_name": "Analytic 1528",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Access (WinEventLog:Security) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイルアクセス (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "FileSizeThresholdMB | TimeWindow | UserContext",
   "detection_logic_en": "Detects the creation or execution of padded binary files (e.g., large size but minimal legitimate content) followed by process execution or lateral movement from the host."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.001",
   "technique_ja": "バイナリパディング",
   "technique_en": "Binary Padding",
   "analytic_id": "AN1529",
   "detection_strategy_id": "DET0553",
   "analytic_name": "Analytic 1529",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | File Creation (linux:osquery)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | ファイル作成 (linux:osquery)",
   "tuning": "FileSizeThresholdMB | UserContext | TimeWindow",
   "detection_logic_en": "Detects abnormal creation of binary files with significant size that are subsequently executed or accessed by non-standard users."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.001",
   "technique_ja": "バイナリパディング",
   "technique_en": "Binary Padding",
   "analytic_id": "AN1530",
   "detection_strategy_id": "DET0553",
   "analytic_name": "Analytic 1530",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (fs:fsusage)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (fs:fsusage)",
   "tuning": "FileSizeThresholdMB | TimeWindow | UserContext",
   "detection_logic_en": "Monitors for anomalous binary files written to disk with padded size and subsequent execution by user or service context."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.002",
   "technique_ja": "ソフトウェアパッキング",
   "technique_en": "Software Packing",
   "analytic_id": "AN0066",
   "detection_strategy_id": "DET0023",
   "analytic_name": "Analytic 0066",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "ParentProcessName | AllocationSizeThreshold",
   "detection_logic_en": "Detection of unpacking behavior through abnormal memory allocation, followed by executable code injection and execution from non-image sections."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.002",
   "technique_ja": "ソフトウェアパッキング",
   "technique_en": "Software Packing",
   "analytic_id": "AN0067",
   "detection_strategy_id": "DET0023",
   "analytic_name": "Analytic 0067",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Process Modification (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | プロセス変更 (auditd:SYSCALL)",
   "tuning": "EntropyThreshold | TimeWindow",
   "detection_logic_en": "Correlates ELF file execution with high-entropy writable memory segments and self-modifying code patterns."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.002",
   "technique_ja": "ソフトウェアパッキング",
   "technique_en": "Software Packing",
   "analytic_id": "AN0068",
   "detection_strategy_id": "DET0023",
   "analytic_name": "Analytic 0068",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Process Modification (macos:endpointsecurity)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | プロセス変更 (macos:endpointsecurity)",
   "tuning": "SignedBinaryContext | UserContext",
   "detection_logic_en": "Detection of packed Mach-O binaries unpacking into memory and transferring control to dynamically modified code segments."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.003",
   "technique_ja": "ステガノグラフィ",
   "technique_en": "Steganography",
   "analytic_id": "AN0331",
   "detection_strategy_id": "DET0119",
   "analytic_name": "Analytic 0331",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | File Access (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Security)",
   "tuning": "ParentProcessImage | MimeHeaderMismatchTolerance | TimeWindow",
   "detection_logic_en": "Detects execution of image viewers or PowerShell scripts accessing or decoding files with mismatched MIME headers or embedded script-like byte patterns; often correlated with suspicious parent-child process lineage and outbound connections."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.003",
   "technique_ja": "ステガノグラフィ",
   "technique_en": "Steganography",
   "analytic_id": "AN0332",
   "detection_strategy_id": "DET0119",
   "analytic_name": "Analytic 0332",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Network Connection Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (auditd:SYSCALL)",
   "tuning": "MonitoredToolsList | ScriptInterpreterMatch",
   "detection_logic_en": "Detects access to media files followed by execution of scripts (bash, Python, etc.) referencing those same files, or outbound traffic triggered shortly after file read. Correlates unusual use of tools like `steghide`, `exiftool`, or image libraries."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.003",
   "technique_ja": "ステガノグラフィ",
   "technique_en": "Steganography",
   "analytic_id": "AN0333",
   "detection_strategy_id": "DET0119",
   "analytic_name": "Analytic 0333",
   "platforms": "macOS",
   "log_sources": "File Access (macos:osquery) | Process Creation (macos:osquery) | Network Connection Creation (macos:unifiedlog)",
   "log_sources_ja": "ファイルアクセス (macos:osquery) | プロセス生成 (macos:osquery) | ネットワーク接続確立 (macos:unifiedlog)",
   "tuning": "StegoToolNamePatterns | ParentScriptSources",
   "detection_logic_en": "Detects manipulation of PNG, JPG, or GIF files by user-initiated scripts followed by script execution or exfiltration behavior, especially from `osascript`, `python`, or `bash`, in combination with LaunchAgent persistence or curl activity."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.004",
   "technique_ja": "配送後コンパイル",
   "technique_en": "Compile After Delivery",
   "analytic_id": "AN1381",
   "detection_strategy_id": "DET0501",
   "analytic_name": "Analytic 1381",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "ParentProcessName | OutputDirectoryPath | TimeWindow",
   "detection_logic_en": "Detects compilation activity using csc.exe, ilasm.exe, or msbuild.exe initiated by user-space processes outside typical development environments, followed by execution or network activity from newly written binaries."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.004",
   "technique_ja": "配送後コンパイル",
   "technique_en": "Compile After Delivery",
   "analytic_id": "AN1382",
   "detection_strategy_id": "DET0501",
   "analytic_name": "Analytic 1382",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Creation (auditd:SYSCALL) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル作成 (auditd:SYSCALL) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "CompilerBinaryPath | FilePermissionProfile",
   "detection_logic_en": "Detects GCC or Clang invoked on suspicious file paths (e.g., /tmp/, ~/Downloads) with output to executable binaries, followed by execution or outbound traffic from these binaries."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.004",
   "technique_ja": "配送後コンパイル",
   "technique_en": "Compile After Delivery",
   "analytic_id": "AN1383",
   "detection_strategy_id": "DET0501",
   "analytic_name": "Analytic 1383",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (macos:osquery) | Network Connection Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:osquery) | ネットワーク接続確立 (macos:unifiedlog)",
   "tuning": "CompilerInvocationPattern | OutputBinaryPath",
   "detection_logic_en": "Detects non-standard compilation activity via Xcode CLI tools or bundled GCC/MONO packages writing new executable files and executing them outside dev environments (e.g., user Downloads folder)."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.005",
   "technique_ja": "ツールからの指標除去",
   "technique_en": "Indicator Removal from Tools",
   "analytic_id": "AN0540",
   "detection_strategy_id": "DET0189",
   "analytic_name": "Analytic 0540",
   "platforms": "Windows",
   "log_sources": "Application Log Content (WinEventLog:Application) | Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "アプリケーションログ内容 (WinEventLog:Application) | プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "AVAlertMessage | TimeWindow | FilenameSimilarityThreshold",
   "detection_logic_en": "Detection of known tools or malware flagged by antivirus, followed by a near-term drop of a similar binary with modified signature and resumed activity (execution, C2, or persistence)."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.005",
   "technique_ja": "ツールからの指標除去",
   "technique_en": "Indicator Removal from Tools",
   "analytic_id": "AN0541",
   "detection_strategy_id": "DET0189",
   "analytic_name": "Analytic 0541",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Process Modification (auditd:SYSCALL) | File Metadata (linux:osquery) | Application Log Content (EDR:detection)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | プロセス変更 (auditd:SYSCALL) | ファイルメタデータ (linux:osquery) | アプリケーションログ内容 (EDR:detection)",
   "tuning": "PathWatchlist | ProcessAncestryDepth",
   "detection_logic_en": "Detection of anti-malware quarantining or flagging a tool, followed by a new binary written to disk with a similar function or name and a resumed process chain."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.005",
   "technique_ja": "ツールからの指標除去",
   "technique_en": "Indicator Removal from Tools",
   "analytic_id": "AN0542",
   "detection_strategy_id": "DET0189",
   "analytic_name": "Analytic 0542",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | File Metadata (macos:osquery)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | ファイルメタデータ (macos:osquery)",
   "tuning": "BinaryChangeThreshold | UserContext",
   "detection_logic_en": "Detection of XProtect or AV quarantining a known tool, followed by modification (file size, hash, string) and subsequent re-execution by the same or related user."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.006",
   "technique_ja": "HTMLスマグリング",
   "technique_en": "HTML Smuggling",
   "analytic_id": "AN0872",
   "detection_strategy_id": "DET0313",
   "analytic_name": "Analytic 0872",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | File Metadata (EDR:detection) | File Metadata (WinEventLog:Sysmon) | Network Traffic Content (Network Traffic)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ファイルメタデータ (EDR:detection) | ファイルメタデータ (WinEventLog:Sysmon) | ネットワークトラフィック内容 (Network Traffic)",
   "tuning": "TimeWindow | DroppedFileExtensionWatchlist | ParentProcessName",
   "detection_logic_en": "Detection of browser-based or email client-driven file creation (often from temp directories) following navigation to or execution of HTML files containing JavaScript Blob APIs or base64 Data URLs, with follow-on execution of the dropped payload. Leveraging Sysmon EventID 15 to inspect Zone.Identifier ADS for HostUrl/ReferrerUrl indicators (e.g., HostUrl=about:internet). Optional: absence of a large HTTP download record for the same URL/client in proxy logs (suggests local assembly)"
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.006",
   "technique_ja": "HTMLスマグリング",
   "technique_en": "HTML Smuggling",
   "analytic_id": "AN0873",
   "detection_strategy_id": "DET0313",
   "analytic_name": "Analytic 0873",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Creation (linux:osquery)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル作成 (linux:osquery)",
   "tuning": "DownloadPathRegex | ExecutableTriggerWindow",
   "detection_logic_en": "Detection of browser-based downloads from HTML sources that trigger file creation in temp or user directories followed by execution of new files within short timeframes and suspicious parent-child lineage."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.006",
   "technique_ja": "HTMLスマグリング",
   "technique_en": "HTML Smuggling",
   "analytic_id": "AN0874",
   "detection_strategy_id": "DET0313",
   "analytic_name": "Analytic 0874",
   "platforms": "macOS",
   "log_sources": "File Creation (macos:unifiedlog) | Process Creation (macos:osquery) | File Metadata (gatekeeper/quarantine database)",
   "log_sources_ja": "ファイル作成 (macos:unifiedlog) | プロセス生成 (macos:osquery) | ファイルメタデータ (gatekeeper/quarantine database)",
   "tuning": "QuarantineFlagCheck | BlobKeywordAlertList",
   "detection_logic_en": "Detection of HTML-based downloads via Safari/Chrome that create obfuscated files (e.g., .zip, .app, .js) in user directories and are followed by suspicious executions from preview or launch services."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.007",
   "technique_ja": "動的API解決",
   "technique_en": "Dynamic API Resolution",
   "analytic_id": "AN0250",
   "detection_strategy_id": "DET0091",
   "analytic_name": "Analytic 0250",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Kernel-Process)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Kernel-Process)",
   "tuning": "APILoadWithoutImport | TimeWindow | EntropyThreshold | StackTraceFilter",
   "detection_logic_en": "Behavioral chain involving suspicious use of GetProcAddress and LoadLibrary following memory allocation and manual mapping, often paired with low entropy strings, abnormal API use without static import tables, or delayed module load behaviors."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.008",
   "technique_ja": "ストリップ済みペイロード",
   "technique_en": "Stripped Payloads",
   "analytic_id": "AN0055",
   "detection_strategy_id": "DET0019",
   "analytic_name": "Analytic 0055",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | File Metadata (EDR:file)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ファイルメタデータ (EDR:file)",
   "tuning": "EntropyThreshold | ParentProcessName | TimeWindow",
   "detection_logic_en": "Executable or script payloads lacking symbol information and readable strings that are created or dropped by unusual or short-lived processes."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.008",
   "technique_ja": "ストリップ済みペイロード",
   "technique_en": "Stripped Payloads",
   "analytic_id": "AN0056",
   "detection_strategy_id": "DET0019",
   "analytic_name": "Analytic 0056",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:EXECVE) | File Modification (auditd:SYSCALL) | File Metadata (linux:osquery)",
   "log_sources_ja": "プロセス生成 (auditd:EXECVE) | ファイル変更 (auditd:SYSCALL) | ファイルメタデータ (linux:osquery)",
   "tuning": "StripFlags | DirectoryScope | FileSizeRange",
   "detection_logic_en": "Executable or binary files created without symbol tables or with stripped sections, especially by non-user shell processes or compilers invoked outside standard dev paths."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.008",
   "technique_ja": "ストリップ済みペイロード",
   "technique_en": "Stripped Payloads",
   "analytic_id": "AN0057",
   "detection_strategy_id": "DET0019",
   "analytic_name": "Analytic 0057",
   "platforms": "macOS",
   "log_sources": "File Creation (macos:unifiedlog) | Process Creation (macos:endpointsecurity) | File Metadata (macos:osquery)",
   "log_sources_ja": "ファイル作成 (macos:unifiedlog) | プロセス生成 (macos:endpointsecurity) | ファイルメタデータ (macos:osquery)",
   "tuning": "RunOnlyFlag | ParentProcess | SignedStatus",
   "detection_logic_en": "Creation of run-only AppleScripts or Mach-O binaries lacking symbol table and string references, especially when dropped by user space scripting engines or staging apps."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.008",
   "technique_ja": "ストリップ済みペイロード",
   "technique_en": "Stripped Payloads",
   "analytic_id": "AN0058",
   "detection_strategy_id": "DET0019",
   "analytic_name": "Analytic 0058",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "MIMEType | PayloadSize | TransferEncoding",
   "detection_logic_en": "Inbound binary payloads transferred over HTTP/S with compressed or encoded headers, lacking signature markers or metadata indicative of compiler/toolchain."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.009",
   "technique_ja": "埋め込みペイロード",
   "technique_en": "Embedded Payloads",
   "analytic_id": "AN0599",
   "detection_strategy_id": "DET0214",
   "analytic_name": "Analytic 0599",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | File Metadata (EDR:file)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ファイルメタデータ (EDR:file)",
   "tuning": "OverlaySizeThreshold | ProcessTreeDepth | TimeWindow",
   "detection_logic_en": "Detection of executables or scripts containing hidden embedded resources or secondary payloads, often with anomalies in file size vs. functionality or dropped child binaries."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.009",
   "technique_ja": "埋め込みペイロード",
   "technique_en": "Embedded Payloads",
   "analytic_id": "AN0600",
   "detection_strategy_id": "DET0214",
   "analytic_name": "Analytic 0600",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | File Metadata (linux:osquery) | File Access (ebpf:syscalls)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | ファイルメタデータ (linux:osquery) | ファイルアクセス (ebpf:syscalls)",
   "tuning": "FileSectionCount | ScriptLength | ExtractedFileCount",
   "detection_logic_en": "Detection of shell scripts, ELF binaries, or archives containing embedded secondary payloads, self-extracting components, or unusual compression behavior during runtime."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.009",
   "technique_ja": "埋め込みペイロード",
   "technique_en": "Embedded Payloads",
   "analytic_id": "AN0601",
   "detection_strategy_id": "DET0214",
   "analytic_name": "Analytic 0601",
   "platforms": "macOS",
   "log_sources": "File Creation (macos:unifiedlog) | Process Creation (macos:endpointsecurity) | File Metadata (macos:osquery)",
   "log_sources_ja": "ファイル作成 (macos:unifiedlog) | プロセス生成 (macos:endpointsecurity) | ファイルメタデータ (macos:osquery)",
   "tuning": "ScriptFormatType | DroppedBinaryCount | ParentProcessName",
   "detection_logic_en": "Detection of Mach-O binaries or AppleScripts that contain nested, encoded, or run-only embedded payloads dropped at runtime."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.010",
   "technique_ja": "コマンド難読化",
   "technique_en": "Command Obfuscation",
   "analytic_id": "AN1394",
   "detection_strategy_id": "DET0505",
   "analytic_name": "Analytic 1394",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security)",
   "tuning": "CommandLineEntropyThreshold | SuspiciousCharacterCount | TimeWindow",
   "detection_logic_en": "Detection of command-line activity exhibiting syntactic obfuscation patterns, such as excessive escape characters, base64 encoding, command concatenation, or outlier command length and entropy."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.010",
   "technique_ja": "コマンド難読化",
   "technique_en": "Command Obfuscation",
   "analytic_id": "AN1395",
   "detection_strategy_id": "DET0505",
   "analytic_name": "Analytic 1395",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Command Execution (linux:osquery)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | コマンド実行 (linux:osquery)",
   "tuning": "CommandLineTokenCount | EncodedExecRegex | GlobPatternAnomalies",
   "detection_logic_en": "Detection of shell commands that leverage encoded execution, command chaining, excessive piping, or unusual token patterns indicative of obfuscation."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.010",
   "technique_ja": "コマンド難読化",
   "technique_en": "Command Obfuscation",
   "analytic_id": "AN1396",
   "detection_strategy_id": "DET0505",
   "analytic_name": "Analytic 1396",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Process Creation (macos:endpointsecurity)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | プロセス生成 (macos:endpointsecurity)",
   "tuning": "InterpreterParentFilter | ScriptEntropyThreshold | ArgumentLengthDeviation",
   "detection_logic_en": "Detection of obfuscated commands via shell, osascript, or AppleScript interpreters using unusual tokens, encoding, variable substitution, or runtime string reconstruction."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.011",
   "technique_ja": "ファイルレスストレージ",
   "technique_en": "Fileless Storage",
   "analytic_id": "AN0973",
   "detection_strategy_id": "DET0344",
   "analytic_name": "Analytic 0973",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | WMI Creation (WinEventLog:Application)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | WMI作成 (WinEventLog:Application)",
   "tuning": "RegistryPathFilter | PayloadEntropyThreshold | TimeWindow",
   "detection_logic_en": "Detects abuse of fileless storage mechanisms such as Registry keys, WMI classes, and Event Logs used to stage payloads, scripts, or encoded content outside traditional files."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.011",
   "technique_ja": "ファイルレスストレージ",
   "technique_en": "Fileless Storage",
   "analytic_id": "AN0974",
   "detection_strategy_id": "DET0344",
   "analytic_name": "Analytic 0974",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:SYSCALL) | File Metadata (linux:osquery)",
   "log_sources_ja": "ファイル作成 (auditd:SYSCALL) | ファイルメタデータ (linux:osquery)",
   "tuning": "PathPrefix | FilenameRegex | ExecCorrelationWindow",
   "detection_logic_en": "Detects usage of shared memory directories (/dev/shm, /run/shm) for temporary storage of obfuscated, encoded, or executable data without persistence to disk."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.012",
   "technique_ja": "LNKアイコンスマグリング",
   "technique_en": "LNK Icon Smuggling",
   "analytic_id": "AN1134",
   "detection_strategy_id": "DET0405",
   "analytic_name": "Analytic 1134",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "ParentProcessName | DestinationIP | TimeWindow | FileExtension",
   "detection_logic_en": "Correlates LNK file execution with embedded resource extraction or suspicious network activity following initial launch, often leading to payload delivery via disguised icons."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.013",
   "technique_ja": "暗号化/エンコードファイル",
   "technique_en": "Encrypted/Encoded File",
   "analytic_id": "AN0237",
   "detection_strategy_id": "DET0087",
   "analytic_name": "Analytic 0237",
   "platforms": "Windows",
   "log_sources": "Module Load (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Process Creation (WinEventLog:Security)",
   "log_sources_ja": "モジュール読み込み (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Security)",
   "tuning": "Image | CommandLine | TimeWindow",
   "detection_logic_en": "Detection of processes that load or decode encrypted/encoded files in memory and subsequently execute or inject them, indicating payload unpacking or memory-resident malware."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.013",
   "technique_ja": "暗号化/エンコードファイル",
   "technique_en": "Encrypted/Encoded File",
   "analytic_id": "AN0238",
   "detection_strategy_id": "DET0087",
   "analytic_name": "Analytic 0238",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (linux:Sysmon)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (linux:Sysmon)",
   "tuning": "UserContext | ProcessLineage | TimeWindow",
   "detection_logic_en": "Detection of suspicious use of shell utilities or scripts that decode or decrypt a payload and execute it without writing to disk."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.013",
   "technique_ja": "暗号化/エンコードファイル",
   "technique_en": "Encrypted/Encoded File",
   "analytic_id": "AN0239",
   "detection_strategy_id": "DET0087",
   "analytic_name": "Analytic 0239",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Process Creation (macos:endpointsecurity) | Process Modification (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | プロセス生成 (macos:endpointsecurity) | プロセス変更 (macos:unifiedlog)",
   "tuning": "ScriptContent | ExecutionChain | UserContext",
   "detection_logic_en": "Detection of encoded payloads being decoded and executed in-memory using scripting tools or third-party decoders."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.014",
   "technique_ja": "ポリモーフィックコード",
   "technique_en": "Polymorphic Code",
   "analytic_id": "AN0919",
   "detection_strategy_id": "DET0324",
   "analytic_name": "Analytic 0919",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "EntropyThreshold | TimeWindow | ParentProcessPatterns",
   "detection_logic_en": "Identifies self-modifying executables that exhibit changes in binary hash, entropy, or memory sections during or between executions—often tied to dynamic unpacking or decryption behaviors."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.014",
   "technique_ja": "ポリモーフィックコード",
   "technique_en": "Polymorphic Code",
   "analytic_id": "AN0920",
   "detection_strategy_id": "DET0324",
   "analytic_name": "Analytic 0920",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Module Load (auditd:SYSCALL) | File Modification (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | モジュール読み込み (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL)",
   "tuning": "WriteExecThreshold | FileEntropyDeviation | ExecutionFrequency",
   "detection_logic_en": "Detects files or processes where execution results in frequent re-creation or modification of ELF binaries or interpreter scripts, often using chmod + execve with abnormal entropy."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.014",
   "technique_ja": "ポリモーフィックコード",
   "technique_en": "Polymorphic Code",
   "analytic_id": "AN0921",
   "detection_strategy_id": "DET0324",
   "analytic_name": "Analytic 0921",
   "platforms": "macOS",
   "log_sources": "Process Metadata (macos:unifiedlog) | File Creation (fs:fsusage) | Process Creation (macos:endpointsecurity) | Process Modification (macos:endpointsecurity)",
   "log_sources_ja": "プロセスメタデータ (macos:unifiedlog) | ファイル作成 (fs:fsusage) | プロセス生成 (macos:endpointsecurity) | プロセス変更 (macos:endpointsecurity)",
   "tuning": "ScriptEnginePatterns | MachOEntropyThreshold | SignedBinaryChangeRate",
   "detection_logic_en": "Tracks modification of executables or interpreter payloads (e.g., Mach-O, dylib) that mutate across runs—using scripting engines, JIT compilers, or side-loaded plugins."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.015",
   "technique_ja": "圧縮",
   "technique_en": "Compression",
   "analytic_id": "AN0782",
   "detection_strategy_id": "DET0281",
   "analytic_name": "Analytic 0782",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "CompressedFileType | SFXExecutionDelay | UserContext",
   "detection_logic_en": "Monitors for compression tool usage (e.g., 7zip, WinRAR, MakeCab) that follows or precedes file modification, suspicious file types (e.g., .exe, .dll) being compressed, or dropped from self-extracting archives followed by immediate execution."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.015",
   "technique_ja": "圧縮",
   "technique_en": "Compression",
   "analytic_id": "AN0783",
   "detection_strategy_id": "DET0281",
   "analytic_name": "Analytic 0783",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Creation (auditd:SYSCALL) | File Access (auditd:SYSCALL) | File Modification (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル作成 (auditd:SYSCALL) | ファイルアクセス (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL)",
   "tuning": "PathRegex | CompressionToolPatterns | ExecutionAfterUnpackWindow",
   "detection_logic_en": "Detects sequential command-line compression utilities (e.g., gzip, tar, zip, 7z) followed by execution of unpacked files, especially in temp directories or under non-standard locations like /dev/shm or /tmp with ELF binaries."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.015",
   "technique_ja": "圧縮",
   "technique_en": "Compression",
   "analytic_id": "AN0784",
   "detection_strategy_id": "DET0281",
   "analytic_name": "Analytic 0784",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Metadata (macos:unifiedlog) | File Creation (fs:fsusage)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイルメタデータ (macos:unifiedlog) | ファイル作成 (fs:fsusage)",
   "tuning": "DecompressionPathMatch | ToolBinaryNames | FollowOnExecutionDelta",
   "detection_logic_en": "Identifies archive utilities (e.g., ditto, unzip, xar, pkgutil) used to extract payloads to non-standard paths, then correlates with execution or file permission changes (e.g., `chmod +x`) and process spawns from decompressed location."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.016",
   "technique_ja": "ジャンクコード挿入",
   "technique_en": "Junk Code Insertion",
   "analytic_id": "AN0913",
   "detection_strategy_id": "DET0322",
   "analytic_name": "Analytic 0913",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "NOPThreshold | ExecutableSizeThreshold | TimeWindow",
   "detection_logic_en": "Detects the presence of executables with high NOP padding, unusually large binary size for their function, and follow-on execution or memory injection from such files, especially when originating from temp or user-space paths."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.016",
   "technique_ja": "ジャンクコード挿入",
   "technique_en": "Junk Code Insertion",
   "analytic_id": "AN0914",
   "detection_strategy_id": "DET0322",
   "analytic_name": "Analytic 0914",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Process Modification (auditd:SYSCALL)",
   "log_sources_ja": "ファイル作成 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | プロセス変更 (auditd:SYSCALL)",
   "tuning": "BinarySizeThreshold | MemoryWriteTargets | ExecutionAfterWriteWindow",
   "detection_logic_en": "Detects ELF binaries written to disk that demonstrate anomalous file size or entropy, quickly followed by execution or memory region writes into remote processes (e.g., using ptrace)."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.016",
   "technique_ja": "ジャンクコード挿入",
   "technique_en": "Junk Code Insertion",
   "analytic_id": "AN0915",
   "detection_strategy_id": "DET0322",
   "analytic_name": "Analytic 0915",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:endpointsecurity) | Process Modification (macos:endpointsecurity) | Process Access (macos:endpointsecurity)",
   "log_sources_ja": "プロセス生成 (macos:endpointsecurity) | プロセス変更 (macos:endpointsecurity) | プロセスアクセス (macos:endpointsecurity)",
   "tuning": "TempFilePaths | MachOPaddingThreshold | FollowOnPrivilegeEscalation",
   "detection_logic_en": "Identifies Mach-O binaries dropped into temporary directories with abnormally high binary size or padding patterns, followed by privilege escalation, `exec`, or memory mapping of other processes."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.017",
   "technique_ja": "SVGスマグリング",
   "technique_en": "SVG Smuggling",
   "analytic_id": "AN1407",
   "detection_strategy_id": "DET0510",
   "analytic_name": "Analytic 1407",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | ParentProcessWhitelist | FileExtensionPattern",
   "detection_logic_en": "Detects suspicious SVG file creation or download events followed by script engine execution (e.g., wscript.exe, mshta.exe, rundll32.exe), network callbacks, or browser-based credential collection."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.017",
   "technique_ja": "SVGスマグリング",
   "technique_en": "SVG Smuggling",
   "analytic_id": "AN1408",
   "detection_strategy_id": "DET0510",
   "analytic_name": "Analytic 1408",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TargetPaths | ExecutionContext | NetworkDestinations",
   "detection_logic_en": "Detects downloaded SVG files followed by execution of browser processes or tools like xdg-open, and rapid follow-on network connections or process spawns to interpreters like python or bash."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.017",
   "technique_ja": "SVGスマグリング",
   "technique_en": "SVG Smuggling",
   "analytic_id": "AN1409",
   "detection_strategy_id": "DET0510",
   "analytic_name": "Analytic 1409",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:endpointsecurity) | Network Traffic Content (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:endpointsecurity) | ネットワークトラフィック内容 (macos:unifiedlog)",
   "tuning": "ScriptEngines | UserContext | EmbeddedContentIndicators",
   "detection_logic_en": "Detects SVGs downloaded via browser that invoke AppleScript, osascript, or JavaScriptCore processes, followed by network egress or file drop to LaunchAgents or ~/Library."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.018",
   "technique_ja": "不可視Unicode",
   "technique_en": "Invisible Unicode",
   "analytic_id": "AN2063",
   "detection_strategy_id": "DET0920",
   "analytic_name": "Analytic 2063",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Security) | Script Execution (WinEventLog:PowerShell) | File Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Security) | スクリプト実行 (WinEventLog:PowerShell) | ファイル作成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "AllocationSizeThreshold | ExecutionContext | UnicodeDensityThreshold",
   "detection_logic_en": "Detection identifies execution of scripts or files that appear visually benign (low printable character ratio) but result in runtime decoding, dynamic evaluation, and subsequent process or network activity. Correlation links script execution with abnormal Unicode density and follow-on behavior such as child process creation or outbound connections."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.018",
   "technique_ja": "不可視Unicode",
   "technique_en": "Invisible Unicode",
   "analytic_id": "AN2064",
   "detection_strategy_id": "DET0920",
   "analytic_name": "Analytic 2064",
   "platforms": "Linux",
   "log_sources": "File Metadata (auditd:SYSCALL) | Command Execution (auditd:EXECVE)",
   "log_sources_ja": "ファイルメタデータ (auditd:SYSCALL) | コマンド実行 (auditd:EXECVE)",
   "tuning": "DecodeUtility | EntropyThreshold",
   "detection_logic_en": "Detection identifies execution of scripts containing high concentrations of invisible Unicode characters followed by decoding or interpretation behaviors (e.g., base64 decode, eval) and subsequent process or network activity. Emphasis is placed on mismatch between file entropy/structure and execution output."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1027.018",
   "technique_ja": "不可視Unicode",
   "technique_en": "Invisible Unicode",
   "analytic_id": "AN2065",
   "detection_strategy_id": "DET0920",
   "analytic_name": "Analytic 2065",
   "platforms": "macOS",
   "log_sources": "Network Connection Creation (NSM:Flow) | Command Execution (macos:unifiedlog) | File Access (macOS:unifiedlog)",
   "log_sources_ja": "ネットワーク接続確立 (NSM:Flow) | コマンド実行 (macos:unifiedlog) | ファイルアクセス (macOS:unifiedlog)",
   "tuning": "ExecutionContext | UnicodeCharacterSet",
   "detection_logic_en": "Detection identifies execution of scripts or applications containing invisible Unicode payloads reconstructed at runtime, correlated with abnormal AppleScript, JavaScript for Automation, or shell execution and subsequent process or network behavior inconsistent with visible file content. "
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036",
   "technique_ja": "偽装（マスカレード）",
   "technique_en": "Masquerading",
   "analytic_id": "AN0355",
   "detection_strategy_id": "DET0127",
   "analytic_name": "Analytic 0355",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Service Creation (WinEventLog:System)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | サービス作成 (WinEventLog:System)",
   "tuning": "OriginalFilenameMismatch | KnownSystemUtilityPaths | TimeWindow",
   "detection_logic_en": "Adversary renames LOLBINs or deploys binaries with spoofed file names, internal PE metadata, or misleading icons to appear legitimate. File creation is followed by execution or service registration inconsistent with known usage."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036",
   "technique_ja": "偽装（マスカレード）",
   "technique_en": "Masquerading",
   "analytic_id": "AN0356",
   "detection_strategy_id": "DET0127",
   "analytic_name": "Analytic 0356",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Modification (linux:syslog) | File Metadata (linux:osquery)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル変更 (linux:syslog) | ファイルメタデータ (linux:osquery)",
   "tuning": "DropLocationPattern | FilenameAnomalies | ExecutionDelayWindow",
   "detection_logic_en": "Adversary drops renamed binaries in uncommon directories (e.g., /tmp, /dev/shm) or uses special characters in names (e.g., trailing space, Unicode RLO). Execution or cronjob registration follows shortly after file drop."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036",
   "technique_ja": "偽装（マスカレード）",
   "technique_en": "Masquerading",
   "analytic_id": "AN0357",
   "detection_strategy_id": "DET0127",
   "analytic_name": "Analytic 0357",
   "platforms": "macOS",
   "log_sources": "Process Metadata (macos:unifiedlog) | Process Creation (macos:endpointsecurity) | File Metadata (fs:fileevents)",
   "log_sources_ja": "プロセスメタデータ (macos:unifiedlog) | プロセス生成 (macos:endpointsecurity) | ファイルメタデータ (fs:fileevents)",
   "tuning": "InfoPlistDiscrepancy | LaunchAgentPath | ExecutionTrigger",
   "detection_logic_en": "Adversary creates disguised launch daemons or apps with misleading names and bundle metadata (e.g., Info.plist values inconsistent with binary path or icon). Launch is correlated with user logon or persistence setup."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036",
   "technique_ja": "偽装（マスカレード）",
   "technique_en": "Masquerading",
   "analytic_id": "AN0358",
   "detection_strategy_id": "DET0127",
   "analytic_name": "Analytic 0358",
   "platforms": "Containers",
   "log_sources": "Process Creation (containerd:runtime) | Image Metadata (docker:events) | File Modification (ebpf:syscalls)",
   "log_sources_ja": "プロセス生成 (containerd:runtime) | イメージメタデータ (docker:events) | ファイル変更 (ebpf:syscalls)",
   "tuning": "ImageLabelMismatch | StartupScriptLocation | ProcessNamePattern",
   "detection_logic_en": "Adversary uses renamed container images, injects files into containers with misleading names or metadata (e.g., renamed system binaries), and executes them during startup or scheduled jobs."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036",
   "technique_ja": "偽装（マスカレード）",
   "technique_en": "Masquerading",
   "analytic_id": "AN0359",
   "detection_strategy_id": "DET0127",
   "analytic_name": "Analytic 0359",
   "platforms": "ESXi",
   "log_sources": "Service Metadata (esxi:hostd) | Command Execution (esxi:shell)",
   "log_sources_ja": "サービスメタデータ (esxi:hostd) | コマンド実行 (esxi:shell)",
   "tuning": "ServiceNameBaseline | ScriptFilePath | ExecutionContext",
   "detection_logic_en": "Adversary places scripts or binaries with misleading names in /etc/rc.local.d or /var/spool/cron, or registers services with legitimate-sounding names not present in default ESXi builds."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.001",
   "technique_ja": "無効なコード署名",
   "technique_en": "Invalid Code Signature",
   "analytic_id": "AN0089",
   "detection_strategy_id": "DET0031",
   "analytic_name": "Analytic 0089",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Windows Defender) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Windows Defender) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "SignatureValidationResult | ParentProcessName | TimeWindow",
   "detection_logic_en": "Execution of binaries with invalid digital signatures, where metadata claims code is signed but validation fails. Behavior is often correlated with suspicious parent processes or unexpected execution paths."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.001",
   "technique_ja": "無効なコード署名",
   "technique_en": "Invalid Code Signature",
   "analytic_id": "AN0090",
   "detection_strategy_id": "DET0031",
   "analytic_name": "Analytic 0090",
   "platforms": "macOS",
   "log_sources": "File Metadata (macos:unifiedlog) | Process Creation (macos:endpointsecurity) | File Modification (fs:fileevents)",
   "log_sources_ja": "ファイルメタデータ (macos:unifiedlog) | プロセス生成 (macos:endpointsecurity) | ファイル変更 (fs:fileevents)",
   "tuning": "CodeSigningStatus | UserContext | ExecutablePathPrefix",
   "detection_logic_en": "Binaries or applications executed with tampered or unverifiable code signatures. Often tied to Gatekeeper bypasses, App Translocation, or use of unsigned launch daemons by untrusted users."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.002",
   "technique_ja": "右から左への上書き(RLO)",
   "technique_en": "Right-to-Left Override",
   "analytic_id": "AN1461",
   "detection_strategy_id": "DET0527",
   "analytic_name": "Analytic 1461",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | File Metadata (WinEventLog:Windows Defender)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | ファイルメタデータ (WinEventLog:Windows Defender)",
   "tuning": "FilenamePattern | ExecutionContext | TimeWindow",
   "detection_logic_en": "Execution of files containing right-to-left override characters (U+202E) to masquerade true file extensions. Often found in phishing payloads or file downloads."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.002",
   "technique_ja": "右から左への上書き(RLO)",
   "technique_en": "Right-to-Left Override",
   "analytic_id": "AN1462",
   "detection_strategy_id": "DET0527",
   "analytic_name": "Analytic 1462",
   "platforms": "macOS",
   "log_sources": "File Metadata (macos:unifiedlog) | Process Creation (macos:endpointsecurity) | File Access (fs:quarantine)",
   "log_sources_ja": "ファイルメタデータ (macos:unifiedlog) | プロセス生成 (macos:endpointsecurity) | ファイルアクセス (fs:quarantine)",
   "tuning": "FilenameDisplay | GatekeeperBypassFlag | UserContext",
   "detection_logic_en": "Execution of files with reversed filename extensions using Unicode RTLO character. Frequently used to deceive Gatekeeper and users in Safari or Mail-based phishing."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.002",
   "technique_ja": "右から左への上書き(RLO)",
   "technique_en": "Right-to-Left Override",
   "analytic_id": "AN1463",
   "detection_strategy_id": "DET0527",
   "analytic_name": "Analytic 1463",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Metadata (linux:osquery) | File Access (desktop:file_manager)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルメタデータ (linux:osquery) | ファイルアクセス (desktop:file_manager)",
   "tuning": "ExtensionMismatch | ProcessLineage | FilenameEntropy",
   "detection_logic_en": "Execution of user-downloaded or created scripts with hidden extensions due to RTLO character insertion in filename, often present in desktop environments or phishing campaigns."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.003",
   "technique_ja": "正規ユーティリティのリネーム",
   "technique_en": "Rename Legitimate Utilities",
   "analytic_id": "AN0012",
   "detection_strategy_id": "DET0005",
   "analytic_name": "Analytic 0012",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Command Execution (EDR:AMSI)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | コマンド実行 (EDR:AMSI)",
   "tuning": "ImagePath | PEInternalNameMismatch | CommandLinePattern",
   "detection_logic_en": "Execution of binaries where the on-disk filename does not match PE metadata such as OriginalFilename or InternalName. Often observed with renamed LOLBAS or system binaries like rundll32, powershell, or psexec."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.003",
   "technique_ja": "正規ユーティリティのリネーム",
   "technique_en": "Rename Legitimate Utilities",
   "analytic_id": "AN0013",
   "detection_strategy_id": "DET0005",
   "analytic_name": "Analytic 0013",
   "platforms": "macOS",
   "log_sources": "Process Metadata (macos:unifiedlog) | Process Creation (macos:endpointsecurity) | File Modification (fs:fileevents)",
   "log_sources_ja": "プロセスメタデータ (macos:unifiedlog) | プロセス生成 (macos:endpointsecurity) | ファイル変更 (fs:fileevents)",
   "tuning": "PathDeviation | BinaryHashReputation | UserRole",
   "detection_logic_en": "Execution of renamed or relocated native macOS utilities with uncommon names or non-default paths (e.g., renamed `osascript`, `bash`, or `curl`)."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.003",
   "technique_ja": "正規ユーティリティのリネーム",
   "technique_en": "Rename Legitimate Utilities",
   "analytic_id": "AN0014",
   "detection_strategy_id": "DET0005",
   "analytic_name": "Analytic 0014",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Metadata (linux:osquery) | Command Execution (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルメタデータ (linux:osquery) | コマンド実行 (linux:syslog)",
   "tuning": "ExecutionPath | ParentProcessContext | TimeWindow",
   "detection_logic_en": "Execution of renamed common utilities (e.g., `bash`, `nc`, `python`, `sh`) from atypical directories or with names intended to deceive defenders or EDRs."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.004",
   "technique_ja": "タスク/サービスの偽装",
   "technique_en": "Masquerade Task or Service",
   "analytic_id": "AN0324",
   "detection_strategy_id": "DET0117",
   "analytic_name": "Analytic 0324",
   "platforms": "Windows",
   "log_sources": "Service Creation (WinEventLog:System) | Scheduled Job Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "サービス作成 (WinEventLog:System) | スケジュールジョブ作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TaskNameSimilarityThreshold | BinaryReputationScore | ExecutionContext",
   "detection_logic_en": "Creation or modification of Windows services or scheduled tasks with names or descriptions mimicking legitimate entries, followed by anomalous execution of untrusted binaries or LOLBAS."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.004",
   "technique_ja": "タスク/サービスの偽装",
   "technique_en": "Masquerade Task or Service",
   "analytic_id": "AN0325",
   "detection_strategy_id": "DET0117",
   "analytic_name": "Analytic 0325",
   "platforms": "Linux",
   "log_sources": "Scheduled Job Modification (auditd:CONFIG_CHANGE) | Service Metadata (linux:osquery) | Scheduled Job Metadata (linux:cron)",
   "log_sources_ja": "スケジュールジョブ変更 (auditd:CONFIG_CHANGE) | サービスメタデータ (linux:osquery) | スケジュールジョブメタデータ (linux:cron)",
   "tuning": "UnitFilePath | ServiceNameDeviation | ExecStartPath",
   "detection_logic_en": "Creation or modification of `systemd` service units or cron jobs using deceptive naming and untrusted command paths, often followed by lateral network activity or privilege escalation."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.004",
   "technique_ja": "タスク/サービスの偽装",
   "technique_en": "Masquerade Task or Service",
   "analytic_id": "AN0326",
   "detection_strategy_id": "DET0117",
   "analytic_name": "Analytic 0326",
   "platforms": "macOS",
   "log_sources": "Scheduled Job Metadata (fs:fileevents) | Process Creation (macos:endpointsecurity) | Service Metadata (macos:unifiedlog)",
   "log_sources_ja": "スケジュールジョブメタデータ (fs:fileevents) | プロセス生成 (macos:endpointsecurity) | サービスメタデータ (macos:unifiedlog)",
   "tuning": "PlistLabelSimilarity | UnsignedBinaryExecution | UserContext",
   "detection_logic_en": "Creation of LaunchAgents or LaunchDaemons with names resembling known system services but executing non-Apple signed code or scripts."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.005",
   "technique_ja": "正規リソース名/場所への一致",
   "technique_en": "Match Legitimate Resource Name or Location",
   "analytic_id": "AN0983",
   "detection_strategy_id": "DET0347",
   "analytic_name": "Analytic 0983",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "trusted_directory_list | process_baseline_age",
   "detection_logic_en": "Detects processes or binaries executed from trusted directories (e.g., System32) or using trusted names (e.g., svchost.exe) where the metadata, hash, or parent process does not align with legitimate activity patterns."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.005",
   "technique_ja": "正規リソース名/場所への一致",
   "technique_en": "Match Legitimate Resource Name or Location",
   "analytic_id": "AN0984",
   "detection_strategy_id": "DET0347",
   "analytic_name": "Analytic 0984",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Access (auditd:SYSCALL) | Process Modification (auditd:SYSCALL) | File Metadata (linux:osquery)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルアクセス (auditd:SYSCALL) | プロセス変更 (auditd:SYSCALL) | ファイルメタデータ (linux:osquery)",
   "tuning": "monitored_paths | hash_validation_window",
   "detection_logic_en": "Detects renamed binaries or scripts placed into trusted paths like /usr/bin or /lib with mismatched metadata or unexpected creation/modification times."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.005",
   "technique_ja": "正規リソース名/場所への一致",
   "technique_en": "Match Legitimate Resource Name or Location",
   "analytic_id": "AN0985",
   "detection_strategy_id": "DET0347",
   "analytic_name": "Analytic 0985",
   "platforms": "macOS",
   "log_sources": "Process Metadata (macos:unifiedlog) | File Metadata (fs:fsusage)",
   "log_sources_ja": "プロセスメタデータ (macos:unifiedlog) | ファイルメタデータ (fs:fsusage)",
   "tuning": "expected_bundle_names | signed_by_apple_check",
   "detection_logic_en": "Detects binaries or launch daemons in /System/Library or /Applications with mismatched bundle names, unexpected metadata, or improper installation origin."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.005",
   "technique_ja": "正規リソース名/場所への一致",
   "technique_en": "Match Legitimate Resource Name or Location",
   "analytic_id": "AN0986",
   "detection_strategy_id": "DET0347",
   "analytic_name": "Analytic 0986",
   "platforms": "Containers",
   "log_sources": "Image Metadata (kubernetes:apiserver) | Process Metadata (containerd:events)",
   "log_sources_ja": "イメージメタデータ (kubernetes:apiserver) | プロセスメタデータ (containerd:events)",
   "tuning": "trusted_namespace_list | image_baseline_hashes",
   "detection_logic_en": "Detects malicious containers or pods using names, labels, or namespaces that mimic legitimate workloads; also checks for image layer mismatches and unauthorized resource deployments."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.005",
   "technique_ja": "正規リソース名/場所への一致",
   "technique_en": "Match Legitimate Resource Name or Location",
   "analytic_id": "AN0987",
   "detection_strategy_id": "DET0347",
   "analytic_name": "Analytic 0987",
   "platforms": "ESXi",
   "log_sources": "Process Creation (esxi:vmkernel) | Module Load (esxi:vmkernel) | Service Metadata (esxi:hostd) | Scheduled Job Creation (esxi:hostd)",
   "log_sources_ja": "プロセス生成 (esxi:vmkernel) | モジュール読み込み (esxi:vmkernel) | サービスメタデータ (esxi:hostd) | スケジュールジョブ作成 (esxi:hostd)",
   "tuning": "esxi_baseline_file_list | service_creation_alert_threshold",
   "detection_logic_en": "Detects VIBs, scripts, or binaries placed into directories like /bin or /etc/vmware with names mimicking standard ESXi components. Also monitors unauthorized creation of services."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.006",
   "technique_ja": "ファイル名末尾のスペース",
   "technique_en": "Space after Filename",
   "analytic_id": "AN0812",
   "detection_strategy_id": "DET0292",
   "analytic_name": "Analytic 0812",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Metadata (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルメタデータ (linux:syslog)",
   "tuning": "ExecutableNameTrailingSpace | UserContext | TimeWindow",
   "detection_logic_en": "Detection of file execution where the file name contains a trailing space to masquerade as a known executable. Adversaries may exploit the way command line interpreters handle file names with trailing whitespace."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.006",
   "technique_ja": "ファイル名末尾のスペース",
   "technique_en": "Space after Filename",
   "analytic_id": "AN0813",
   "detection_strategy_id": "DET0292",
   "analytic_name": "Analytic 0813",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Access (fs:fsusage)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイルアクセス (fs:fsusage)",
   "tuning": "FilenamePattern | TargetPath | UserContext",
   "detection_logic_en": "Execution of renamed or dropped files with a trailing space to deceive users or analysts, especially in LaunchAgents or LaunchDaemons."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.007",
   "technique_ja": "二重ファイル拡張子",
   "technique_en": "Double File Extension",
   "analytic_id": "AN1033",
   "detection_strategy_id": "DET0366",
   "analytic_name": "Analytic 1033",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "benign_extensions | dangerous_extensions | monitored_paths | TimeWindow | UserContext",
   "detection_logic_en": "Detects adversary behavior where a file with a benign-looking first extension (e.g., .txt, .jpg) ends with a dangerous second extension (e.g., .exe, .scr), and is subsequently executed. The behavior chain includes file creation with misleading naming and user or system-initiated process execution from the disguised file."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.008",
   "technique_ja": "ファイルタイプの偽装",
   "technique_en": "Masquerade File Type",
   "analytic_id": "AN0630",
   "detection_strategy_id": "DET0226",
   "analytic_name": "Analytic 0630",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "benign_extensions | monitored_directories | MagicByteMismatchThreshold | TimeWindow | ParentProcessAnomalyScore",
   "detection_logic_en": "Detects behavior where files with non-executable or misleading extensions (e.g., .jpg, .txt) are created or modified but subsequently executed as binaries based on internal file headers or abnormal parent process lineage. This includes identifying polyglot files or malformed magic bytes indicative of masquerading attempts."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.008",
   "technique_ja": "ファイルタイプの偽装",
   "technique_en": "Masquerade File Type",
   "analytic_id": "AN0631",
   "detection_strategy_id": "DET0226",
   "analytic_name": "Analytic 0631",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Metadata (linux:osquery)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルメタデータ (linux:osquery)",
   "tuning": "benign_extensions | HeaderInspectionEnabled | ExecPathScope",
   "detection_logic_en": "Detects when a script or binary is named with misleading or benign-looking extensions (.jpg, .doc) and is then executed via command line or a scheduled task. Includes ELF header mismatches and content-type inconsistencies on disk."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.008",
   "technique_ja": "ファイルタイプの偽装",
   "technique_en": "Masquerade File Type",
   "analytic_id": "AN0632",
   "detection_strategy_id": "DET0226",
   "analytic_name": "Analytic 0632",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog)",
   "tuning": "LaunchAgentScope | SignatureEnforcementLevel | TimeWindow",
   "detection_logic_en": "Detects binaries disguised as media or document types through extension-only masquerading or by modifying the file signature. Observes execution of files whose extension is not typically executable (.jpg, .txt), yet have valid Mach-O headers or execute via Terminal or launch services."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.009",
   "technique_ja": "プロセスツリーの分断",
   "technique_en": "Break Process Trees",
   "analytic_id": "AN1223",
   "detection_strategy_id": "DET0443",
   "analytic_name": "Analytic 1223",
   "platforms": "Linux",
   "log_sources": "OS API Execution (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "OS API実行 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "TimeWindow | ReparentingDetectionScope | ExecutableScope",
   "detection_logic_en": "Detects anomalous process execution patterns where a process's parent terminates quickly after process creation or is re-parented to 'init' (PID 1), often indicating double-fork or daemon-style detachment. These behaviors sever the parent-child relationship and obscure the execution origin in process tree analysis."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.009",
   "technique_ja": "プロセスツリーの分断",
   "technique_en": "Break Process Trees",
   "analytic_id": "AN1224",
   "detection_strategy_id": "DET0443",
   "analytic_name": "Analytic 1224",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | OS API Execution (fs:fsusage)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | OS API実行 (fs:fsusage)",
   "tuning": "AnomalyParentPID | AllowedServices | ProcessNameEntropy",
   "detection_logic_en": "Detects execution patterns where a child process is detached from its original parent, often showing up under 'launchd' (PID 1) with no parent lineage. These breakages in the process tree are indicative of evasive techniques using `daemon()`, `fork()` or background execution flags."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.010",
   "technique_ja": "アカウント名の偽装",
   "technique_en": "Masquerade Account Name",
   "analytic_id": "AN1077",
   "detection_strategy_id": "DET0383",
   "analytic_name": "Analytic 1077",
   "platforms": "Windows",
   "log_sources": "User Account Creation (WinEventLog:Security) | User Account Metadata (windows:osquery)",
   "log_sources_ja": "ユーザーアカウント作成 (WinEventLog:Security) | ユーザーアカウントメタデータ (windows:osquery)",
   "tuning": "SimilarityThreshold | MonitoredAccountList | TimeWindow",
   "detection_logic_en": "Detects adversary behavior where a newly created or renamed user account closely resembles existing service or administrator accounts to blend in and avoid detection. Common patterns include prefix/suffix modifications, homoglyphs, or use of names like 'admin1', 'adm1n', or 'backup_help'."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.010",
   "technique_ja": "アカウント名の偽装",
   "technique_en": "Masquerade Account Name",
   "analytic_id": "AN1078",
   "detection_strategy_id": "DET0383",
   "analytic_name": "Analytic 1078",
   "platforms": "Linux",
   "log_sources": "User Account Creation (auditd:SYSCALL) | User Account Modification (auditd:SYSCALL) | User Account Metadata (linux:osquery)",
   "log_sources_ja": "ユーザーアカウント作成 (auditd:SYSCALL) | ユーザーアカウント変更 (auditd:SYSCALL) | ユーザーアカウントメタデータ (linux:osquery)",
   "tuning": "AllowedSystemAccounts | LevenshteinThreshold | ScriptInitiatorDetection",
   "detection_logic_en": "Detects creation or renaming of accounts with names that closely match known service, root, or admin accounts. Behavior often follows account discovery or deletion, attempting to blend into system activity logs using trusted name conventions."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.010",
   "technique_ja": "アカウント名の偽装",
   "technique_en": "Masquerade Account Name",
   "analytic_id": "AN1079",
   "detection_strategy_id": "DET0383",
   "analytic_name": "Analytic 1079",
   "platforms": "Identity Provider",
   "log_sources": "User Account Creation (azure:audit) | User Account Modification (azure:audit) | User Account Metadata (saas:okta)",
   "log_sources_ja": "ユーザーアカウント作成 (azure:audit) | ユーザーアカウント変更 (azure:audit) | ユーザーアカウントメタデータ (saas:okta)",
   "tuning": "RoleScope | NamingHeuristics",
   "detection_logic_en": "Detects adversary creation of cloud or IdP accounts whose names resemble existing privileged or service accounts. May indicate preparation for privilege escalation or defense evasion."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.010",
   "technique_ja": "アカウント名の偽装",
   "technique_en": "Masquerade Account Name",
   "analytic_id": "AN1080",
   "detection_strategy_id": "DET0383",
   "analytic_name": "Analytic 1080",
   "platforms": "Containers",
   "log_sources": "User Account Creation (docker:daemon)",
   "log_sources_ja": "ユーザーアカウント作成 (docker:daemon)",
   "tuning": "ContainerContextScope | MasqueradePatternList",
   "detection_logic_en": "Monitors for the creation of accounts inside containers using names that resemble legitimate orchestrator or backup identities to mask adversary persistence."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.011",
   "technique_ja": "プロセス引数の上書き",
   "technique_en": "Overwrite Process Arguments",
   "analytic_id": "AN0466",
   "detection_strategy_id": "DET0164",
   "analytic_name": "Analytic 0466",
   "platforms": "Linux",
   "log_sources": "Process Metadata (auditd:SYSCALL) | Process Modification (ebpf:tracepoints)",
   "log_sources_ja": "プロセスメタデータ (auditd:SYSCALL) | プロセス変更 (ebpf:tracepoints)",
   "tuning": "TimeWindow | AllowedArgvMismatchPatterns | ParentExecutableTrustList",
   "detection_logic_en": "Detects adversary behavior where the command-line arguments of a running process are overwritten in memory to spoof the process name, typically replacing it with a benign or misleading string. The detection correlates unexpected null byte sequences, discrepancies between `/proc/<pid>/cmdline` and process ancestry, and suspicious memory writes shortly after process start."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.012",
   "technique_ja": "ブラウザフィンガープリント",
   "technique_en": "Browser Fingerprint",
   "analytic_id": "AN2029",
   "detection_strategy_id": "DET0898",
   "analytic_name": "Analytic 2029",
   "platforms": "Windows",
   "log_sources": "Network Traffic Content (NSM:Flow) | Network Connection Creation (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Kernel-Process)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow) | ネットワーク接続確立 (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Kernel-Process)",
   "tuning": "HeaderSignatureMatch | UserAgentFingerprint | NonBrowserProcessList",
   "detection_logic_en": "Process execution without GUI context (e.g., powershell.exe, wscript.exe) generates HTTP traffic with a spoofed User-Agent mimicking a legitimate browser. No corresponding UI application (e.g., msedge.exe) is active or in parent lineage. The User-Agent deviates from known enterprise baselines or contains spoofed platform indicators.  User-Agent strings can be gathered with API calls such as `ShellExecuteW` to open the default browser on a socket to receive an HTTP reply, or by hard coding the User-Agent string for a specific browser."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.012",
   "technique_ja": "ブラウザフィンガープリント",
   "technique_en": "Browser Fingerprint",
   "analytic_id": "AN2031",
   "detection_strategy_id": "DET0898",
   "analytic_name": "Analytic 2031",
   "platforms": "Linux",
   "log_sources": "Network Traffic Content (NSM:Flow) | Network Connection Creation (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow) | ネットワーク接続確立 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "HeaderSignatureMatch | UserAgentFingerprint",
   "detection_logic_en": "Detection of HTTP outbound requests with inconsistent or spoofed User-Agent headers from command-line tools (e.g., curl, wget, python requests) following interactive user shells or scheduled jobs outside of normal user session behavior."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1036.012",
   "technique_ja": "ブラウザフィンガープリント",
   "technique_en": "Browser Fingerprint",
   "analytic_id": "AN2032",
   "detection_strategy_id": "DET0898",
   "analytic_name": "Analytic 2032",
   "platforms": "macOS",
   "log_sources": "Network Connection Creation (macos:unifiedlog) | Network Traffic Content (NSM:Flow) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ネットワーク接続確立 (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow) | プロセス生成 (macos:unifiedlog)",
   "tuning": "UserAgentFingerprint | HeaderSignatureMatch",
   "detection_logic_en": "Observation of scripted network requests (e.g., using osascript, curl, or python) that include mismatched or spoofed browser User-Agent strings compared to the typical macOS Safari or Chrome baseline, especially when triggered by non-interactive launch agents, login hooks, or background daemons."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1055",
   "technique_ja": "プロセスインジェクション",
   "technique_en": "Process Injection",
   "analytic_id": "AN1399",
   "detection_strategy_id": "DET0508",
   "analytic_name": "Analytic 1399",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Kernel-Process)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Kernel-Process)",
   "tuning": "AccessMask | TimeWindow | InjectedProcessList",
   "detection_logic_en": "Detects process injection by correlating memory manipulation API calls (e.g., VirtualAllocEx, WriteProcessMemory), suspicious thread creation (e.g., CreateRemoteThread), and unusual DLL loads within another process's context."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1055",
   "technique_ja": "プロセスインジェクション",
   "technique_en": "Process Injection",
   "analytic_id": "AN1400",
   "detection_strategy_id": "DET0508",
   "analytic_name": "Analytic 1400",
   "platforms": "Linux",
   "log_sources": "OS API Execution (auditd:SYSCALL) | File Access (auditd:SYSCALL) | Process Modification (linux:procfs)",
   "log_sources_ja": "OS API実行 (auditd:SYSCALL) | ファイルアクセス (auditd:SYSCALL) | プロセス変更 (linux:procfs)",
   "tuning": "TargetPIDThreshold | TimeWindow",
   "detection_logic_en": "Detects ptrace- or memfd-based process injection through audit logs capturing system calls (e.g., ptrace, mmap) targeting running processes along with suspicious file descriptors or memory writes."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1055",
   "technique_ja": "プロセスインジェクション",
   "technique_en": "Process Injection",
   "analytic_id": "AN1401",
   "detection_strategy_id": "DET0508",
   "analytic_name": "Analytic 1401",
   "platforms": "macOS",
   "log_sources": "Process Access (macos:unifiedlog) | Process Metadata (macos:endpointsecurity) | Module Load (macos:syslog)",
   "log_sources_ja": "プロセスアクセス (macos:unifiedlog) | プロセスメタデータ (macos:endpointsecurity) | モジュール読み込み (macos:syslog)",
   "tuning": "TargetProcessSignature | MachSyscallContext",
   "detection_logic_en": "Detects memory-based injection by monitoring `task_for_pid`, `mach_vm_write`, and dylib injection patterns through `DYLD_INSERT_LIBRARIES` or manual memory mapping."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1055.001",
   "technique_ja": "DLLインジェクション",
   "technique_en": "Dynamic-link Library Injection",
   "analytic_id": "AN1095",
   "detection_strategy_id": "DET0389",
   "analytic_name": "Analytic 1095",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Named Pipe Metadata (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | 名前付きパイプメタデータ (WinEventLog:Sysmon)",
   "tuning": "InjectedDLLSignatureStatus | TimeWindow | TargetProcessList | ParentProcessAnomalyThreshold",
   "detection_logic_en": "Detects DLL injection through correlation of memory allocation and writing to remote process memory (e.g., VirtualAllocEx, WriteProcessMemory), followed by remote thread creation (e.g., CreateRemoteThread) that loads a suspicious or unsigned DLL using LoadLibrary or reflective loading."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1055.002",
   "technique_ja": "PEインジェクション",
   "technique_en": "Portable Executable Injection",
   "analytic_id": "AN0297",
   "detection_strategy_id": "DET0106",
   "analytic_name": "Analytic 0297",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Process Modification (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | プロセス変更 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "PayloadEntropyThreshold | TargetProcessList | TimeWindow | ParentProcessAnomalyThreshold",
   "detection_logic_en": "Detects PE injection through a behavioral sequence where one process opens (OpenProcess) a handle to another, allocates remote memory (VirtualAllocEx), writes a PE header (MZ) or shellcode (WriteProcessMemory), then initiates a new thread (CreateRemoteThread or NtCreateThreadEx) in that process—executing injected code in memory without touching disk. Optional: injects a trampoline or shellcode that unpacks/reflectively maps the payload."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1055.003",
   "technique_ja": "スレッド実行ハイジャック",
   "technique_en": "Thread Execution Hijacking",
   "analytic_id": "AN0822",
   "detection_strategy_id": "DET0295",
   "analytic_name": "Analytic 0822",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Process Modification (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Kernel-Process) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | プロセス変更 (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Kernel-Process) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TargetProcessList | TimeWindow | SuspiciousThreadContextRegions | ParentProcessAnomalyThreshold",
   "detection_logic_en": "Detects hijacking of an existing thread (OpenThread) through a behavioral chain involving thread suspension (SuspendThread), memory modification (VirtualAllocEx + WriteProcessMemory), context manipulation (SetThreadContext), and thread resumption—all within another live process's address space (ResumeThread)."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1055.004",
   "technique_ja": "非同期プロシージャコール(APC)",
   "technique_en": "Asynchronous Procedure Call",
   "analytic_id": "AN0277",
   "detection_strategy_id": "DET0100",
   "analytic_name": "Analytic 0277",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Process Modification (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Kernel-Process) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | プロセス変更 (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Kernel-Process) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "APCTargetProcessList | ThreadQueueDepthThreshold | TimeWindow | UserContextSensitivity",
   "detection_logic_en": "Detects malicious injection behavior involving memory allocation, remote thread queuing via APC (e.g., QueueUserAPC), and altered thread context within another live process to execute unauthorized code under legitimate context."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1055.005",
   "technique_ja": "スレッドローカルストレージ",
   "technique_en": "Thread Local Storage",
   "analytic_id": "AN1289",
   "detection_strategy_id": "DET0467",
   "analytic_name": "Analytic 1289",
   "platforms": "Windows",
   "log_sources": "Module Load (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Process Modification (WinEventLog:Sysmon) | OS API Execution (EDR:memory)",
   "log_sources_ja": "モジュール読み込み (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | プロセス変更 (WinEventLog:Sysmon) | OS API実行 (EDR:memory)",
   "tuning": "TargetProcessFilter | TimeWindowBetweenLoadAndTLSModification | AnomalousThreadStartThreshold | PayloadEntropyThreshold",
   "detection_logic_en": "Detects thread local storage (TLS) callback injection by monitoring memory modifications to PE headers and TLS directory structures during or after process hollowing events, followed by anomalous thread behavior prior to main entry point execution."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1055.008",
   "technique_ja": "ptraceシステムコール",
   "technique_en": "Ptrace System Calls",
   "analytic_id": "AN0579",
   "detection_strategy_id": "DET0203",
   "analytic_name": "Analytic 0579",
   "platforms": "Linux",
   "log_sources": "OS API Execution (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Process Metadata (linux:osquery)",
   "log_sources_ja": "OS API実行 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | プロセスメタデータ (linux:osquery)",
   "tuning": "TargetProcessNameFilter | TimeWindowBetweenPtraceAndMemoryWrite | UserContextMismatch | ProcessRelationshipConstraint",
   "detection_logic_en": "Detects ptrace-based process injection by correlating audit logs of ptrace syscalls, memory modifications (e.g., poketext, pokedata), and suspicious register manipulation on a target process not normally debugged by the originator. Alerts on processes attempting to ptrace non-child or privileged processes, especially those followed by abnormal memory or execution behavior."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1055.009",
   "technique_ja": "Procメモリ",
   "technique_en": "Proc Memory",
   "analytic_id": "AN1494",
   "detection_strategy_id": "DET0541",
   "analytic_name": "Analytic 1494",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | OS API Execution (auditd:SYSCALL) | File Access (linux:osquery)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | OS API実行 (auditd:SYSCALL) | ファイルアクセス (linux:osquery)",
   "tuning": "TargetProcNameRegex | TimeWindowBetweenMapAccessAndMemWrite | InvokerBinaryAllowlist | FileWriteThreshold",
   "detection_logic_en": "Detects adversary behavior where a process enumerates and modifies another process's memory using /proc/[pid]/maps and /proc/[pid]/mem files. This includes identifying gadgets via memory mappings and overwriting process memory via low-level file modification or dd usage."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1055.011",
   "technique_ja": "Extra Window Memoryインジェクション",
   "technique_en": "Extra Window Memory Injection",
   "analytic_id": "AN0608",
   "detection_strategy_id": "DET0217",
   "analytic_name": "Analytic 0608",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Win32k) | Process Creation (WinEventLog:Security)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Win32k) | プロセス生成 (WinEventLog:Security)",
   "tuning": "TargetWindowClassRegex | ExecutionTriggerWindowMessage | SharedSectionWriteThreshold | TimeWindowSetWindowLongToMessageTrigger",
   "detection_logic_en": "Detects adversary manipulation of Extra Window Memory (EWM) in a GUI process, where the attacker uses SetWindowLong or SetClassLong to redirect function pointers to injected shellcode stored in shared memory, then triggers execution via a window message like SendNotifyMessage."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1055.012",
   "technique_ja": "プロセスハロウィング",
   "technique_en": "Process Hollowing",
   "analytic_id": "AN1076",
   "detection_strategy_id": "DET0382",
   "analytic_name": "Analytic 1076",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Process Modification (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Kernel-Process)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | プロセス変更 (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Kernel-Process)",
   "tuning": "HollowedImageNamePattern | TimeWindow_ProcessCreateToResume | SuspendedProcessStartFlag | MemoryWriteSizeThreshold",
   "detection_logic_en": "Detects adversary use of suspended process creation, using the CREATE_SUSPENDED flag via CreateProcess, followed by unmapping the memory of the child process (NtUnmapViewOfSection) and replacing it with malicious code via VirtualAllocEx/WriteProcessMemory, then SetThreadContext and ResumeThread to begin execution within the hollowed process."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1055.013",
   "technique_ja": "プロセスドッペルゲンギング",
   "technique_en": "Process Doppelgänging",
   "analytic_id": "AN1501",
   "detection_strategy_id": "DET0544",
   "analytic_name": "Analytic 1501",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Kernel-Process)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Kernel-Process)",
   "tuning": "TransactionExecutableNamePattern | TimeWindow_TransactionToExecution | ThreadStartEntropyThreshold | TxF API Call Frequency Threshold",
   "detection_logic_en": "Detects adversary abuse of Transactional NTFS (TxF) and undocumented process loading mechanisms (e.g., NtCreateProcessEx) to create a hollowed process from an uncommitted, maliciously tainted file image in memory, later executed via NtCreateThreadEx."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1055.014",
   "technique_ja": "VDSOハイジャック",
   "technique_en": "VDSO Hijacking",
   "analytic_id": "AN1241",
   "detection_strategy_id": "DET0448",
   "analytic_name": "Analytic 1241",
   "platforms": "Linux",
   "log_sources": "OS API Execution (auditd:SYSCALL) | Process Modification (auditd:memprotect) | Module Load (auditd:file-events) | Process Creation (linux:osquery)",
   "log_sources_ja": "OS API実行 (auditd:SYSCALL) | プロセス変更 (auditd:memprotect) | モジュール読み込み (auditd:file-events) | プロセス生成 (linux:osquery)",
   "tuning": "SuspiciousSharedObjectPathRegex | TimeWindow_PtraceToMmap | ExecMemoryProtectionThreshold | AnomalousParentProcessList",
   "detection_logic_en": "Detects the redirection of syscall execution flow via modification of VDSO code stubs or GOT entries to load and execute a malicious shared object through mmap and ptrace."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1055.015",
   "technique_ja": "ListPlanting",
   "technique_en": "ListPlanting",
   "analytic_id": "AN0941",
   "detection_strategy_id": "DET0331",
   "analytic_name": "Analytic 0941",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Process Modification (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Win32k)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | プロセス変更 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Win32k)",
   "tuning": "TimeWindow_PostMessage_to_LVM_SORTITEMS | TargetWindowClassName | UserContextAnomalyThreshold | InterprocessWindowMessagingFrequency",
   "detection_logic_en": "Detects the use of message-based injection by monitoring for sequences involving FindWindow (EnumWindows or EnumChildWindows), VirtualAllocEx or related API calls, combined with suspicious PostMessage/SendMessage (e.g., LVM_SETITEMPOSITION) use to SysListView32 controls, followed by LVM_SORTITEMS invocation instead of WriteProcessMemory."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070",
   "technique_ja": "痕跡の除去",
   "technique_en": "Indicator Removal",
   "analytic_id": "AN0520",
   "detection_strategy_id": "DET0184",
   "analytic_name": "Analytic 0520",
   "platforms": "Windows",
   "log_sources": "File Deletion (WinEventLog:Sysmon) | Application Log Content (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル削除 (WinEventLog:Sysmon) | アプリケーションログ内容 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | TargetFilePathPattern",
   "detection_logic_en": "Monitors sequences involving deletion/modification of logs, registry keys, scheduled tasks, or prefetch files following suspicious process activity or elevated access escalation."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070",
   "technique_ja": "痕跡の除去",
   "technique_en": "Indicator Removal",
   "analytic_id": "AN0521",
   "detection_strategy_id": "DET0184",
   "analytic_name": "Analytic 0521",
   "platforms": "Linux",
   "log_sources": "File Deletion (auditd:SYSCALL) | Application Log Content (linux:cli)",
   "log_sources_ja": "ファイル削除 (auditd:SYSCALL) | アプリケーションログ内容 (linux:cli)",
   "tuning": "MonitoredPaths | UserContext",
   "detection_logic_en": "Detects deletion or overwriting of bash history, syslog, audit logs, and .ssh metadata following privilege elevation or suspicious process spawning."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070",
   "technique_ja": "痕跡の除去",
   "technique_en": "Indicator Removal",
   "analytic_id": "AN0522",
   "detection_strategy_id": "DET0184",
   "analytic_name": "Analytic 0522",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | File Deletion (fs:fsusage) | File Modification (macos:osquery)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | ファイル削除 (fs:fsusage) | ファイル変更 (macos:osquery)",
   "tuning": "PlistTargetPaths | ExecutionChainDepth",
   "detection_logic_en": "Detects clearing of unified logs, deletion of plist files tied to persistence, and manipulation of Terminal history after initial execution."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070",
   "technique_ja": "痕跡の除去",
   "technique_en": "Indicator Removal",
   "analytic_id": "AN0523",
   "detection_strategy_id": "DET0184",
   "analytic_name": "Analytic 0523",
   "platforms": "Containers",
   "log_sources": "File Deletion (docker:daemon) | File Metadata (ebpf:syscalls)",
   "log_sources_ja": "ファイル削除 (docker:daemon) | ファイルメタデータ (ebpf:syscalls)",
   "tuning": "LogMountPaths | ContainerLabelScope",
   "detection_logic_en": "Monitors tampering with audit logs, volumes, or mounted storage often used for side-channel logging (e.g., /var/log inside containers) post-compromise."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070",
   "technique_ja": "痕跡の除去",
   "technique_en": "Indicator Removal",
   "analytic_id": "AN0524",
   "detection_strategy_id": "DET0184",
   "analytic_name": "Analytic 0524",
   "platforms": "ESXi",
   "log_sources": "File Deletion (esxi:hostd)",
   "log_sources_ja": "ファイル削除 (esxi:hostd)",
   "tuning": "LogSourceType | LogPathPattern",
   "detection_logic_en": "Tracks suspicious use of ESXi shell commands or PowerCLI to delete logs, rotate system files, or tamper with hostd/vpxa history."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070",
   "technique_ja": "痕跡の除去",
   "technique_en": "Indicator Removal",
   "analytic_id": "AN0525",
   "detection_strategy_id": "DET0184",
   "analytic_name": "Analytic 0525",
   "platforms": "Office Suite",
   "log_sources": "Scheduled Job Modification (m365:exchange) | Application Log Content (m365:unified)",
   "log_sources_ja": "スケジュールジョブ変更 (m365:exchange) | アプリケーションログ内容 (m365:unified)",
   "tuning": "TargetMailboxScope | AuditLogDepth",
   "detection_logic_en": "Detects deletion or hiding of security-related mail rules, audit mailboxes, or calendar/log sync artifacts indicative of tampering post-intrusion."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.003",
   "technique_ja": "コマンド履歴の消去",
   "technique_en": "Clear Command History",
   "analytic_id": "AN0467",
   "detection_strategy_id": "DET0165",
   "analytic_name": "Analytic 0467",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Deletion (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル削除 (auditd:SYSCALL)",
   "tuning": "TimeWindow | UserContext | HistoryFilePath",
   "detection_logic_en": "Detects adversary behavior clearing command history via `history -c`, deletion or modification of ~/.bash_history, or manipulation of the HISTFILE environment variable post-login."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.003",
   "technique_ja": "コマンド履歴の消去",
   "technique_en": "Clear Command History",
   "analytic_id": "AN0468",
   "detection_strategy_id": "DET0165",
   "analytic_name": "Analytic 0468",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (fs:fsusage)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (fs:fsusage)",
   "tuning": "TimeWindow | UserContext | HistoryFilePath",
   "detection_logic_en": "Detects adversary clearing shell history using `history -c` or deleting/altering ~/.zsh_history or ~/.bash_history. Focus on sessions with missing or wiped history."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.003",
   "technique_ja": "コマンド履歴の消去",
   "technique_en": "Clear Command History",
   "analytic_id": "AN0469",
   "detection_strategy_id": "DET0165",
   "analytic_name": "Analytic 0469",
   "platforms": "Windows",
   "log_sources": "Command Execution (WinEventLog:PowerShell) | File Deletion (WinEventLog:Sysmon) | File Modification (WinEventLog:Security)",
   "log_sources_ja": "コマンド実行 (WinEventLog:PowerShell) | ファイル削除 (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Security)",
   "tuning": "HistoryFilePath | UserContext | CommandPattern",
   "detection_logic_en": "Detects PowerShell `Clear-History` invocation or deletion of `ConsoleHost_history.txt` to erase past PowerShell session history."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.003",
   "technique_ja": "コマンド履歴の消去",
   "technique_en": "Clear Command History",
   "analytic_id": "AN0470",
   "detection_strategy_id": "DET0165",
   "analytic_name": "Analytic 0470",
   "platforms": "ESXi",
   "log_sources": "File Deletion (esxi:shell)",
   "log_sources_ja": "ファイル削除 (esxi:shell)",
   "tuning": "LogFilePath | TimeWindow",
   "detection_logic_en": "Detects modification or truncation of `/var/log/shell.log` used to persist ESXi shell command history. Especially suspicious shortly after login or config changes."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.003",
   "technique_ja": "コマンド履歴の消去",
   "technique_en": "Clear Command History",
   "analytic_id": "AN0471",
   "detection_strategy_id": "DET0165",
   "analytic_name": "Analytic 0471",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:syslog)",
   "log_sources_ja": "コマンド実行 (networkdevice:syslog)",
   "tuning": "CommandPattern | DeviceType",
   "detection_logic_en": "Detects use of `clear history` or `clear logging` commands on network device CLI to remove past activity logs."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.004",
   "technique_ja": "ファイル削除",
   "technique_en": "File Deletion",
   "analytic_id": "AN0392",
   "detection_strategy_id": "DET0140",
   "analytic_name": "Analytic 0392",
   "platforms": "Windows",
   "log_sources": "File Deletion (WinEventLog:Sysmon) | File Access (WinEventLog:Security) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "ファイル削除 (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Security) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "TimeWindow | FilePathPattern | UserContext",
   "detection_logic_en": "Detects adversary behavior deleting artifacts (e.g., dropped payloads, evidence files) using native or external utilities (e.g., del, erase, SDelete). Detects deletion events correlated with unusual process lineage or timing post-execution."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.004",
   "technique_ja": "ファイル削除",
   "technique_en": "File Deletion",
   "analytic_id": "AN0393",
   "detection_strategy_id": "DET0140",
   "analytic_name": "Analytic 0393",
   "platforms": "Linux",
   "log_sources": "File Deletion (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイル削除 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "PathRegex | TimeWindow | SecureDeletionTool",
   "detection_logic_en": "Detects deletion of suspicious files (e.g., payloads, temp exes, scripts) via `rm`, `unlink`, or secure deletion tools like `shred`, especially when performed by unexpected users or shortly after execution."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.004",
   "technique_ja": "ファイル削除",
   "technique_en": "File Deletion",
   "analytic_id": "AN0394",
   "detection_strategy_id": "DET0140",
   "analytic_name": "Analytic 0394",
   "platforms": "macOS",
   "log_sources": "File Modification (fs:fsusage) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ファイル変更 (fs:fsusage) | プロセス生成 (macos:unifiedlog)",
   "tuning": "FilePathRegex | ToolUsageAnomaly",
   "detection_logic_en": "Detects removal of adversary artifacts via `rm`, `unlink`, or secure tools, with focus on shell sessions, temp files, and modified LaunchAgents or system directories."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.004",
   "technique_ja": "ファイル削除",
   "technique_en": "File Deletion",
   "analytic_id": "AN0395",
   "detection_strategy_id": "DET0140",
   "analytic_name": "Analytic 0395",
   "platforms": "ESXi",
   "log_sources": "File Deletion (esxi:shell)",
   "log_sources_ja": "ファイル削除 (esxi:shell)",
   "tuning": "LogFilePath | TimeWindow",
   "detection_logic_en": "Detects manual or scripted removal of logs, artifacts, or malware droppings via `rm` or PowerCLI in ESXi shell. Focus on deletions from /tmp/, /var/core/, or /scratch."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.005",
   "technique_ja": "ネットワーク共有接続の削除",
   "technique_en": "Network Share Connection Removal",
   "analytic_id": "AN0286",
   "detection_strategy_id": "DET0103",
   "analytic_name": "Analytic 0286",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TimeWindow | UserContext | ProcessCommandLineRegex | NetworkShareNamePattern",
   "detection_logic_en": "Detects network share disconnection attempts using command-line tools like `net use /delete`, PowerShell `Remove-SmbMapping`, and correlation with process lineage and SMB session teardown activity."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.006",
   "technique_ja": "タイムストンプ",
   "technique_en": "Timestomp",
   "analytic_id": "AN1626",
   "detection_strategy_id": "DET0591",
   "analytic_name": "Analytic 1626",
   "platforms": "Windows",
   "log_sources": "File Metadata (WinEventLog:Sysmon) | File Access (WinEventLog:Security) | OS API Execution (EDR:file)",
   "log_sources_ja": "ファイルメタデータ (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Security) | OS API実行 (EDR:file)",
   "tuning": "TimeWindow | APINamePattern | TimestampDeltaThreshold",
   "detection_logic_en": "Detects attempts to modify file timestamps via API usage (e.g., `SetFileTime`), CLI tools (e.g., `w32tm`, PowerShell), or double-timestomp behavior where $SI and $FN timestamps are mismatched or reverted."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.006",
   "technique_ja": "タイムストンプ",
   "technique_en": "Timestomp",
   "analytic_id": "AN1627",
   "detection_strategy_id": "DET0591",
   "analytic_name": "Analytic 1627",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Metadata (linux:osquery)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルメタデータ (linux:osquery)",
   "tuning": "MonitoredCommandList | FilePathRegex | DeltaThreshold",
   "detection_logic_en": "Detects use of timestamp-altering commands like `touch -a -m -t` or `touch -r`, particularly when executed by unusual users or in suspicious directories."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.006",
   "technique_ja": "タイムストンプ",
   "technique_en": "Timestomp",
   "analytic_id": "AN1628",
   "detection_strategy_id": "DET0591",
   "analytic_name": "Analytic 1628",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Metadata (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイルメタデータ (macos:osquery)",
   "tuning": "CommandMatch | UserContext",
   "detection_logic_en": "Detects timestamp changes using `touch`, `SetFile`, or direct metadata tampering (e.g., xattr manipulation) from Terminal, scripts, or low-level APIs."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.006",
   "technique_ja": "タイムストンプ",
   "technique_en": "Timestomp",
   "analytic_id": "AN1629",
   "detection_strategy_id": "DET0591",
   "analytic_name": "Analytic 1629",
   "platforms": "ESXi",
   "log_sources": "File Modification (esxi:vmkernel)",
   "log_sources_ja": "ファイル変更 (esxi:vmkernel)",
   "tuning": "TimestampAgeComparison | PersistenceOverlap",
   "detection_logic_en": "Detects abuse of busybox commands (e.g., `touch`) or log timestamp tampering during backdoor persistence or evasion."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.007",
   "technique_ja": "ネットワーク接続履歴と構成の消去",
   "technique_en": "Clear Network Connection History and Configurations",
   "analytic_id": "AN0133",
   "detection_strategy_id": "DET0049",
   "analytic_name": "Analytic 0133",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Command Execution (EDR:cli) | Firewall Rule Modification (WinEventLog:Security)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (EDR:cli) | ファイアウォールルール変更 (WinEventLog:Security)",
   "tuning": "TargetPathRegex | TimeWindow | UserContext",
   "detection_logic_en": "Detects attempts to clear RDP/network history and modify network configuration artifacts through command execution, registry key deletion, firewall rule changes, and suspicious file deletions (e.g., Default.rdp, registry edits to Terminal Server Client keys)."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.007",
   "technique_ja": "ネットワーク接続履歴と構成の消去",
   "technique_en": "Clear Network Connection History and Configurations",
   "analytic_id": "AN0134",
   "detection_strategy_id": "DET0049",
   "analytic_name": "Analytic 0134",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Modification (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL)",
   "tuning": "CommandMatchPattern | LogPathFilter",
   "detection_logic_en": "Detects deletion or overwriting of logs/configs that store SSH or proxy activity, such as /var/log/auth.log or custom .bash_history clearing tied to SSH sessions or firewall rule changes."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.007",
   "technique_ja": "ネットワーク接続履歴と構成の消去",
   "technique_en": "Clear Network Connection History and Configurations",
   "analytic_id": "AN0135",
   "detection_strategy_id": "DET0049",
   "analytic_name": "Analytic 0135",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Modification (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル変更 (macos:osquery)",
   "tuning": "FilenameMatch | TimeDeltaFromLogin",
   "detection_logic_en": "Detects removal of Remote Login or Screen Sharing logs in Unified Logging, deletion of `com.apple.UTun`, or suspicious Terminal use of `rm`, `sudo pfctl -F all` to clear network state/config history."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.007",
   "technique_ja": "ネットワーク接続履歴と構成の消去",
   "technique_en": "Clear Network Connection History and Configurations",
   "analytic_id": "AN0136",
   "detection_strategy_id": "DET0049",
   "analytic_name": "Analytic 0136",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:syslog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (networkdevice:syslog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "CommandPattern | DeviceTypeFilter",
   "detection_logic_en": "Detects firewall rule modifications or reset of logs/connection tables (e.g., `clear logging`, `erase startup-config`, `write erase`) following remote access activity on routers, switches, or VPN appliances."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.008",
   "technique_ja": "メールボックスデータの消去",
   "technique_en": "Clear Mailbox Data",
   "analytic_id": "AN0737",
   "detection_strategy_id": "DET0266",
   "analytic_name": "Analytic 0737",
   "platforms": "Windows",
   "log_sources": "Command Execution (WinEventLog:PowerShell) | File Deletion (WinEventLog:Sysmon) | File Modification (WinEventLog:Security) | Application Log Content (m365:exchange)",
   "log_sources_ja": "コマンド実行 (WinEventLog:PowerShell) | ファイル削除 (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Security) | アプリケーションログ内容 (m365:exchange)",
   "tuning": "MailstorePath | TransportRuleNames | PowerShellCommandMatch",
   "detection_logic_en": "Detects mailbox manipulation or deletion via PowerShell (e.g., Remove-MailboxExportRequest), file deletion from Outlook data stores (Unistore.db), or tampering with quarantined mail logs."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.008",
   "technique_ja": "メールボックスデータの消去",
   "technique_en": "Clear Mailbox Data",
   "analytic_id": "AN0738",
   "detection_strategy_id": "DET0266",
   "analytic_name": "Analytic 0738",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Deletion (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル削除 (auditd:SYSCALL)",
   "tuning": "MailFolderPath | CommandPattern",
   "detection_logic_en": "Detects the use of mail utilities like `mail` or `mailx` to delete mailbox content, or file-level deletion of inbox files from `/var/spool/mail/` or `/var/mail/` following suspicious sessions."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.008",
   "technique_ja": "メールボックスデータの消去",
   "technique_en": "Clear Mailbox Data",
   "analytic_id": "AN0739",
   "detection_strategy_id": "DET0266",
   "analytic_name": "Analytic 0739",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Deletion (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル削除 (macos:osquery)",
   "tuning": "ScriptCommandMatch | LibraryPathMatch",
   "detection_logic_en": "Detects removal of Apple Mail artifacts via AppleScript or direct deletion of mailbox content in ~/Library/Mail/, especially when preceded by Remote Login or C2-related API access."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.008",
   "technique_ja": "メールボックスデータの消去",
   "technique_en": "Clear Mailbox Data",
   "analytic_id": "AN0740",
   "detection_strategy_id": "DET0266",
   "analytic_name": "Analytic 0740",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:exchange) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "アプリケーションログ内容 (m365:exchange) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "CmdletFilter | UserRoleScope",
   "detection_logic_en": "Detects Exchange Online or on-prem transport rule changes (e.g., header stripping) and mailbox export cleanup via `Remove-MailboxExportRequest`, as well as admin actions via Exchange PowerShell sessions."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.009",
   "technique_ja": "永続化の消去",
   "technique_en": "Clear Persistence",
   "analytic_id": "AN0113",
   "detection_strategy_id": "DET0040",
   "analytic_name": "Analytic 0113",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | User Account Deletion (WinEventLog:Security) | Scheduled Job Creation (WinEventLog:TaskScheduler) | Windows Registry Key Modification (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ユーザーアカウント削除 (WinEventLog:Security) | スケジュールジョブ作成 (WinEventLog:TaskScheduler) | Windowsレジストリキー変更 (WinEventLog:Security)",
   "tuning": "TargetRegistryPathRegex | DeletedScheduledTaskName | DeletedAccountGroupScope",
   "detection_logic_en": "Detects adversary activity that removes persistence artifacts such as services, registry keys, scheduled tasks, user accounts, and binaries through commands like `sc delete`, `schtasks /delete`, or `reg delete`."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.009",
   "technique_ja": "永続化の消去",
   "technique_en": "Clear Persistence",
   "analytic_id": "AN0114",
   "detection_strategy_id": "DET0040",
   "analytic_name": "Analytic 0114",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Deletion (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル削除 (auditd:SYSCALL)",
   "tuning": "ServicePathMatch | CronUserScope | UserDeletionActivity",
   "detection_logic_en": "Detects removal of persistence artifacts such as crontab entries, systemd service units, and malicious user accounts through commands like `crontab -r`, `rm /etc/systemd/system/*.service`, or `userdel`."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.009",
   "technique_ja": "永続化の消去",
   "technique_en": "Clear Persistence",
   "analytic_id": "AN0115",
   "detection_strategy_id": "DET0040",
   "analytic_name": "Analytic 0115",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Deletion (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル削除 (macos:osquery)",
   "tuning": "LaunchDaemonPath | CorrelatedProcessImage",
   "detection_logic_en": "Detects deletion of launch agents (~/Library/LaunchAgents/) and launch daemons (/Library/LaunchDaemons/), especially after suspicious process execution or when tied to known persistence methods."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.009",
   "technique_ja": "永続化の消去",
   "technique_en": "Clear Persistence",
   "analytic_id": "AN0116",
   "detection_strategy_id": "DET0040",
   "analytic_name": "Analytic 0116",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:vmkernel) | File Deletion (esxi:shell)",
   "log_sources_ja": "コマンド実行 (esxi:vmkernel) | ファイル削除 (esxi:shell)",
   "tuning": "ScriptRemovalPath | StartupEntryClearance",
   "detection_logic_en": "Detects adversary removal of persistence implants (e.g., rc.local entries or crontab injections) via CLI (`rm`, `sed`, `crontab -r`) and deletion of startup or management scripts."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.010",
   "technique_ja": "マルウェアの再配置",
   "technique_en": "Relocate Malware",
   "analytic_id": "AN1216",
   "detection_strategy_id": "DET0439",
   "analytic_name": "Analytic 1216",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Deletion (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイル削除 (WinEventLog:Sysmon)",
   "tuning": "SuspiciousTargetPathRegex | TimeWindow | FileExtensionFilter",
   "detection_logic_en": "Detects the relocation of malicious executables via copy/move actions across suspicious folders (e.g., from Downloads to System32), followed by deletion of the original source or renaming to blend into legitimate binaries."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.010",
   "technique_ja": "マルウェアの再配置",
   "technique_en": "Relocate Malware",
   "analytic_id": "AN1217",
   "detection_strategy_id": "DET0439",
   "analytic_name": "Analytic 1217",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL)",
   "tuning": "RelocationPathPatterns | BinaryEntropyThreshold",
   "detection_logic_en": "Detects binary movement or copying between untrusted and trusted paths (e.g., /tmp/ → /usr/bin/ or /etc/init.d/) that may indicate persistence attempts or cleanup of origin traces."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.010",
   "technique_ja": "マルウェアの再配置",
   "technique_en": "Relocate Malware",
   "analytic_id": "AN1218",
   "detection_strategy_id": "DET0439",
   "analytic_name": "Analytic 1218",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Modification (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル変更 (macos:osquery)",
   "tuning": "TargetBundlePathPattern | QuarantineFlagCheck",
   "detection_logic_en": "Detects movement of binaries to `~/Library/`, `/System/`, or app bundle locations, especially after initial execution or download from Safari or Mail."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1070.010",
   "technique_ja": "マルウェアの再配置",
   "technique_en": "Relocate Malware",
   "analytic_id": "AN1219",
   "detection_strategy_id": "DET0439",
   "analytic_name": "Analytic 1219",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:syslog)",
   "log_sources_ja": "コマンド実行 (networkdevice:syslog)",
   "tuning": "StartupConfigPath | CommandPatternMatch",
   "detection_logic_en": "Detects firmware or script relocation attempts (e.g., CLI-based `copy`, `move`, or `rename`) between temporary partitions and config startup folders on routers or switches."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1543",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1543",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | User Account Authentication (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | ユーザーアカウント認証 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "LogonType | TimeWindow | GeoIPMismatch",
   "detection_logic_en": "Detection of compromised or misused valid accounts via anomalous logon patterns, abnormal logon types, and inconsistent geographic or time-based activity across Windows endpoints."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1544",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1544",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | User Account Authentication (NSM:Connections)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ユーザーアカウント認証 (NSM:Connections)",
   "tuning": "UserContext | HostDensityThreshold | LoginMethod",
   "detection_logic_en": "Detection of valid account misuse through SSH logins, sudo/su abuse, and service account anomalies outside expected patterns."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1545",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1545",
   "platforms": "macOS",
   "log_sources": "Logon Session Metadata (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ログオンセッションメタデータ (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "LoginOrigin | ProcessTreeDepth",
   "detection_logic_en": "Detection of interactive and remote logins by service accounts or users at unusual times, with unexpected child process activity."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1546",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1546",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (saas:okta)",
   "log_sources_ja": "ユーザーアカウント認証 (saas:okta)",
   "tuning": "MFAFailureCount | RiskScoreThreshold | IPGeoVelocity",
   "detection_logic_en": "Detection of valid account abuse in IdP logs via geographic anomalies, impossible travel, risky sign-ins, and multiple MFA attempts or failures."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078",
   "technique_ja": "有効なアカウント",
   "technique_en": "Valid Accounts",
   "analytic_id": "AN1547",
   "detection_strategy_id": "DET0560",
   "analytic_name": "Analytic 1547",
   "platforms": "Containers",
   "log_sources": "User Account Authentication (kubernetes:audit)",
   "log_sources_ja": "ユーザーアカウント認証 (kubernetes:audit)",
   "tuning": "ServiceAccountScope | ClusterIPWhitelist",
   "detection_logic_en": "Detection of containerized service accounts or compromised kubeconfigs being used for cluster access from unexpected nodes or IPs."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1283",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1283",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security)",
   "tuning": "UserContext | TimeWindow",
   "detection_logic_en": "Detection of default account usage such as Guest or Administrator performing interactive or remote logons on systems outside of installation or maintenance windows."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1284",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1284",
   "platforms": "Linux",
   "log_sources": "Logon Session Metadata (auditd:USER_LOGIN)",
   "log_sources_ja": "ログオンセッションメタデータ (auditd:USER_LOGIN)",
   "tuning": "SSHMethod | RemoteIPWhitelist",
   "detection_logic_en": "Monitoring for SSH logins from default accounts such as 'root', especially when login is via password and not key-based authentication."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1285",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1285",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (AWS:CloudTrail)",
   "log_sources_ja": "ユーザーアカウント認証 (AWS:CloudTrail)",
   "tuning": "AccountList | GeoLocation",
   "detection_logic_en": "Use of known default service accounts or root-level cloud accounts performing authentication or changes to IAM policy."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1286",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1286",
   "platforms": "ESXi",
   "log_sources": "User Account Authentication (esxi:auth)",
   "log_sources_ja": "ユーザーアカウント認証 (esxi:auth)",
   "tuning": "AccountName | IPRange",
   "detection_logic_en": "Abuse of system-generated or default privileged accounts such as 'root' or 'vpxuser' logging into ESXi hosts."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078.001",
   "technique_ja": "デフォルトアカウント",
   "technique_en": "Default Accounts",
   "analytic_id": "AN1287",
   "detection_strategy_id": "DET0465",
   "analytic_name": "Analytic 1287",
   "platforms": "Network Devices",
   "log_sources": "User Account Authentication (networkdevice:syslog)",
   "log_sources_ja": "ユーザーアカウント認証 (networkdevice:syslog)",
   "tuning": "Username | InterfaceType",
   "detection_logic_en": "Login activity from default admin credentials (e.g., 'admin', 'cisco') on routers, firewalls, and switches."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Accounts",
   "analytic_id": "AN0590",
   "detection_strategy_id": "DET0210",
   "analytic_name": "Analytic 0590",
   "platforms": "Windows",
   "log_sources": "Logon Session Metadata (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッションメタデータ (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext | LogonType",
   "detection_logic_en": "Detection of suspicious logon behavior using valid domain accounts across multiple hosts, off-hours, or simultaneous sessions from geographically distant locations."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Accounts",
   "analytic_id": "AN0591",
   "detection_strategy_id": "DET0210",
   "analytic_name": "Analytic 0591",
   "platforms": "Linux",
   "log_sources": "User Account Authentication (auditd:SYSCALL) | Logon Session Metadata (linux:syslog)",
   "log_sources_ja": "ユーザーアカウント認証 (auditd:SYSCALL) | ログオンセッションメタデータ (linux:syslog)",
   "tuning": "HostnameScope | AccountDomain",
   "detection_logic_en": "Use of domain accounts via sssd or winbind for logon activity outside of typical patterns, especially on sensitive systems or with lateral movement tools."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Accounts",
   "analytic_id": "AN0592",
   "detection_strategy_id": "DET0210",
   "analytic_name": "Analytic 0592",
   "platforms": "macOS",
   "log_sources": "User Account Authentication (macos:unifiedlog)",
   "log_sources_ja": "ユーザーアカウント認証 (macos:unifiedlog)",
   "tuning": "UserLocation | LogonMethod",
   "detection_logic_en": "Domain logins using network accounts or mobile accounts via Open Directory or Active Directory plugins, especially outside business hours or on atypical endpoints."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Accounts",
   "analytic_id": "AN0593",
   "detection_strategy_id": "DET0210",
   "analytic_name": "Analytic 0593",
   "platforms": "ESXi",
   "log_sources": "User Account Authentication (esxi:vpxd) | Logon Session Metadata (esxi:hostd)",
   "log_sources_ja": "ユーザーアカウント認証 (esxi:vpxd) | ログオンセッションメタデータ (esxi:hostd)",
   "tuning": "AccountType | LoginInterface",
   "detection_logic_en": "Login to vSphere or ESXi hosts using domain accounts, especially those associated with vpxuser or unexpected group memberships."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078.003",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Accounts",
   "analytic_id": "AN1137",
   "detection_strategy_id": "DET0407",
   "analytic_name": "Analytic 1137",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Logon Session Metadata (WinEventLog:Security)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | ログオンセッションメタデータ (WinEventLog:Security)",
   "tuning": "TimeWindow | UserContext",
   "detection_logic_en": "Detects anomalous usage of local accounts to log into a system, especially accounts not typically used interactively or outside business hours."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078.003",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Accounts",
   "analytic_id": "AN1138",
   "detection_strategy_id": "DET0407",
   "analytic_name": "Analytic 1138",
   "platforms": "Linux",
   "log_sources": "Logon Session Metadata (auditd:USER_LOGIN) | User Account Authentication (linux:auth)",
   "log_sources_ja": "ログオンセッションメタデータ (auditd:USER_LOGIN) | ユーザーアカウント認証 (linux:auth)",
   "tuning": "TimeWindow | HostRole",
   "detection_logic_en": "Detects interactive or service logins from local accounts outside expected operational context or at anomalous times."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078.003",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Accounts",
   "analytic_id": "AN1139",
   "detection_strategy_id": "DET0407",
   "analytic_name": "Analytic 1139",
   "platforms": "macOS",
   "log_sources": "Logon Session Metadata (macos:unifiedlog)",
   "log_sources_ja": "ログオンセッションメタデータ (macos:unifiedlog)",
   "tuning": "UserContext | TimeWindow",
   "detection_logic_en": "Detects abnormal or rare logins via local accounts through system or remote mechanisms such as SSH."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Accounts",
   "analytic_id": "AN1503",
   "detection_strategy_id": "DET0546",
   "analytic_name": "Analytic 1503",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (azure:signinlogs) | Logon Session Metadata (saas:okta)",
   "log_sources_ja": "ユーザーアカウント認証 (azure:signinlogs) | ログオンセッションメタデータ (saas:okta)",
   "tuning": "AnomalousLocationThreshold | ProtocolType",
   "detection_logic_en": "Detects anomalous authentication activity such as sign-ins from impossible geolocations or legacy protocols from high-privileged accounts."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Accounts",
   "analytic_id": "AN1504",
   "detection_strategy_id": "DET0546",
   "analytic_name": "Analytic 1504",
   "platforms": "IaaS",
   "log_sources": "User Account Authentication (AWS:CloudTrail) | Logon Session Creation (gcp:audit)",
   "log_sources_ja": "ユーザーアカウント認証 (AWS:CloudTrail) | ログオンセッション作成 (gcp:audit)",
   "tuning": "ServiceInteractionBaseline | RoleSwitchRateThreshold",
   "detection_logic_en": "Detects cloud account use for API calls that exceed normal scope, such as IAM changes or access to services never used before."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Accounts",
   "analytic_id": "AN1505",
   "detection_strategy_id": "DET0546",
   "analytic_name": "Analytic 1505",
   "platforms": "SaaS",
   "log_sources": "Logon Session Metadata (m365:unified) | User Account Authentication (gcp:audit)",
   "log_sources_ja": "ログオンセッションメタデータ (m365:unified) | ユーザーアカウント認証 (gcp:audit)",
   "tuning": "FileDownloadThreshold | SharingPolicyViolationThreshold",
   "detection_logic_en": "Detects unexpected access or usage of cloud productivity tools (e.g., downloading large numbers of files, creating external shares) by internal users."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1078.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Accounts",
   "analytic_id": "AN1506",
   "detection_strategy_id": "DET0546",
   "analytic_name": "Analytic 1506",
   "platforms": "Office Suite",
   "log_sources": "Logon Session Metadata (m365:signinlogs) | User Account Authentication (gcp:audit)",
   "log_sources_ja": "ログオンセッションメタデータ (m365:signinlogs) | ユーザーアカウント認証 (gcp:audit)",
   "tuning": "BusinessHours | OfficeProductivityToolBaseline",
   "detection_logic_en": "Detects login and usage patterns deviating from typical Microsoft 365 or Google Workspace user profiles."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1127",
   "technique_ja": "信頼された開発ツールによるプロキシ実行",
   "technique_en": "Trusted Developer Utilities Proxy Execution",
   "analytic_id": "AN0488",
   "detection_strategy_id": "DET0172",
   "analytic_name": "Analytic 0488",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Process Metadata (WinEventLog:AppLocker)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | プロセスメタデータ (WinEventLog:AppLocker)",
   "tuning": "TimeWindow | AllowedUtilitiesList | DeveloperHosts | SuspiciousChildList | RarePathRegex | UnsignedOrInvalidSignatureOnly | ParentProcessAllowList | NetworkReputationThreshold",
   "detection_logic_en": "A trusted/signed developer utility (parent) is executed in a non-developer context and (a) spawns suspicious children (e.g., powershell.exe, cmd.exe, rundll32.exe, regsvr32.exe, wscript.exe), (b) loads unsigned/user-writable DLLs, (c) writes and then runs a new PE from user-writable paths, and/or (d) immediately makes outbound network connections."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1127.001",
   "technique_ja": "MSBuild",
   "technique_en": "MSBuild",
   "analytic_id": "AN1535",
   "detection_strategy_id": "DET0556",
   "analytic_name": "Analytic 1535",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Process Modification (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Process Metadata (WinEventLog:Microsoft-Windows-CodeIntegrity/Operational) | Script Execution (EDR:AMSI)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス変更 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | プロセスメタデータ (WinEventLog:Microsoft-Windows-CodeIntegrity/Operational) | スクリプト実行 (EDR:AMSI)",
   "tuning": "TimeWindow | DeveloperHosts | SuspiciousChildList | RarePathRegex | UnsignedOrInvalidSignatureOnly | NetworkReputationThreshold | BehaviorRiskScoreThreshold",
   "detection_logic_en": "MSBuild.exe is invoked outside expected developer/build contexts or with anomalous arguments (e.g., non-canonical paths, remote shares, Base64/obfuscated property values). Within a short window, it (a) spawns high-risk LOLBins/script interpreters, (b) writes new PE/DLL/script artifacts into user-writable paths and executes them, (c) loads unsigned/user-writable modules, (d) performs memory injection/thread creation into other processes, and/or (e) initiates outbound network connections."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1127.002",
   "technique_ja": "ClickOnce",
   "technique_en": "ClickOnce",
   "analytic_id": "AN0550",
   "detection_strategy_id": "DET0191",
   "analytic_name": "Analytic 0550",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Module Load (WinEventLog:Sysmon) | Process Metadata (WinEventLog:Microsoft-Windows-Security-Mitigations/KernelMode)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon) | プロセスメタデータ (WinEventLog:Microsoft-Windows-Security-Mitigations/KernelMode)",
   "tuning": "TimeWindow | KnownClickOnceApps | SuspiciousChildList",
   "detection_logic_en": "Abuse of ClickOnce applications where rundll32.exe invokes dfshim.dll with ShOpenVerbApplication or dfsvc.exe spawns unexpected child processes or loads unsigned modules."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1127.003",
   "technique_ja": "JamPlus",
   "technique_en": "JamPlus",
   "analytic_id": "AN1610",
   "detection_strategy_id": "DET0585",
   "analytic_name": "Analytic 1610",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Process Metadata (WinEventLog:Microsoft-Windows-CodeIntegrity/Operational)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | プロセスメタデータ (WinEventLog:Microsoft-Windows-CodeIntegrity/Operational)",
   "tuning": "TimeWindow | AllowedBuildHosts | SuspiciousChildList | RarePathRegex",
   "detection_logic_en": "Abuse of JamPlus.exe to launch malicious payloads via crafted .jam files, resulting in abnormal process creation, command execution, or artifact generation outside of standard development workflows."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1134",
   "technique_ja": "アクセストークン操作",
   "technique_en": "Access Token Manipulation",
   "analytic_id": "AN0786",
   "detection_strategy_id": "DET0283",
   "analytic_name": "Analytic 0786",
   "platforms": "Windows",
   "log_sources": "Logon Session Metadata (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | OS API Execution (ETW:Token) | Active Directory Object Modification (WinEventLog:Security)",
   "log_sources_ja": "ログオンセッションメタデータ (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | OS API実行 (ETW:Token) | Active Directoryオブジェクト変更 (WinEventLog:Security)",
   "tuning": "TimeWindow | AllowedServiceAccounts | KnownAdminTools | ParentProcessAnomalyThreshold",
   "detection_logic_en": "Detection of suspicious token manipulation chains: use of token-related APIs (e.g., LogonUser, DuplicateTokenEx) or commands (runas) → spawning of a new process under a different security context (e.g., SYSTEM) → mismatched parent-child process lineage or anomalies in Event Tracing for Windows (ETW) token/PPID data → abnormal lateral or privilege escalation activity."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1134.001",
   "technique_ja": "トークンの偽装/窃取",
   "technique_en": "Token Impersonation/Theft",
   "analytic_id": "AN1324",
   "detection_strategy_id": "DET0482",
   "analytic_name": "Analytic 1324",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Process Access (WinEventLog:Sysmon) | OS API Execution (ETW:Token)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon) | OS API実行 (ETW:Token)",
   "tuning": "AllowedSystemProcesses | TimeWindow | UserContextFilter | ParentProcessAnomalyThreshold",
   "detection_logic_en": "Detection of token duplication and impersonation attempts by correlating suspicious command-line executions (e.g., runas) with API calls to DuplicateToken, DuplicateTokenEx, ImpersonateLoggedOnUser, or SetThreadToken. The chain includes the initial command execution or in-memory API invocation → token handle duplication or thread token assignment → a new or existing process assuming the impersonated user's context."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1134.002",
   "technique_ja": "トークンを用いたプロセス作成",
   "technique_en": "Create Process with Token",
   "analytic_id": "AN1253",
   "detection_strategy_id": "DET0456",
   "analytic_name": "Analytic 1253",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Process Access (WinEventLog:Sysmon) | OS API Execution (ETW:ProcThread) | Logon Session Metadata (WinEventLog:Security) | Active Directory Object Modification (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon) | OS API実行 (ETW:ProcThread) | ログオンセッションメタデータ (WinEventLog:Security) | Active Directoryオブジェクト変更 (WinEventLog:Security)",
   "tuning": "TimeWindow | AllowedImpersonators | IntegrityEscalationDelta | ParentChildUserMismatch | SensitiveTargets",
   "detection_logic_en": "A process (often after stealing/creating a token) calls CreateProcessWithTokenW/CreateProcessAsUserW or uses runas to spawn a **new** process whose security context (SID/LogonId/IntegrityLevel) differs from its parent. Chain: (1) suspicious command/API → (2) privileged handle or token duplication/open → (3) new child process running as another user / higher integrity → (4) optional follow‑on privileged/lateral actions."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1134.003",
   "technique_ja": "トークンの作成と偽装",
   "technique_en": "Make and Impersonate Token",
   "analytic_id": "AN1375",
   "detection_strategy_id": "DET0498",
   "analytic_name": "Analytic 1375",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Logon Session Metadata (WinEventLog:Security) | OS API Execution (etw:Microsoft-Windows-Security-Auditing)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ログオンセッションメタデータ (WinEventLog:Security) | OS API実行 (etw:Microsoft-Windows-Security-Auditing)",
   "tuning": "TimeWindow | SuspiciousLogonTypes | AllowedImpersonators | ParentChildUserMismatch | IntegrityEscalationDelta",
   "detection_logic_en": "A process creates a brand‑new logon session/token (LogonUser*/LsaLogonUser) and then assigns/impersonates it (SetThreadToken/ImpersonateLoggedOnUser) to run actions under that freshly created security context. Chain: (1) suspicious command or script block (e.g., runas /netonly, PowerShell P/Invoke of LogonUser) → (2) ETW/API evidence of LogonUser*/SetThreadToken → (3) Security 4624 New Logon (often LogonType=9 NewCredentials or 2/3 from a non‑interactive parent) with no interactive desktop → (4) sysmon 1 process(es) executing with the new LogonId/SID different from the parent process → (5) optional privileged ops/lateral movement."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1134.004",
   "technique_ja": "親PIDスプーフィング",
   "technique_en": "Parent PID Spoofing",
   "analytic_id": "AN1351",
   "detection_strategy_id": "DET0489",
   "analytic_name": "Analytic 1351",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | OS API Execution (etw:Microsoft-Windows-Kernel-Process) | Process Metadata (etw:Microsoft-Windows-Kernel-Process)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | OS API実行 (etw:Microsoft-Windows-Kernel-Process) | プロセスメタデータ (etw:Microsoft-Windows-Kernel-Process)",
   "tuning": "TimeWindow | AllowedSpoofers | ParentPrivilegeDeltaThreshold | LineageMismatchTolerance | SensitiveParents",
   "detection_logic_en": "A process explicitly forges its parent using EXTENDED_STARTUPINFO + PROC_THREAD_ATTRIBUTE_PARENT_PROCESS (UpdateProcThreadAttribute → CreateProcess[A/W]/CreateProcessAsUserW) or other Native API paths, resulting in **mismatched/implausible lineage** across ETW EventHeader ProcessId, Security 4688 Creator Process ID/Name, and sysmon ParentProcessGuid. Often paired with privilege escalation when the chosen parent runs as SYSTEM."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1134.005",
   "technique_ja": "SID履歴インジェクション",
   "technique_en": "SID-History Injection",
   "analytic_id": "AN0383",
   "detection_strategy_id": "DET0136",
   "analytic_name": "Analytic 0383",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Modification (WinEventLog:Security) | User Account Metadata (WinEventLog:Security) | OS API Execution (etw:Microsoft-Windows-Directory-Services-SAM)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (WinEventLog:Security) | ユーザーアカウントメタデータ (WinEventLog:Security) | OS API実行 (etw:Microsoft-Windows-Directory-Services-SAM)",
   "tuning": "AllowedSIDHistoryChanges | TimeWindow | PrivilegedSIDList | UserContextFilter | AnomalousSIDCountThreshold",
   "detection_logic_en": "Detection of unauthorized modification of Active Directory SID-History attributes to escalate privileges. This chain involves: (1) privileged operations or API calls to DsAddSidHistory or related AD modification functions, (2) observed attribute changes in SID-History (Event ID 5136), (3) new logon sessions where the token includes unexpected or privileged SID-History values, and (4) follow-on resource access using elevated privileges derived from SID-History injection."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1140",
   "technique_ja": "ファイル/情報の難読化解除・デコード",
   "technique_en": "Deobfuscate/Decode Files or Information",
   "analytic_id": "AN0767",
   "detection_strategy_id": "DET0275",
   "analytic_name": "Analytic 0767",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "ToolName | FileExtensionFilter | CommandLineRegex | TimeWindow",
   "detection_logic_en": "An adversary leverages built-in tools such as certutil.exe, powershell.exe, or copy.exe to decode, reassemble, or extract hidden malicious content from obfuscated containers or encoded formats. The decoding utility often spawns shortly after file staging or download and may be chained with script interpreters or further payload execution."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1140",
   "technique_ja": "ファイル/情報の難読化解除・デコード",
   "technique_en": "Deobfuscate/Decode Files or Information",
   "analytic_id": "AN0768",
   "detection_strategy_id": "DET0275",
   "analytic_name": "Analytic 0768",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL)",
   "tuning": "ShellProcessName | DecodeUtility | ParentProcess | ArgumentPattern",
   "detection_logic_en": "The adversary uses native utilities like base64, gzip, tar, or openssl to decode, decompress, or decrypt files that were previously staged or downloaded. These tools may be chained with curl/wget and executed via bash/zsh, often to extract an embedded payload or reverse shell script."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1140",
   "technique_ja": "ファイル/情報の難読化解除・デコード",
   "technique_en": "Deobfuscate/Decode Files or Information",
   "analytic_id": "AN0769",
   "detection_strategy_id": "DET0275",
   "analytic_name": "Analytic 0769",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog)",
   "tuning": "DecodeInterpreter | ExecutionContext | UserContext",
   "detection_logic_en": "The adversary invokes built-in scripting or decoding tools like base64, plutil, or AppleScript-based utilities to decode files embedded in staging artifacts. Decoding often occurs post-download or as part of post-exploitation payload deployment via zsh, python, or osascript."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1197",
   "technique_ja": "BITSジョブ",
   "technique_en": "BITS Jobs",
   "analytic_id": "AN0274",
   "detection_strategy_id": "DET0098",
   "analytic_name": "Analytic 0274",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | Service Creation (WinEventLog:System)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | サービス作成 (WinEventLog:System)",
   "tuning": "TimeWindow | ExpectedUpdateHosts | SuspiciousCliSwitches | NotifyCmdBlockList | UserContext | ExternalNetCIDRs | JobLifetimeThreshold",
   "detection_logic_en": "Behavioral chain: (1) An actor creates or modifies a BITS job via bitsadmin.exe, PowerShell BITS cmdlets, or COM; (2) the job performs HTTP(S)/SMB network transfers while the owning user is logged on; (3) upon job completion/error, BITS launches a notify command (SetNotifyCmdLine) from svchost.exe -k netsvcs -s BITS, often establishing persistence by keeping long-lived jobs. The strategy correlates process creation, command/script telemetry, BITS-Client operational events, and network connections initiated by BITS."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1202",
   "technique_ja": "間接的コマンド実行",
   "technique_en": "Indirect Command Execution",
   "analytic_id": "AN0576",
   "detection_strategy_id": "DET0200",
   "analytic_name": "Analytic 0576",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | AllowedUtilities | HighRiskChildren | UserContext | DestCIDRs",
   "detection_logic_en": "Cause→effect chain: (1) A user or service launches an indirection utility (e.g., forfiles.exe, pcalua.exe, wsl.exe, scriptrunner.exe, ssh.exe with -o ProxyCommand/LocalCommand). (2) That utility spawns a secondary program/command (PowerShell, cmd, msiexec, regsvr32, curl, arbitrary EXE) and/or opens outbound network connections. (3) Optional precursor modification of SSH config to persist LocalCommand/ProxyCommand. Correlate process creation, command/script content, file access to %USERPROFILE%\\.ssh\\config, and network connections from the utility or its child."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1205",
   "technique_ja": "トラフィックシグナリング",
   "technique_en": "Traffic Signaling",
   "analytic_id": "AN1448",
   "detection_strategy_id": "DET0524",
   "analytic_name": "Analytic 1448",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Flow (WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィックフロー (WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "TimeWindowKnock | PortSequenceMinLen | SuspiciousProcesses | AllowedFirewallChangers | WoLAllowedWindows",
   "detection_logic_en": "A remote host sends a short sequence of failed connection attempts (RST/ICMP unreachable) to a set of closed ports. Within a brief window the endpoint (a) adds/enables a firewall rule or (b) a sniffer-backed process begins listening or opens a new socket, after which a successful connection occurs. Also detects Wake-on-LAN magic packets seen on local segment."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1205",
   "technique_ja": "トラフィックシグナリング",
   "technique_en": "Traffic Signaling",
   "analytic_id": "AN1449",
   "detection_strategy_id": "DET0524",
   "analytic_name": "Analytic 1449",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ServicePort | KnockResetRatio | ProcessAllowList",
   "detection_logic_en": "Closed-port knock sequence from a remote IP followed by on-host firewall change (iptables/nftables) or daemon starts listening (socket open) and a successful TCP/UDP connect. Optional detection of libpcap/raw-socket sniffers spawning to watch for secret values."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1205",
   "technique_ja": "トラフィックシグナリング",
   "technique_en": "Traffic Signaling",
   "analytic_id": "AN1450",
   "detection_strategy_id": "DET0524",
   "analytic_name": "Analytic 1450",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Flow (macos:unifiedlog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィックフロー (macos:unifiedlog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "PFAnchorPaths | DeveloperMode",
   "detection_logic_en": "Remote knock sequence followed by PF/socketfilterfw rule update or a background process listening on a new port; then a successful TCP session. Also flags WoL magic packets on local segment."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1205",
   "technique_ja": "トラフィックシグナリング",
   "technique_en": "Traffic Signaling",
   "analytic_id": "AN1451",
   "detection_strategy_id": "DET0524",
   "analytic_name": "Analytic 1451",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Flow (networkdevice:syslog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィックフロー (networkdevice:syslog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "MgmtPortSet | DeviceRole",
   "detection_logic_en": "Crafted ‘synful knock’ patterns toward routers/switches (same src hits interface/broadcast/network address on same port in short order) followed by ACL/telnet/SSH enablement or module change. Detect device image/ACL updates then a new mgmt session."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1205.001",
   "technique_ja": "ポートノッキング",
   "technique_en": "Port Knocking",
   "analytic_id": "AN0842",
   "detection_strategy_id": "DET0302",
   "analytic_name": "Analytic 0842",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Flow (WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィックフロー (WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall)",
   "tuning": "TimeWindow | MinSequenceLen | RuleChangeAllowList | WatchedPorts",
   "detection_logic_en": "A remote source rapidly touches a short sequence of closed ports (SYN→RST/S0) on a Windows host. Within a short window the host changes firewall state (WFP rule added/modified or service starts listening) and then the same source completes the first successful handshake to the newly opened port."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1205.001",
   "technique_ja": "ポートノッキング",
   "technique_en": "Port Knocking",
   "analytic_id": "AN0843",
   "detection_strategy_id": "DET0302",
   "analytic_name": "Analytic 0843",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "ServicePort | KnockTolerance | MgmtAllowList",
   "detection_logic_en": "A source performs a short closed-port sequence; the host then modifies iptables/nftables/ufw rules or starts a daemon binding a new socket, followed by a successful connection from the same source."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1205.001",
   "technique_ja": "ポートノッキング",
   "technique_en": "Port Knocking",
   "analytic_id": "AN0844",
   "detection_strategy_id": "DET0302",
   "analytic_name": "Analytic 0844",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Flow (macos:unifiedlog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィックフロー (macos:unifiedlog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "PFAnchorPaths | DevMode",
   "detection_logic_en": "A source performs a closed-port sequence; the endpoint enables a PF/socketfilterfw rule or a background process binds a port; then a successful connection completes from the same source."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1205.001",
   "technique_ja": "ポートノッキング",
   "technique_en": "Port Knocking",
   "analytic_id": "AN0845",
   "detection_strategy_id": "DET0302",
   "analytic_name": "Analytic 0845",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Flow (networkdevice:syslog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィックフロー (networkdevice:syslog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "MgmtPortSet | DeviceRole",
   "detection_logic_en": "Router/switch receives a knock pattern (same src touches device unicast, broadcast, and network-address on same or stepped ports) followed by ACL/line-vty/service enable and the first mgmt session success."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1205.002",
   "technique_ja": "ソケットフィルタ",
   "technique_en": "Socket Filters",
   "analytic_id": "AN0462",
   "detection_strategy_id": "DET0162",
   "analytic_name": "Analytic 0462",
   "platforms": "Windows",
   "log_sources": "Service Creation (WinEventLog:System) | Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Driver Load (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "サービス作成 (WinEventLog:System) | プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ドライバ読み込み (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TimeWindow | CaptureLibIndicators | AllowedInstallers | ReversePorts",
   "detection_logic_en": "Adversary installs/uses packet-capture or raw-socket capability (WinPcap/Npcap, wpcap/packet DLLs or raw socket attach) and sets a filter. A crafted inbound packet is observed; within a short window the host process that loaded capture libraries initiates an outbound connection (e.g., reverse shell) to the packet origin."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1205.002",
   "technique_ja": "ソケットフィルタ",
   "technique_en": "Socket Filters",
   "analytic_id": "AN0463",
   "detection_strategy_id": "DET0162",
   "analytic_name": "Analytic 0463",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (linux:osquery) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (linux:osquery) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "UserContext | MinPayloadEntropy | AFPacketAllowList",
   "detection_logic_en": "Process creates a raw/packet socket and attaches a (e)BPF filter (setsockopt SO_ATTACH_FILTER/ATTACH_BPF or bpf(BPF_PROG_LOAD)). Immediately after a matching inbound packet, the same process binds/connects outward to a remote host (reverse shell or beacon)."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1205.002",
   "technique_ja": "ソケットフィルタ",
   "technique_en": "Socket Filters",
   "analytic_id": "AN0464",
   "detection_strategy_id": "DET0162",
   "analytic_name": "Analytic 0464",
   "platforms": "macOS",
   "log_sources": "Process Creation (OpenBSM:AuditTrail) | Network Connection Creation (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (OpenBSM:AuditTrail) | ネットワーク接続確立 (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "BPFDevicePath | DeveloperMode",
   "detection_logic_en": "Process opens /dev/bpf* (libpcap) or loads NetworkExtension filter, then after a crafted inbound packet the same process initiates an outbound connection to the trigger origin."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1211",
   "technique_ja": "ステルスのための脆弱性悪用",
   "technique_en": "Exploitation for Stealth",
   "analytic_id": "AN1633",
   "detection_strategy_id": "DET0595",
   "analytic_name": "Analytic 1633",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "DefensiveProcessList | AllowedModulePaths | CrashThreshold",
   "detection_logic_en": "Detects exploitation attempts targeting defensive security software or OS services. Defender observation includes abnormal process behavior (e.g., AV or EDR crashing unexpectedly), unsigned/untrusted modules loaded into defensive processes, or privilege escalation from security agent services. Multi-event correlation ties exploitation attempts to subsequent evasive behavior like service termination or missing logs."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1211",
   "technique_ja": "ステルスのための脆弱性悪用",
   "technique_en": "Exploitation for Stealth",
   "analytic_id": "AN1634",
   "detection_strategy_id": "DET0595",
   "analytic_name": "Analytic 1634",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Application Log Content (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | アプリケーションログ内容 (linux:syslog)",
   "tuning": "WatchedBinaries | CrashPatterns",
   "detection_logic_en": "Detects kernel- or user-space exploitation attempts targeting auditd, AV daemons, or security monitoring agents. Defender observation includes unexpected segfaults, privilege escalation attempts from low-privileged processes, or modifications to security binaries. Correlates exploitation attempts with subsequent gaps in logging or terminated processes."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1211",
   "technique_ja": "ステルスのための脆弱性悪用",
   "technique_en": "Exploitation for Stealth",
   "analytic_id": "AN1635",
   "detection_strategy_id": "DET0595",
   "analytic_name": "Analytic 1635",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "SecurityDaemons | UnsignedProcessThreshold",
   "detection_logic_en": "Detects exploitation of macOS security and integrity services, such as Gatekeeper, XProtect, or EDR agents. Defender observations include unsigned processes attempting privileged operations, abnormal termination of security daemons, or modification of system integrity logs."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1211",
   "technique_ja": "ステルスのための脆弱性悪用",
   "technique_en": "Exploitation for Stealth",
   "analytic_id": "AN1636",
   "detection_strategy_id": "DET0595",
   "analytic_name": "Analytic 1636",
   "platforms": "IaaS",
   "log_sources": "Application Log Content (AWS:CloudTrail)",
   "log_sources_ja": "アプリケーションログ内容 (AWS:CloudTrail)",
   "tuning": "CriticalAPIs | TimeWindow",
   "detection_logic_en": "Detects exploitation of IaaS cloud security boundaries to evade defense controls. Defender perspective includes anomalous API calls that bypass audit logging, disable monitoring, or manipulate guardrails (e.g., CloudTrail tampering). Correlation highlights when exploitation attempts precede sudden absence of expected telemetry."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1211",
   "technique_ja": "ステルスのための脆弱性悪用",
   "technique_en": "Exploitation for Stealth",
   "analytic_id": "AN1637",
   "detection_strategy_id": "DET0595",
   "analytic_name": "Analytic 1637",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified)",
   "tuning": "MonitoredApps | ConsentAnomalyThreshold",
   "detection_logic_en": "Detects adversary abuse of SaaS platform vulnerabilities to bypass logging, monitoring, or consent boundaries. Defender perspective focuses on abnormal application integration events, missing audit logs, or API calls from unauthorized service principals that align with exploitation attempts."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1216",
   "technique_ja": "システムスクリプトによるプロキシ実行",
   "technique_en": "System Script Proxy Execution",
   "analytic_id": "AN1288",
   "detection_strategy_id": "DET0466",
   "analytic_name": "Analytic 1288",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | Module Load (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | モジュール読み込み (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "ParentProcessName | TimeWindow | ChildCommandLineRegex | SignedToUnsignedTransition",
   "detection_logic_en": "Execution of Microsoft-signed scripts (e.g., pubprn.vbs, installutil.exe, wscript.exe, cscript.exe) used to proxy execution of untrusted or external binaries. Behavior is detected through command-line process lineage, child process spawning, and unsigned payload execution from signed parent."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1216.001",
   "technique_ja": "PubPrn",
   "technique_en": "PubPrn",
   "analytic_id": "AN1464",
   "detection_strategy_id": "DET0528",
   "analytic_name": "Analytic 1464",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | Network Connection Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | ネットワーク接続確立 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "CommandLineRegex | ParentProcessName | NetworkDestinationDomain | TimeWindow",
   "detection_logic_en": "Execution of PubPrn.vbs via cscript.exe using the 'script:' moniker to load and execute a remote .sct scriptlet file, bypassing signature validation and proxying remote payloads through a signed Microsoft script host."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1216.002",
   "technique_ja": "SyncAppvPublishingServer",
   "technique_en": "SyncAppvPublishingServer",
   "analytic_id": "AN1220",
   "detection_strategy_id": "DET0440",
   "analytic_name": "Analytic 1220",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | Module Load (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | モジュール読み込み (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "CommandLineRegex | ScriptInterpreter | PowerShellObfuscationScore | TimeWindow",
   "detection_logic_en": "Execution of SyncAppvPublishingServer.vbs through wscript.exe with a command-line containing embedded PowerShell, proxying malicious PowerShell execution through a Microsoft-signed VBScript interpreter to evade detection and restrictions."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218",
   "technique_ja": "システムバイナリによるプロキシ実行",
   "technique_en": "System Binary Proxy Execution",
   "analytic_id": "AN0226",
   "detection_strategy_id": "DET0081",
   "analytic_name": "Analytic 0226",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "ParentProcessName | SignedBinaryList | CommandLineRegex | RemoteDomainAllowlist",
   "detection_logic_en": "Execution of trusted, Microsoft-signed binaries such as `rundll32.exe`, `msiexec.exe`, or `regsvr32.exe` used to execute externally hosted, unsigned, or suspicious payloads through command-line parameters or network retrieval."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218",
   "technique_ja": "システムバイナリによるプロキシ実行",
   "technique_en": "System Binary Proxy Execution",
   "analytic_id": "AN0227",
   "detection_strategy_id": "DET0081",
   "analytic_name": "Analytic 0227",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (auditd:SYSCALL)",
   "tuning": "TrustedBinaryList | AnomalyScore",
   "detection_logic_en": "Execution of trusted system binaries (e.g., `split`, `tee`, `bash`, `env`) used in uncommon sequences or chained behaviors to execute malicious payloads or perform actions inconsistent with normal system or script behavior."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218",
   "technique_ja": "システムバイナリによるプロキシ実行",
   "technique_en": "System Binary Proxy Execution",
   "analytic_id": "AN0228",
   "detection_strategy_id": "DET0081",
   "analytic_name": "Analytic 0228",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Connection Creation (macos:osquery)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワーク接続確立 (macos:osquery)",
   "tuning": "TrustedUtilityList | SignedToUnsignedTransition",
   "detection_logic_en": "Use of system binaries such as `osascript`, `bash`, or `curl` to download or execute unsigned code or files in conjunction with application proxying."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218.001",
   "technique_ja": "コンパイル済みHTMLファイル",
   "technique_en": "Compiled HTML File",
   "analytic_id": "AN0968",
   "detection_strategy_id": "DET0342",
   "analytic_name": "Analytic 0968",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "CHMPathRegex | ChildProcessList | NetworkDestinationAllowlist | TimeWindow",
   "detection_logic_en": "Execution of hh.exe to open a .chm file followed by suspicious child processes or script engine invocation (VBScript, JScript, mshta, powershell). Behavior includes loading a CHM file from untrusted locations, or immediately spawning commands indicative of payload execution."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218.002",
   "technique_ja": "コントロールパネル",
   "technique_en": "Control Panel",
   "analytic_id": "AN0558",
   "detection_strategy_id": "DET0194",
   "analytic_name": "Analytic 0558",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Windows Registry Key Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | Windowsレジストリキー作成 (WinEventLog:Sysmon)",
   "tuning": "CPLPathRegex | ParentProcessName | NewFileTimeWindow | RegistryKeyAllowlist",
   "detection_logic_en": "Execution of control.exe or rundll32.exe with parameters pointing to CPL files, especially from non-standard directories or newly created files, followed by suspicious child process execution or registry modifications registering new Control Panel items."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218.003",
   "technique_ja": "CMSTP",
   "technique_en": "CMSTP",
   "analytic_id": "AN0932",
   "detection_strategy_id": "DET0328",
   "analytic_name": "Analytic 0932",
   "platforms": "Windows",
   "log_sources": "Command Execution (WinEventLog:PowerShell) | Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Windows Registry Key Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "コマンド実行 (WinEventLog:PowerShell) | ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | Windowsレジストリキー作成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "INFPathRegex | ExternalIPAllowlist | COMInterfaceGUIDs | RegistryKeyAllowlist | TimeWindow",
   "detection_logic_en": "Execution of CMSTP.exe with arguments pointing to suspicious or remote INF/SCT/DLL payloads, optionally followed by outbound network connections to untrusted IPs, process injection via COM interfaces (CMSTPLUA, CMLUAUTIL), registry modifications registering malicious profiles, or creation of suspicious INF/DLL/SCT files prior to execution."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218.004",
   "technique_ja": "InstallUtil",
   "technique_en": "InstallUtil",
   "analytic_id": "AN0388",
   "detection_strategy_id": "DET0138",
   "analytic_name": "Analytic 0388",
   "platforms": "Windows",
   "log_sources": "Command Execution (WinEventLog:PowerShell) | Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "コマンド実行 (WinEventLog:PowerShell) | プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "InstallUtilPathRegex | AssemblyPathRegex | ChildProcessList | TimeWindow",
   "detection_logic_en": "Execution of InstallUtil.exe from .NET framework directories with arguments specifying non-standard or attacker-supplied assemblies, especially when followed by suspicious child process creation or script execution. Detection also includes correlation of newly created binaries prior to InstallUtil invocation and anomalous command-line usage compared to historical baselines."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218.005",
   "technique_ja": "Mshta",
   "technique_en": "Mshta",
   "analytic_id": "AN1397",
   "detection_strategy_id": "DET0506",
   "analytic_name": "Analytic 1397",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "CommandLinePattern | SuspiciousParentProcesses | AllowedHTASources | TimeWindow",
   "detection_logic_en": "Detection of mshta.exe execution where command-line arguments reference remote or local HTA/script content (VBScript/JScript) followed by subsequent file creation, network retrieval, or process spawning that indicates payload execution outside standard Internet Explorer security context. Correlation includes parent process lineage, command-line inspection, and network connection creation to untrusted or anomalous endpoints."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218.007",
   "technique_ja": "Msiexec",
   "technique_en": "Msiexec",
   "analytic_id": "AN0445",
   "detection_strategy_id": "DET0158",
   "analytic_name": "Analytic 0445",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Module Load (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "SuspiciousCommandlinePatterns | SuspiciousDestinationList | TimeWindow | LegitimateMSIHashes",
   "detection_logic_en": "Detection of msiexec.exe execution where command-line arguments reference remote MSI packages, UNC paths, HTTP/HTTPS URLs, or DLLs, correlated with subsequent module loads and/or network connections to previously unseen destinations. The behavioral chain links process creation of msiexec.exe with suspicious parameters, network activity to retrieve payloads, and module loading indicative of malicious installation or DLL execution."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218.008",
   "technique_ja": "Odbcconf",
   "technique_en": "Odbcconf",
   "analytic_id": "AN1335",
   "detection_strategy_id": "DET0486",
   "analytic_name": "Analytic 1335",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Module Load (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "ParentProcessName | AllowedCommandPatterns | TimeWindow | ApprovedModuleHashes",
   "detection_logic_en": "Identifies abuse of odbcconf.exe to execute malicious DLLs using the REGSVR command flag. Behavior chain: (1) Process creation of odbcconf.exe with /REGSVR or /A {REGSVR ...} arguments → (2) DLL load by odbcconf.exe of non-standard or unsigned modules → (3) Optional follow-on process creation or network activity from loaded DLL."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218.009",
   "technique_ja": "Regsvcs/Regasm",
   "technique_en": "Regsvcs/Regasm",
   "analytic_id": "AN1028",
   "detection_strategy_id": "DET0361",
   "analytic_name": "Analytic 1028",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Module Load (WinEventLog:Sysmon) | Windows Registry Key Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon) | Windowsレジストリキー作成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "AssemblyPathRegex | SuspiciousFlags | ParentProcessAllowList | KnownGoodAssemblies | RegistryKeyAllowList | TimeWindow | SignedToUnsignedTransition",
   "detection_logic_en": "Abuse of Regsvcs.exe or Regasm.exe to execute arbitrary code embedded in .NET assemblies via [ComRegisterFunction]/[ComUnregisterFunction]. Behavioral chain: (1) Process creation of regsvcs/regasm with suspicious assembly paths/flags → (2) Assembly/DLL load inside regsvcs/regasm → (3) Registry writes to HKCR\\CLSID/ProgID during COM registration → (4) Optional child process or network activity spawned by installer/registration code."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218.010",
   "technique_ja": "Regsvr32",
   "technique_en": "Regsvr32",
   "analytic_id": "AN0785",
   "detection_strategy_id": "DET0282",
   "analytic_name": "Analytic 0785",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Module Load (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "AllowedDLLPaths | ScriptletExtensions | TimeWindow | ParentProcessWhitelist",
   "detection_logic_en": "Detection focuses on identifying anomalous regsvr32.exe executions that deviate from normal administrative or system use. Defenders may observe regsvr32.exe loading scriptlets or DLLs from unusual paths (especially temporary directories or remote URLs), command-line arguments invoking /i or /u with suspicious file references, network connections initiated by regsvr32.exe, and unsigned or untrusted DLLs being loaded shortly after regsvr32.exe invocation. Correlated sequences include regsvr32.exe process creation, module load of DLL/scriptlet, and optional outbound network traffic."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218.011",
   "technique_ja": "Rundll32",
   "technique_en": "Rundll32",
   "analytic_id": "AN1308",
   "detection_strategy_id": "DET0475",
   "analytic_name": "Analytic 1308",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | ParentProcessFilter | AllowedDLLs | ExternalIPRange",
   "detection_logic_en": "Detects rundll32.exe invoked with atypical arguments (.dll, .cpl, javascript:, mshtml). DLLs not normally loaded by rundll32 are mapped into memory. Control_RunDLL or RunHTMLApplication invoked. Suspicious DLLs or scripts accessed from disk or network. Rundll32 reaches out to external domains (e.g., fetching .sct or .hta)."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218.012",
   "technique_ja": "Verclsid",
   "technique_en": "Verclsid",
   "analytic_id": "AN0118",
   "detection_strategy_id": "DET0042",
   "analytic_name": "Analytic 0118",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "AllowedCLSIDs | ParentProcessFilter | TimeWindow | ExternalIPRange",
   "detection_logic_en": "Detects abuse of verclsid.exe to execute COM objects by monitoring process creation, CLSID arguments, DLLs or scriptlet engines loaded into memory, and If the CLSID points to remote SCT/HTA content, verclsid.exe makes outbound connections."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218.013",
   "technique_ja": "Mavinject",
   "technique_en": "Mavinject",
   "analytic_id": "AN1207",
   "detection_strategy_id": "DET0433",
   "analytic_name": "Analytic 1207",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Process Access (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | DLLPathRegex | TargetProcessAllowList | MinGrantedAccessSet | ParentProcessFilter | ExternalIPAllowlist | SignedToUnsignedTransition",
   "detection_logic_en": "Abuse of mavinject.exe to inject DLLs or import descriptors into another running process. Chain: (1) mavinject.exe starts with /INJECTRUNNING or /HMODULE → (2) mavinject obtains high-access handles to a target process (VM_WRITE/CREATE_THREAD) → (3) target process loads attacker DLL (module load) → (4) optional follow-on child activity or network egress from the target process."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218.014",
   "technique_ja": "MMC",
   "technique_en": "MMC",
   "analytic_id": "AN0622",
   "detection_strategy_id": "DET0222",
   "analytic_name": "Analytic 0622",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Windows Registry Key Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | OS API Execution (WinEventLog:Microsoft-Windows-COM/Operational) | Network Connection Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | Windowsレジストリキー作成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | OS API実行 (WinEventLog:Microsoft-Windows-COM/Operational) | ネットワーク接続確立 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "TimeWindow | AllowedMSCList | SuspiciousMSCPathRegex | AllowedCLSIDs | ParentProcessAllowList | SignedToUnsignedTransition | ExternalIPAllowlist",
   "detection_logic_en": "Abuse of mmc.exe to execute non-Microsoft or user-staged .msc files and malicious COM CLSIDs. Behavioral chain: (1) suspicious mmc.exe invocation with /a or -Embedding and non-standard .msc path → (2) COM activation of non-baseline CLSIDs by mmc.exe → (3) mmc.exe loads non-baseline DLLs (user-writable/UNC/unsigned) → (4) optional network/DNS activity from mmc.exe."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218.015",
   "technique_ja": "Electronアプリケーション",
   "technique_en": "Electron Applications",
   "analytic_id": "AN0071",
   "detection_strategy_id": "DET0025",
   "analytic_name": "Analytic 0071",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext | AllowedElectronApps | AllowedChildProcesses | ElectronAppDomainAllowlist | AsarIntegrityHash",
   "detection_logic_en": "Abuse of trusted Electron apps (Teams, Slack, Chrome) to spawn child processes or execute payloads via malicious command-line arguments (e.g., --gpu-launcher) and modified app resources (.asar). Behavior chain: suspicious parent process (Electron app) → unusual command-line args → child process creation → optional DLL/network artifacts."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218.015",
   "technique_ja": "Electronアプリケーション",
   "technique_en": "Electron Applications",
   "analytic_id": "AN0072",
   "detection_strategy_id": "DET0025",
   "analytic_name": "Analytic 0072",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "AsarIntegrityCheck | SuspiciousChildProcesses",
   "detection_logic_en": "Abuse of Linux Electron binaries by modifying app.asar or config JS files and spawning unexpected child processes (bash, curl, python)."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1218.015",
   "technique_ja": "Electronアプリケーション",
   "technique_en": "Electron Applications",
   "analytic_id": "AN0073",
   "detection_strategy_id": "DET0025",
   "analytic_name": "Analytic 0073",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (macos:osquery)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:osquery)",
   "tuning": "AllowedAppBundlePaths | SignedToUnsignedTransition",
   "detection_logic_en": "Abuse of macOS Electron apps by modifying app.asar bundles and spawning child processes (osascript, curl, sh) from Electron executables."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1220",
   "technique_ja": "XSLスクリプト処理",
   "technique_en": "XSL Script Processing",
   "analytic_id": "AN0581",
   "detection_strategy_id": "DET0205",
   "analytic_name": "Analytic 0581",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "CommandLinePattern | ParentProcess | TimeWindow | RemoteXSLDomainWhitelist",
   "detection_logic_en": "Execution of XSL scripts via msxsl.exe or wmic.exe using embedded JScript or VBScript for proxy execution. Detection correlates process creation, command-line patterns, and module load behavior of scripting components (e.g., jscript.dll)."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1221",
   "technique_ja": "テンプレートインジェクション",
   "technique_en": "Template Injection",
   "analytic_id": "AN1564",
   "detection_strategy_id": "DET0566",
   "analytic_name": "Analytic 1564",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TemplateURLPatterns | ParentProcess | TimeWindow | ChildProcessAnomalyThreshold",
   "detection_logic_en": "Detection of Office or document viewer processes (e.g., winword.exe) initiating network connections to remote templates or executing scripts due to manipulated template references (e.g., embedded in .docx, .rtf, or .dotm files), followed by suspicious child process creation (e.g., PowerShell)."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1480",
   "technique_ja": "実行ガードレール",
   "technique_en": "Execution Guardrails",
   "analytic_id": "AN1551",
   "detection_strategy_id": "DET0562",
   "analytic_name": "Analytic 1551",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | User Account Authentication (WinEventLog:Security) | Logon Session Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Process Modification (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | WMI Creation (WinEventLog:WMI) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ユーザーアカウント認証 (WinEventLog:Security) | ログオンセッション作成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | プロセス変更 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | WMI作成 (WinEventLog:WMI) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "DiscoveryTimeWindow | DiscoveryActivityThreshold | CryptographicLibraryWhitelist | WMIQueryComplexityThreshold | EnvironmentalArtifactList | ExecutionDelayBaseline",
   "detection_logic_en": "Windows environmental validation behavioral chain: (1) Rapid system discovery reconnaissance through WMI queries, registry enumeration, and network share discovery, (2) Environment-specific artifact collection (hostname, domain, IP addresses, installed software, hardware identifiers), (3) Cryptographic operations or conditional logic based on collected environmental values, (4) Selective payload execution contingent on environmental validation results, (5) Temporal correlation between discovery activities and subsequent execution or network communication"
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1480",
   "technique_ja": "実行ガードレール",
   "technique_en": "Execution Guardrails",
   "analytic_id": "AN1552",
   "detection_strategy_id": "DET0562",
   "analytic_name": "Analytic 1552",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Access (auditd:SYSCALL) | Network Connection Creation (auditd:SYSCALL) | Command Execution (auditd:PROCTITLE) | User Account Authentication (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルアクセス (auditd:SYSCALL) | ネットワーク接続確立 (auditd:SYSCALL) | コマンド実行 (auditd:PROCTITLE) | ユーザーアカウント認証 (linux:syslog)",
   "tuning": "SystemDiscoveryCommandList | ReconnaissanceBurstThreshold | EnvironmentalCheckPatterns | NetworkDiscoveryBaseline | ConditionalExecutionIndicators",
   "detection_logic_en": "Linux environmental validation behavioral chain: (1) Intensive system enumeration through command execution (uname, hostname, ifconfig, lsblk, mount), (2) File system reconnaissance targeting specific paths, network configurations, and installed packages, (3) Process and user enumeration to validate target environment characteristics, (4) Conditional script execution or binary activation based on environmental criteria, (5) Network connectivity validation and external IP address resolution for geolocation verification"
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1480",
   "technique_ja": "実行ガードレール",
   "technique_en": "Execution Guardrails",
   "analytic_id": "AN1553",
   "detection_strategy_id": "DET0562",
   "analytic_name": "Analytic 1553",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Access (fs:fileevents)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイルアクセス (fs:fileevents)",
   "tuning": "MacOSDiscoveryTools | SecurityFeatureEnumeration | HardwareFingerprintBaseline | SIPBypassIndicators",
   "detection_logic_en": "macOS environmental validation behavioral chain: (1) System profiling through system_profiler, sysctl, and hardware discovery commands, (2) Network interface and configuration enumeration for geolocation and network environment validation, (3) Application installation and version discovery for software environment fingerprinting, (4) Security feature detection (SIP, Gatekeeper, XProtect status), (5) Conditional payload execution based on macOS-specific environmental criteria and System Integrity Protection bypass validation"
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1480",
   "technique_ja": "実行ガードレール",
   "technique_en": "Execution Guardrails",
   "analytic_id": "AN1554",
   "detection_strategy_id": "DET0562",
   "analytic_name": "Analytic 1554",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:shell) | Process Creation (esxi:hostd)",
   "log_sources_ja": "コマンド実行 (esxi:shell) | プロセス生成 (esxi:hostd)",
   "tuning": "ESXiDiscoveryCommands | VMInventoryEnumerationThreshold | HypervisorEnvironmentBaseline | DatastoreAccessPatterns",
   "detection_logic_en": "ESXi hypervisor environmental validation behavioral chain: (1) Virtual machine inventory and configuration enumeration through vim-cmd and esxcli commands, (2) Host hardware and network configuration discovery for hypervisor environment validation, (3) Datastore and storage configuration reconnaissance, (4) vCenter connectivity and cluster membership validation, (5) Selective malware deployment based on virtualization infrastructure characteristics and target VM validation"
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1480.001",
   "technique_ja": "環境キーイング",
   "technique_en": "Environmental Keying",
   "analytic_id": "AN1305",
   "detection_strategy_id": "DET0474",
   "analytic_name": "Analytic 1305",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | WMI Creation (WinEventLog:WMI) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | WMI作成 (WinEventLog:WMI) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "DiscoveryTimeWindow | CriticalDiscoveryThreshold | TargetSpecificArtifacts | CryptographicIndicatorPatterns | LegitimateAdminAccounts | BusinessHoursBaseline | WMIQueryComplexityThreshold",
   "detection_logic_en": "Windows-specific environmental keying behavioral chain: (1) Rapid system information discovery through multiple techniques (WMI queries, registry enumeration, network share discovery, hostname/domain checks), (2) Target validation through specific environmental artifact collection (AD domain membership, network topology, installed software versions), (3) Cryptographic operation correlation indicating payload decryption based on collected environmental values, (4) Subsequent malicious code execution following successful environmental validation, (5) Temporal clustering of discovery activities suggesting automated environmental assessment"
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1480.001",
   "technique_ja": "環境キーイング",
   "technique_en": "Environmental Keying",
   "analytic_id": "AN1306",
   "detection_strategy_id": "DET0474",
   "analytic_name": "Analytic 1306",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | File Access (linux:syslog) | Process Creation (linux:osquery)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ファイルアクセス (linux:syslog) | プロセス生成 (linux:osquery)",
   "tuning": "DiscoveryCommandSequenceThreshold | ProcessAncestryDepth | CryptographicLibraryIndicators | TargetSpecificFilesystems | AuthorizedDiscoveryUsers | NetworkConfigurationBaseline | ContainerContextIdentifiers",
   "detection_logic_en": "Linux environmental keying behavioral chain: (1) System information gathering through native commands (uname, hostname, id, whoami, ifconfig/ip) and file system enumeration, (2) Network configuration discovery (route tables, DNS settings, network interfaces), (3) Filesystem and mount point analysis for target-specific directories or devices, (4) Process and service enumeration to identify target-specific software, (5) Cryptographic library usage correlation with collected environmental data, (6) Payload execution following successful environmental validation"
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1480.001",
   "technique_ja": "環境キーイング",
   "technique_en": "Environmental Keying",
   "analytic_id": "AN1307",
   "detection_strategy_id": "DET0474",
   "analytic_name": "Analytic 1307",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Command Execution (macos:unifiedlog) | File Access (fs:fsevents)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | コマンド実行 (macos:unifiedlog) | ファイルアクセス (fs:fsevents)",
   "tuning": "SystemProfilerDataTypes | SecurityFrameworkOperationPatterns | UnifiedLogRetentionWindow | ApplicationBundleValidationPaths | NetworkConfigurationIdentifiers | MacOSVersionBaseline | FSEventsFilteringCriteria",
   "detection_logic_en": "macOS environmental keying behavioral chain: (1) System information discovery through native utilities (system_profiler, sw_vers, hostname, dscl) and Security framework queries, (2) Hardware and software enumeration including serial numbers, installed applications, and system versions, (3) Network configuration assessment (networksetup, scutil) and wireless network discovery, (4) Keychain and security context validation, (5) Unified Logs correlation with cryptographic framework usage (CommonCrypto, Security.framework), (6) Application bundle execution following environmental validation"
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1480.002",
   "technique_ja": "相互排他",
   "technique_en": "Mutual Exclusion",
   "analytic_id": "AN0372",
   "detection_strategy_id": "DET0132",
   "analytic_name": "Analytic 0372",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "mutex_name_entropy_threshold | parent_process_path | TimeWindow",
   "detection_logic_en": "Adversary-created named mutex using system APIs (e.g., CreateMutexW) followed by conditional process termination or alternate code path indicating malware avoiding reinfection."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1480.002",
   "technique_ja": "相互排他",
   "technique_en": "Mutual Exclusion",
   "analytic_id": "AN0373",
   "detection_strategy_id": "DET0132",
   "analytic_name": "Analytic 0373",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Process Termination (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | プロセス終了 (auditd:SYSCALL)",
   "tuning": "lockfile_path_regex | exit_code | TimeWindow",
   "detection_logic_en": "File lock acquired via open() + flock() or lockf() on predictable path (e.g., /tmp/.lock123) followed by conditional early exit or divergent process behavior."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1480.002",
   "technique_ja": "相互排他",
   "technique_en": "Mutual Exclusion",
   "analytic_id": "AN0374",
   "detection_strategy_id": "DET0132",
   "analytic_name": "Analytic 0374",
   "platforms": "macOS",
   "log_sources": "OS API Execution (macos:unifiedlog) | Process Termination (macos:unifiedlog)",
   "log_sources_ja": "OS API実行 (macos:unifiedlog) | プロセス終了 (macos:unifiedlog)",
   "tuning": "lockfile_path | user_context | TimeWindow",
   "detection_logic_en": "User-mode application uses flock() or NSDistributedLock to gain exclusive access to a resource file (e.g., /tmp/guard.lock), conditional logic alters execution if already locked."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1497",
   "technique_ja": "仮想化/サンドボックス回避",
   "technique_en": "Virtualization/Sandbox Evasion",
   "analytic_id": "AN0127",
   "detection_strategy_id": "DET0046",
   "analytic_name": "Analytic 0127",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | KnownVMArtifactList",
   "detection_logic_en": "Execution of discovery commands or API calls for virtualization artifacts (e.g., registry keys, device drivers, services), sleep/skipped execution behavior, or sandbox evasion DLLs before payload deployment."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1497",
   "technique_ja": "仮想化/サンドボックス回避",
   "technique_en": "Virtualization/Sandbox Evasion",
   "analytic_id": "AN0128",
   "detection_strategy_id": "DET0046",
   "analytic_name": "Analytic 0128",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Command Execution (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | コマンド実行 (auditd:SYSCALL)",
   "tuning": "TimeWindow | CommandArtifactMatchList",
   "detection_logic_en": "Execution of commands to enumerate virtualization-related files or processes (e.g., '/sys/class/dmi/id/product_name', dmesg, lscpu, lspci), or querying hypervisor interfaces prior to malware execution."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1497",
   "technique_ja": "仮想化/サンドボックス回避",
   "technique_en": "Virtualization/Sandbox Evasion",
   "analytic_id": "AN0129",
   "detection_strategy_id": "DET0046",
   "analytic_name": "Analytic 0129",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Module Load (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | モジュール読み込み (macos:unifiedlog)",
   "tuning": "ProcessCommandPattern | SleepThreshold",
   "detection_logic_en": "Execution of scripts or binaries that check for virtualization indicators (e.g., system_profiler, ioreg -l, kextstat), combined with delay functions or anomalous launchd activity."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1497.001",
   "technique_ja": "システムチェック",
   "technique_en": "System Checks",
   "analytic_id": "AN0478",
   "detection_strategy_id": "DET0168",
   "analytic_name": "Analytic 0478",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | ProcessAncestry | UserContext",
   "detection_logic_en": "Script or binary performs a rapid sequence of system discovery checks (e.g., CPU count, RAM size, registry keys, running processes) indicative of VM detection"
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1497.001",
   "technique_ja": "システムチェック",
   "technique_en": "System Checks",
   "analytic_id": "AN0479",
   "detection_strategy_id": "DET0168",
   "analytic_name": "Analytic 0479",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL)",
   "tuning": "TimeWindow | CommandPattern",
   "detection_logic_en": "Shell script or binary uses multiple system commands (e.g., dmidecode, lscpu, lspci) in quick succession to detect virtualization environment"
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1497.001",
   "technique_ja": "システムチェック",
   "technique_en": "System Checks",
   "analytic_id": "AN0480",
   "detection_strategy_id": "DET0168",
   "analytic_name": "Analytic 0480",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog)",
   "tuning": "ExecutionBurst | ToolName",
   "detection_logic_en": "Bash, Swift, or Objective-C programs enumerate system profile, I/O registry, or inspect kernel extensions to identify VM artifacts"
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1497.002",
   "technique_ja": "ユーザー活動ベースのチェック",
   "technique_en": "User Activity Based Checks",
   "analytic_id": "AN1182",
   "detection_strategy_id": "DET0420",
   "analytic_name": "Analytic 1182",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Logon Session Metadata (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | ログオンセッションメタデータ (WinEventLog:Security)",
   "tuning": "TimeWindow | UserContext",
   "detection_logic_en": "Process execution that probes user activity artifacts (e.g., desktop files, registry history) following recent user login/unlock events."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1497.002",
   "technique_ja": "ユーザー活動ベースのチェック",
   "technique_en": "User Activity Based Checks",
   "analytic_id": "AN1183",
   "detection_strategy_id": "DET0420",
   "analytic_name": "Analytic 1183",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Command Execution (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | コマンド実行 (auditd:SYSCALL)",
   "tuning": "ArtifactCountThreshold | KnownToolSignatures",
   "detection_logic_en": "Access to shell history or GUI input state (xdotool, xinput) for presence validation prior to payload execution."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1497.002",
   "technique_ja": "ユーザー活動ベースのチェック",
   "technique_en": "User Activity Based Checks",
   "analytic_id": "AN1184",
   "detection_strategy_id": "DET0420",
   "analytic_name": "Analytic 1184",
   "platforms": "macOS",
   "log_sources": "OS API Execution (macos:unifiedlog) | File Access (macos:unifiedlog)",
   "log_sources_ja": "OS API実行 (macos:unifiedlog) | ファイルアクセス (macos:unifiedlog)",
   "tuning": "TimeWindow | UserContext",
   "detection_logic_en": "API usage or filesystem access revealing user state or browser artifacts (e.g., Safari bookmarks, CGEventState)."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1497.003",
   "technique_ja": "時間ベースのチェック",
   "technique_en": "Time Based Checks",
   "analytic_id": "AN0396",
   "detection_strategy_id": "DET0141",
   "analytic_name": "Analytic 0396",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "SleepDurationThreshold | TimeBetweenExecutionAndNextStage | UserContext",
   "detection_logic_en": "Process creation involving suspicious delays (e.g., Sleep, ping -n loops, WaitForSingleObject), followed by sensitive system access or lateral movement behaviors."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1497.003",
   "technique_ja": "時間ベースのチェック",
   "technique_en": "Time Based Checks",
   "analytic_id": "AN0397",
   "detection_strategy_id": "DET0141",
   "analytic_name": "Analytic 0397",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Metadata (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルメタデータ (auditd:SYSCALL)",
   "tuning": "SleepLoopCount | ExecutionScriptType",
   "detection_logic_en": "Script-based execution of sleep loops or time delay commands (e.g., sleep, ping delay, while-loops) followed by file creation or network connections."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1497.003",
   "technique_ja": "時間ベースのチェック",
   "technique_en": "Time Based Checks",
   "analytic_id": "AN0398",
   "detection_strategy_id": "DET0141",
   "analytic_name": "Analytic 0398",
   "platforms": "macOS",
   "log_sources": "OS API Execution (macos:unifiedlog) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "OS API実行 (macos:unifiedlog) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "AppBundleIdentifier | TimeToNextEvent",
   "detection_logic_en": "Use of `usleep`, `nanosleep`, or `NSTimer` calls in executables or binaries with no GUI interaction, especially followed by disk/network activity."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1535",
   "technique_ja": "未使用/非サポートのクラウドリージョン",
   "technique_en": "Unused/Unsupported Cloud Regions",
   "analytic_id": "AN0690",
   "detection_strategy_id": "DET0247",
   "analytic_name": "Analytic 0690",
   "platforms": "IaaS",
   "log_sources": "Instance Start (AWS:CloudTrail) | Cloud Storage Creation (AWS:CloudTrail) | User Account Metadata (CloudTrail:GetCallerIdentity) | Network Connection Creation (AWS:VPCFlowLogs)",
   "log_sources_ja": "インスタンス起動 (AWS:CloudTrail) | クラウドストレージ作成 (AWS:CloudTrail) | ユーザーアカウントメタデータ (CloudTrail:GetCallerIdentity) | ネットワーク接続確立 (AWS:VPCFlowLogs)",
   "tuning": "UnusedRegionList | TimeWindow | AllowedServiceList | OutboundTrafficThreshold",
   "detection_logic_en": "Detects creation of cloud instances, services, or resources in normally unused or unsupported regions, especially following initial account access or credential use from known regions. Correlates resource provisioning across regions with absence of historical usage and alerting from standard logging services (e.g., GuardDuty not enabled in that region)."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1542",
   "technique_ja": "OS起動前ブート",
   "technique_en": "Pre-OS Boot",
   "analytic_id": "AN0774",
   "detection_strategy_id": "DET0278",
   "analytic_name": "Analytic 0774",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Drive Access (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | ドライブアクセス (WinEventLog:Sysmon)",
   "tuning": "AllowedFirmwareUpdateTools | TimeWindow | EntropyThreshold",
   "detection_logic_en": "Unusual modification of boot records (MBR, VBR) or EFI partitions not associated with legitimate patch cycles or OS upgrades. Registry or WMI events associated with firmware update tools executed from unexpected parent processes. API calls (e.g., DeviceIoControl) writing directly to raw disk sectors. Subsequent abnormal boot configuration changes followed by unsigned driver loads."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1542",
   "technique_ja": "OS起動前ブート",
   "technique_en": "Pre-OS Boot",
   "analytic_id": "AN0775",
   "detection_strategy_id": "DET0278",
   "analytic_name": "Analytic 0775",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Command Execution (auditd:EXECVE)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | コマンド実行 (auditd:EXECVE)",
   "tuning": "PackageManagerUpdateWhitelist | FilesystemPaths",
   "detection_logic_en": "Detection of writes to /boot or EFI directories outside of expected package manager updates. Monitoring kernel log and auditd events for attempts to overwrite bootloader binaries (e.g., grub, shim). Unexpected execution of efibootmgr or dd writing to /dev/sdX devices followed by boot parameter changes."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1542",
   "technique_ja": "OS起動前ブート",
   "technique_en": "Pre-OS Boot",
   "analytic_id": "AN0776",
   "detection_strategy_id": "DET0278",
   "analytic_name": "Analytic 0776",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog)",
   "tuning": "AllowedBootUtilities | BootParamBaseline",
   "detection_logic_en": "Abnormal modification of EFI firmware binaries in /System/Library/CoreServices/ or NVRAM parameters not associated with OS updates. Unified logs capturing calls to bless or nvram commands executed from untrusted parent processes. Sudden unsigned kext loads after EFI variable tampering."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1542",
   "technique_ja": "OS起動前ブート",
   "technique_en": "Pre-OS Boot",
   "analytic_id": "AN0777",
   "detection_strategy_id": "DET0278",
   "analytic_name": "Analytic 0777",
   "platforms": "Network Devices",
   "log_sources": "Firmware Modification (networkdevice:config) | Drive Modification (networkdevice:firmware)",
   "log_sources_ja": "ファームウェア変更 (networkdevice:config) | ドライブ変更 (networkdevice:firmware)",
   "tuning": "ApprovedFirmwareHashes | MaintenanceWindows",
   "detection_logic_en": "Unexpected firmware image uploads via TFTP/FTP/SCP. Configuration changes modifying boot image pointers. Logs showing boot variable redirection to non-standard images. Anomalous reboots immediately following firmware changes not tied to patch schedules."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1542.001",
   "technique_ja": "システムファームウェア",
   "technique_en": "System Firmware",
   "analytic_id": "AN0275",
   "detection_strategy_id": "DET0099",
   "analytic_name": "Analytic 0275",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Drive Access (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ドライブアクセス (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "AllowedFirmwareUpdateTools | TimeWindow | KnownGoodFirmwareHashes",
   "detection_logic_en": "Unexpected write operations to BIOS/UEFI firmware regions or EFI boot partitions that do not correlate with legitimate vendor firmware updates. API calls or utilities such as fwupdate.exe or vendor flash tools executed from non-administrative or non-IT management accounts. Suspicious raw disk writes targeting System Firmware GUID partitions followed by abnormal reboot sequences."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1542.001",
   "technique_ja": "システムファームウェア",
   "technique_en": "System Firmware",
   "analytic_id": "AN0276",
   "detection_strategy_id": "DET0099",
   "analytic_name": "Analytic 0276",
   "platforms": "Network Devices",
   "log_sources": "Firmware Modification (networkdevice:config) | Drive Modification (networkdevice:runtime)",
   "log_sources_ja": "ファームウェア変更 (networkdevice:config) | ドライブ変更 (networkdevice:runtime)",
   "tuning": "ApprovedFirmwareHashes | MaintenanceWindows | SourceIPWhitelist",
   "detection_logic_en": "Unauthorized firmware uploads to routers, switches, or firewalls via TFTP/FTP/SCP. Logs showing boot variable or startup image path changes redirecting to non-standard firmware images. Abnormal reboots or firmware rollback attempts following configuration modification events."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1542.002",
   "technique_ja": "コンポーネントファームウェア",
   "technique_en": "Component Firmware",
   "analytic_id": "AN0916",
   "detection_strategy_id": "DET0323",
   "analytic_name": "Analytic 0916",
   "platforms": "Windows",
   "log_sources": "Driver Load (WinEventLog:Sysmon) | Firmware Modification (firmware:integrity )",
   "log_sources_ja": "ドライバ読み込み (WinEventLog:Sysmon) | ファームウェア変更 (firmware:integrity )",
   "tuning": "KnownGoodFirmwareHashes | DriverAllowList | TimeWindow",
   "detection_logic_en": "Detection of anomalous driver and firmware interactions, including unsigned or unexpected firmware updates, driver loads linked to hardware components, and suspicious use of privileged APIs to read/write firmware or controller memory."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1542.002",
   "technique_ja": "コンポーネントファームウェア",
   "technique_en": "Component Firmware",
   "analytic_id": "AN0917",
   "detection_strategy_id": "DET0323",
   "analytic_name": "Analytic 0917",
   "platforms": "Linux",
   "log_sources": "Firmware Modification (auditd:SYSCALL) | Driver Load (linux:syslog)",
   "log_sources_ja": "ファームウェア変更 (auditd:SYSCALL) | ドライバ読み込み (linux:syslog)",
   "tuning": "FirmwareImageBaseline | AlertThresholds",
   "detection_logic_en": "Detection of suspicious use of ioctl/sysfs calls to access device firmware, unexpected flashing tools execution, and anomalous firmware checksums logged by SMART or kernel audit mechanisms."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1542.002",
   "technique_ja": "コンポーネントファームウェア",
   "technique_en": "Component Firmware",
   "analytic_id": "AN0918",
   "detection_strategy_id": "DET0323",
   "analytic_name": "Analytic 0918",
   "platforms": "macOS",
   "log_sources": "Firmware Modification (macos:unifiedlog)",
   "log_sources_ja": "ファームウェア変更 (macos:unifiedlog)",
   "tuning": "ApprovedKextList | EFIHashBaseline",
   "detection_logic_en": "Detection of EFI/firmware manipulation attempts via abnormal driver loads, unsigned kexts, or tampered NVRAM variables associated with component firmware configuration."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1542.003",
   "technique_ja": "ブートキット",
   "technique_en": "Bootkit",
   "analytic_id": "AN0428",
   "detection_strategy_id": "DET0150",
   "analytic_name": "Analytic 0428",
   "platforms": "Windows",
   "log_sources": "Drive Access (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ドライブアクセス (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "KnownGoodMBRHashes | ESPFileWhitelist | TimeWindow",
   "detection_logic_en": "Detection of raw access to physical drives, modification of boot records (MBR/VBR), and suspicious file creation or alteration within the EFI System Partition (ESP). Correlates privileged process execution with low-level disk modification and unexpected driver or firmware interactions."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1542.003",
   "technique_ja": "ブートキット",
   "technique_en": "Bootkit",
   "analytic_id": "AN0429",
   "detection_strategy_id": "DET0150",
   "analytic_name": "Analytic 0429",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Drive Modification (linux:syslog)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | ドライブ変更 (linux:syslog)",
   "tuning": "BootloaderHashBaseline | EFIFileAllowlist | AlertThresholds",
   "detection_logic_en": "Detection of suspicious write operations to block devices, modifications of bootloader files (GRUB, initrd, vmlinuz), and unexpected changes within the EFI System Partition. Monitors privileged execution of utilities like dd, grub-install, or efibootmgr that modify boot sectors or loader entries."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1542.004",
   "technique_ja": "ROMMONkit",
   "technique_en": "ROMMONkit",
   "analytic_id": "AN0497",
   "detection_strategy_id": "DET0175",
   "analytic_name": "Analytic 0497",
   "platforms": "Network Devices",
   "log_sources": "Firmware Modification (networkdevice:config) | OS API Execution (networkdevice:syslog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "ファームウェア変更 (networkdevice:config) | OS API実行 (networkdevice:syslog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "ApprovedROMMONVersions | TimeWindow | AdminUserContext",
   "detection_logic_en": "Detection of anomalous ROMMON image changes or upgrades, unexpected reboots following firmware updates, and unauthorized use of firmware upgrade commands or TFTP transfers. Correlation of config modification, privilege escalation, and boot cycle anomalies provides visibility into ROMMON tampering attempts."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1542.005",
   "technique_ja": "TFTPブート",
   "technique_en": "TFTP Boot",
   "analytic_id": "AN1603",
   "detection_strategy_id": "DET0582",
   "analytic_name": "Analytic 1603",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:config) | Firmware Modification (networkdevice:syslog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (networkdevice:config) | ファームウェア変更 (networkdevice:syslog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "ApprovedTFTPServers | TimeWindow | BaselineBootImageHash",
   "detection_logic_en": "Detection of unauthorized changes to boot configurations pointing to TFTP servers, unusual firmware loads during netbooting, or suspicious TFTP traffic. Correlation of boot config modifications, command history logs, and unexpected system image hashes provides detection coverage for adversaries attempting to persist via malicious TFTP boot images."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564",
   "technique_ja": "アーティファクトの隠蔽",
   "technique_en": "Hide Artifacts",
   "analytic_id": "AN1384",
   "detection_strategy_id": "DET0502",
   "analytic_name": "Analytic 1384",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "FileExtensions | ADSDetection",
   "detection_logic_en": "Abuse of file/registry attributes to hide malicious files, directories, or services. Defender view: detection of attrib.exe setting hidden/system flags, creation of Alternate Data Streams, or registry keys altering file visibility."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564",
   "technique_ja": "アーティファクトの隠蔽",
   "technique_en": "Hide Artifacts",
   "analytic_id": "AN1385",
   "detection_strategy_id": "DET0502",
   "analytic_name": "Analytic 1385",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:EXECVE) | File Creation (auditd:FILE)",
   "log_sources_ja": "コマンド実行 (auditd:EXECVE) | ファイル作成 (auditd:FILE)",
   "tuning": "DirectoryScope | AttributeFlags",
   "detection_logic_en": "Hidden file creation using leading '.' or file attribute changes with chattr (immutable/hidden flags). Defender view: detect execution of chattr, lsattr anomalies, and unusual hidden files appearing in system directories."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564",
   "technique_ja": "アーティファクトの隠蔽",
   "technique_en": "Hide Artifacts",
   "analytic_id": "AN1386",
   "detection_strategy_id": "DET0502",
   "analytic_name": "Analytic 1386",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Creation (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル作成 (macos:unifiedlog)",
   "tuning": "HiddenDirectories",
   "detection_logic_en": "Hidden files via 'chflags hidden' or Apple-specific attributes, LaunchAgents/LaunchDaemons placed in non-standard hidden directories. Defender view: detect command execution modifying file flags and unusual plist creation in hidden paths."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564",
   "technique_ja": "アーティファクトの隠蔽",
   "technique_en": "Hide Artifacts",
   "analytic_id": "AN1387",
   "detection_strategy_id": "DET0502",
   "analytic_name": "Analytic 1387",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:shell) | File Metadata (esxi:syslog)",
   "log_sources_ja": "コマンド実行 (esxi:shell) | ファイルメタデータ (esxi:syslog)",
   "tuning": "VMFileScope",
   "detection_logic_en": "Abuse of VMFS or ESXi shell to hide datastore files, renaming/moving VMDK or VMX files into hidden directories. Defender view: anomalous ESXi shell commands or file operations obscuring VM artifacts."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564",
   "technique_ja": "アーティファクトの隠蔽",
   "technique_en": "Hide Artifacts",
   "analytic_id": "AN1388",
   "detection_strategy_id": "DET0502",
   "analytic_name": "Analytic 1388",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified)",
   "tuning": "MacroScope",
   "detection_logic_en": "Malicious macros or embedded objects hidden within Office documents by renaming streams or using hidden OLE objects. Defender view: detection of hidden macro streams or objects in documents correlated with anomalous execution."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.001",
   "technique_ja": "隠しファイルとディレクトリ",
   "technique_en": "Hidden Files and Directories",
   "analytic_id": "AN0091",
   "detection_strategy_id": "DET0032",
   "analytic_name": "Analytic 0091",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "MonitoredExtensions | ADSMonitoring",
   "detection_logic_en": "Suspicious use of attrib.exe or PowerShell commands to set hidden attributes on files/directories. Defender view: processes modifying file attributes to 'hidden' or creating files with ADS (alternate data streams)."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.001",
   "technique_ja": "隠しファイルとディレクトリ",
   "technique_en": "Hidden Files and Directories",
   "analytic_id": "AN0092",
   "detection_strategy_id": "DET0032",
   "analytic_name": "Analytic 0092",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:FILE) | Command Execution (auditd:EXECVE)",
   "log_sources_ja": "ファイル作成 (auditd:FILE) | コマンド実行 (auditd:EXECVE)",
   "tuning": "DirectoryScope",
   "detection_logic_en": "Creation of files or directories with a leading '.' in privileged directories (/etc, /var, /usr/bin). Defender view: monitoring auditd logs for file creations where name begins with '.' and correlated with unusual user/process context."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.001",
   "technique_ja": "隠しファイルとディレクトリ",
   "technique_en": "Hidden Files and Directories",
   "analytic_id": "AN0093",
   "detection_strategy_id": "DET0032",
   "analytic_name": "Analytic 0093",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Metadata (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイルメタデータ (macos:unifiedlog)",
   "tuning": "HiddenAttributeScope",
   "detection_logic_en": "Use of chflags hidden or SetFile -a V commands to hide files, or creation of hidden files with leading '.'. Defender view: monitoring process execution and file metadata changes setting UF_HIDDEN attribute."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.002",
   "technique_ja": "隠しユーザー",
   "technique_en": "Hidden Users",
   "analytic_id": "AN1001",
   "detection_strategy_id": "DET0353",
   "analytic_name": "Analytic 1001",
   "platforms": "Windows",
   "log_sources": "User Account Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "ユーザーアカウント作成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "AccountScope | BaselineHiddenUsers",
   "detection_logic_en": "Registry modifications to HKLM\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\UserList setting user visibility to 0, or creation of user accounts not shown on login screen. Defender view: correlation of account creation with registry edits that mark users hidden."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.002",
   "technique_ja": "隠しユーザー",
   "technique_en": "Hidden Users",
   "analytic_id": "AN1002",
   "detection_strategy_id": "DET0353",
   "analytic_name": "Analytic 1002",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:EXECVE) | File Modification (auditd:FILE)",
   "log_sources_ja": "コマンド実行 (auditd:EXECVE) | ファイル変更 (auditd:FILE)",
   "tuning": "DisplayManagerScope",
   "detection_logic_en": "Use of gsettings or direct Display Manager modifications to hide users from greeter login screen. Defender view: anomalous command execution modifying org.gnome.login-screen or other greeter configurations."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.002",
   "technique_ja": "隠しユーザー",
   "technique_en": "Hidden Users",
   "analytic_id": "AN1003",
   "detection_strategy_id": "DET0353",
   "analytic_name": "Analytic 1003",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Modification (macos:unifiedlog) | User Account Metadata (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog) | ユーザーアカウントメタデータ (macos:unifiedlog)",
   "tuning": "UIDThreshold | PlistScope",
   "detection_logic_en": "User creation or modification via dscl with IsHidden=1, UID<500, or plist edits to com.apple.loginwindow Hide500Users flag. Defender view: correlation of hidden account attributes with login screen exclusion."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.003",
   "technique_ja": "隠しウィンドウ",
   "technique_en": "Hidden Window",
   "analytic_id": "AN0360",
   "detection_strategy_id": "DET0128",
   "analytic_name": "Analytic 0360",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "HiddenProcessScope | ParentProcessCorrelation",
   "detection_logic_en": "Suspicious use of scripting parameters or registry edits to hide process windows (e.g., powershell.exe -WindowStyle Hidden, or registry modifications pushing window positions off screen). Defender view: correlation of hidden execution with anomalous process lineage or hVNC-like CreateDesktop API calls."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.003",
   "technique_ja": "隠しウィンドウ",
   "technique_en": "Hidden Window",
   "analytic_id": "AN0361",
   "detection_strategy_id": "DET0128",
   "analytic_name": "Analytic 0361",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:EXECVE) | Process Metadata (auditd:SYSCALL)",
   "log_sources_ja": "コマンド実行 (auditd:EXECVE) | プロセスメタデータ (auditd:SYSCALL)",
   "tuning": "DisplayScope",
   "detection_logic_en": "Suspicious invocation of GUI utilities or scripts with suppressed or redirected windowing options. Defender view: detection of X11 or Wayland calls to spawn windows that do not appear on active displays, or use of nohup/screen/tmux to mask interactive shells."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.003",
   "technique_ja": "隠しウィンドウ",
   "technique_en": "Hidden Window",
   "analytic_id": "AN0362",
   "detection_strategy_id": "DET0128",
   "analytic_name": "Analytic 0362",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "PlistScope | UserContext",
   "detection_logic_en": "Modification of plist files to set apple.awt.UIElement or similar flags hiding app icons and windows, and dscl/command-line activity that suppresses visibility. Defender view: correlation of plist modifications with unexpected hidden user applications."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.004",
   "technique_ja": "NTFSファイル属性",
   "technique_en": "NTFS File Attributes",
   "analytic_id": "AN1206",
   "detection_strategy_id": "DET0432",
   "analytic_name": "Analytic 1206",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Kernel-File)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Kernel-File)",
   "tuning": "ADSPathWhitelist | ProcessScope | TimeWindow",
   "detection_logic_en": "Suspicious use of NTFS file attributes such as Alternate Data Streams (ADS) or Extended Attributes (EA) to hide data. Defender perspective: anomalous file creations or modifications containing colon syntax (file.ext:ads), API calls like ZwSetEaFile/ZwQueryEaFile, or PowerShell/Windows utilities interacting with -stream parameters. Correlation across file metadata anomalies, process lineage, and command execution provides context."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.005",
   "technique_ja": "隠しファイルシステム",
   "technique_en": "Hidden File System",
   "analytic_id": "AN1271",
   "detection_strategy_id": "DET0461",
   "analytic_name": "Analytic 1271",
   "platforms": "Windows",
   "log_sources": "File Modification (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon) | Firmware Modification (etw:Microsoft-Windows-Kernel-Storage)",
   "log_sources_ja": "ファイル変更 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ファームウェア変更 (etw:Microsoft-Windows-Kernel-Storage)",
   "tuning": "MonitoredRegistryKeys | DiskIOThreshold | TimeWindow",
   "detection_logic_en": "Anomalous creation or mounting of hidden partitions or virtual file systems. Defender view: detection of registry modifications linked to non-standard file systems, suspicious disk I/O patterns, or bootkit-like behavior where hidden volumes are accessed outside normal file system APIs."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.005",
   "technique_ja": "隠しファイルシステム",
   "technique_en": "Hidden File System",
   "analytic_id": "AN1272",
   "detection_strategy_id": "DET0461",
   "analytic_name": "Analytic 1272",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Command Execution (linux:syslog)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | コマンド実行 (linux:syslog)",
   "tuning": "AllowedMountPoints | UserContext",
   "detection_logic_en": "Unusual mounting of loopback or pseudo file systems not aligned with legitimate administrative activity. Defender view: monitoring auditd and syslog for mount commands involving suspicious mount points, reserved blocks, or device mappings indicative of hidden partitions."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.005",
   "technique_ja": "隠しファイルシステム",
   "technique_en": "Hidden File System",
   "analytic_id": "AN1273",
   "detection_strategy_id": "DET0461",
   "analytic_name": "Analytic 1273",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog)",
   "tuning": "MonitoredPlistPaths | ProcessScope",
   "detection_logic_en": "Hidden file system use through APFS containers or custom plist configuration. Defender view: anomalous use of hdiutil or diskutil to attach hidden partitions, modification of plist entries tied to system volumes, or suspicious raw disk access."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.006",
   "technique_ja": "仮想インスタンスの実行",
   "technique_en": "Run Virtual Instance",
   "analytic_id": "AN0909",
   "detection_strategy_id": "DET0321",
   "analytic_name": "Analytic 0909",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Service Creation (WinEventLog:System) | Windows Registry Key Modification (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | サービス作成 (WinEventLog:System) | Windowsレジストリキー変更 (WinEventLog:Security)",
   "tuning": "VirtualizationBinaryWhitelist | TimeWindow",
   "detection_logic_en": "Unusual execution of virtualization binaries (VBoxManage.exe, vmware-vmx.exe, vmwp.exe) with headless or suppressed notification arguments. Registry and service modifications linked to virtualization installs. Defender view: anomalies in process creation, service metadata, and registry writes tied to enabling hidden VMs."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.006",
   "technique_ja": "仮想インスタンスの実行",
   "technique_en": "Run Virtual Instance",
   "analytic_id": "AN0910",
   "detection_strategy_id": "DET0321",
   "analytic_name": "Analytic 0910",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Creation (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル作成 (auditd:SYSCALL)",
   "tuning": "ImageDirectoryWhitelist | UserContext",
   "detection_logic_en": "Execution of QEMU, KVM, or VirtualBox processes with unusual flags (e.g., '-nographic', '-snapshot'). File creation of VM images in atypical directories. Defender view: monitoring audit logs for process executions and file modifications linked to hidden virtualization."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.006",
   "technique_ja": "仮想インスタンスの実行",
   "technique_en": "Run Virtual Instance",
   "analytic_id": "AN0911",
   "detection_strategy_id": "DET0321",
   "analytic_name": "Analytic 0911",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog)",
   "tuning": "PlistKeyScope",
   "detection_logic_en": "Execution of virtualization binaries (Parallels, VMware Fusion, VirtualBox) with arguments to hide UI. File monitoring for plist modifications indicating hidden virtualization behavior. Defender perspective: tracking process lineage and file modifications in system configs."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.006",
   "technique_ja": "仮想インスタンスの実行",
   "technique_en": "Run Virtual Instance",
   "analytic_id": "AN0912",
   "detection_strategy_id": "DET0321",
   "analytic_name": "Analytic 0912",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:hostd) | Image Metadata (esxi:vmkernel)",
   "log_sources_ja": "コマンド実行 (esxi:hostd) | イメージメタデータ (esxi:vmkernel)",
   "tuning": "VMInventorySync",
   "detection_logic_en": "Direct execution of /bin/vmx or presence of rogue .vmx files not registered in vCenter inventory. Defender perspective: anomalous commands in shell history, edits to rc.local.d/local.sh for persistence."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.007",
   "technique_ja": "VBAストンピング",
   "technique_en": "VBA Stomping",
   "analytic_id": "AN0034",
   "detection_strategy_id": "DET0012",
   "analytic_name": "Analytic 0034",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "MonitoredExtensions | TimeWindow",
   "detection_logic_en": "Discrepancies between VBA source code and p-code inside Office documents. Defender perspective: anomalies in file metadata streams, execution of Office processes loading macros without source code consistency, and script execution with no corresponding source metadata."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.007",
   "technique_ja": "VBAストンピング",
   "technique_en": "VBA Stomping",
   "analytic_id": "AN0035",
   "detection_strategy_id": "DET0012",
   "analytic_name": "Analytic 0035",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Metadata (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルメタデータ (linux:syslog)",
   "tuning": "ScannerTooling",
   "detection_logic_en": "Execution of Wine or LibreOffice macros with inconsistent VBA metadata. Defender perspective: file analysis showing p-code embedded without matching source streams."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.007",
   "technique_ja": "VBAストンピング",
   "technique_en": "VBA Stomping",
   "analytic_id": "AN0036",
   "detection_strategy_id": "DET0012",
   "analytic_name": "Analytic 0036",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Metadata (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイルメタデータ (macos:unifiedlog)",
   "tuning": "OfficeVersionScope",
   "detection_logic_en": "Opening of Office files where VBA source code appears benign or missing, but p-code remains active. Defender perspective: process execution of Office apps with macro execution lacking visible source components."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.008",
   "technique_ja": "メール隠蔽ルール",
   "technique_en": "Email Hiding Rules",
   "analytic_id": "AN0551",
   "detection_strategy_id": "DET0192",
   "analytic_name": "Analytic 0551",
   "platforms": "Windows",
   "log_sources": "Command Execution (WinEventLog:PowerShell) | Application Log Content (m365:unified)",
   "log_sources_ja": "コマンド実行 (WinEventLog:PowerShell) | アプリケーションログ内容 (m365:unified)",
   "tuning": "SuspiciousKeywords | UserContext",
   "detection_logic_en": "Suspicious creation or modification of inbox rules through PowerShell (New-InboxRule, Set-InboxRule) to automatically delete, move, or hide emails. Defender perspective: unusual rule activity correlated with mailbox access and filtering patterns."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.008",
   "technique_ja": "メール隠蔽ルール",
   "technique_en": "Email Hiding Rules",
   "analytic_id": "AN0552",
   "detection_strategy_id": "DET0192",
   "analytic_name": "Analytic 0552",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "WatchedPlistFiles",
   "detection_logic_en": "Alterations to plist configuration files (RulesActiveState.plist, SyncedRules.plist, UnsyncedRules.plist, MessageRules.plist) that define email hiding or filtering rules. Defender perspective: unexpected changes in these files associated with Mail.app processes."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.008",
   "technique_ja": "メール隠蔽ルール",
   "technique_en": "Email Hiding Rules",
   "analytic_id": "AN0553",
   "detection_strategy_id": "DET0192",
   "analytic_name": "Analytic 0553",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | Application Log Content (ApplicationLog:MailServer)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | アプリケーションログ内容 (ApplicationLog:MailServer)",
   "tuning": "MailServerLogs",
   "detection_logic_en": "Rule manipulation through local email clients (e.g., Evolution, Thunderbird) or server-side filtering scripts (e.g., sieve) creating conditions to move or discard emails with security-related keywords."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.008",
   "technique_ja": "メール隠蔽ルール",
   "technique_en": "Email Hiding Rules",
   "analytic_id": "AN0554",
   "detection_strategy_id": "DET0192",
   "analytic_name": "Analytic 0554",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified)",
   "tuning": "RuleScope",
   "detection_logic_en": "Suspicious rule creation within Outlook or Exchange clients, including auto-move or delete conditions tied to incident or security alert keywords. Defender perspective: correlation between missing inbound emails and newly added mailbox rules."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.009",
   "technique_ja": "リソースフォーク",
   "technique_en": "Resource Forking",
   "analytic_id": "AN1609",
   "detection_strategy_id": "DET0584",
   "analytic_name": "Analytic 1609",
   "platforms": "macOS",
   "log_sources": "File Metadata (macos:unifiedlog) | Command Execution (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ファイルメタデータ (macos:unifiedlog) | コマンド実行 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "ResourceForkSizeThreshold | MonitoredDirectories | CorrelatedActivityWindow",
   "detection_logic_en": "Unexpected creation or modification of files with `com.apple.ResourceFork` extended attributes containing unusually large or non-standard data. Defender perspective: detection of resource forks in contexts where they are uncommon, especially when paired with process execution or network activity."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.010",
   "technique_ja": "プロセス引数スプーフィング",
   "technique_en": "Process Argument Spoofing",
   "analytic_id": "AN0126",
   "detection_strategy_id": "DET0045",
   "analytic_name": "Analytic 0126",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "SuspendedProcessWindow | SensitiveProcesses | BehavioralCorrelationWindow",
   "detection_logic_en": "Inconsistencies between process command-line arguments logged at creation time and subsequent process behavior. Defender perspective: monitoring for processes launched in a suspended state, followed by memory modifications (e.g., WriteProcessMemory targeting the PEB) that overwrite arguments before execution resumes. Detection also includes observing anomalous behaviors from processes whose logged arguments do not align with executed activity (e.g., network connections, file writes, or registry modifications)."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.011",
   "technique_ja": "プロセス割り込みの無視",
   "technique_en": "Ignore Process Interrupts",
   "analytic_id": "AN0181",
   "detection_strategy_id": "DET0067",
   "analytic_name": "Analytic 0181",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "IgnoredSignals | ProcessLifetimeThreshold",
   "detection_logic_en": "Execution of processes using nohup or shell redirection to ignore SIGHUP and continue running after session termination. Defender perspective: correlation between commands including nohup, disowned jobs, or `&` suffix with continued process execution after parent terminal exit."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.011",
   "technique_ja": "プロセス割り込みの無視",
   "technique_en": "Ignore Process Interrupts",
   "analytic_id": "AN0182",
   "detection_strategy_id": "DET0067",
   "analytic_name": "Analytic 0182",
   "platforms": "Windows",
   "log_sources": "Command Execution (WinEventLog:PowerShell) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "コマンド実行 (WinEventLog:PowerShell) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "MonitoredCmdlets | ErrorActionThreshold",
   "detection_logic_en": "PowerShell or script execution with parameters that suppress errors or ignore user interrupts, such as `-ErrorAction SilentlyContinue`. Defender perspective: detecting discrepancies between suppressed error arguments and continued execution behavior."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.011",
   "technique_ja": "プロセス割り込みの無視",
   "technique_en": "Ignore Process Interrupts",
   "analytic_id": "AN0183",
   "detection_strategy_id": "DET0067",
   "analytic_name": "Analytic 0183",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "WatchedShells | PersistenceCorrelationWindow",
   "detection_logic_en": "Use of nohup, disown, or AppleScript constructs to suppress process interrupts. Defender perspective: commands containing nohup or hidden background tasks (`osascript` with persistent execution) correlated with processes surviving user logouts."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.012",
   "technique_ja": "ファイル/パス除外",
   "technique_en": "File/Path Exclusions",
   "analytic_id": "AN0139",
   "detection_strategy_id": "DET0051",
   "analytic_name": "Analytic 0139",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Access (WinEventLog:Security)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Security)",
   "tuning": "ExcludedPaths | ProcessAllowlist",
   "detection_logic_en": "Creation or modification of files in directories known to be excluded from AV scanning (e.g., C:\\Windows\\Temp, Exchange server directories, or default AV exclusions). Defender perspective: correlate file creation with execution behavior or anomalous parent processes writing to excluded paths."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.012",
   "technique_ja": "ファイル/パス除外",
   "technique_en": "File/Path Exclusions",
   "analytic_id": "AN0140",
   "detection_strategy_id": "DET0051",
   "analytic_name": "Analytic 0140",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:SYSCALL) | File Metadata (auditd:PATH)",
   "log_sources_ja": "ファイル作成 (auditd:SYSCALL) | ファイルメタデータ (auditd:PATH)",
   "tuning": "ExcludedDirectories | CorrelationWindow",
   "detection_logic_en": "Adversaries writing or moving payloads into directories configured as AV/EDR exclusion paths (e.g., /tmp, /var/lib, or custom directories from auditd exclusion rules). Defender perspective: detect file creation in paths matching known exclusions correlated with unusual parent processes."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.012",
   "technique_ja": "ファイル/パス除外",
   "technique_en": "File/Path Exclusions",
   "analytic_id": "AN0141",
   "detection_strategy_id": "DET0051",
   "analytic_name": "Analytic 0141",
   "platforms": "macOS",
   "log_sources": "File Creation (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ファイル作成 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "AVExclusionPaths | ProcessContext",
   "detection_logic_en": "Suspicious file creation or modification in directories ignored by XProtect or AV exclusions (e.g., ~/Library, temporary cache directories). Defender perspective: monitor file events in ignored paths with correlation to execution or persistence activity."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.013",
   "technique_ja": "バインドマウント",
   "technique_en": "Bind Mounts",
   "analytic_id": "AN1196",
   "detection_strategy_id": "DET0428",
   "analytic_name": "Analytic 1196",
   "platforms": "Linux",
   "log_sources": "OS API Execution (auditd:SYSCALL) | File Creation (auditd:PATH) | Process Metadata (linux:osquery)",
   "log_sources_ja": "OS API実行 (auditd:SYSCALL) | ファイル作成 (auditd:PATH) | プロセスメタデータ (linux:osquery)",
   "tuning": "BindMountFlags | WatchedProcPaths | CorrelationWindow",
   "detection_logic_en": "Abuse of bind mounts to obscure process directories. Defender perspective: detecting anomalous mount operations where a process’s /proc entry is remapped to another directory, often hiding malicious activity from native utilities (ps, top). Behavior chain includes: (1) execution of `mount` with `-o bind` or `-B` flags, (2) modification of /proc entries inconsistent with expected process lineage, and (3) subsequent anomalous activity from processes whose metadata no longer matches execution context."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.014",
   "technique_ja": "拡張属性",
   "technique_en": "Extended Attributes",
   "analytic_id": "AN1135",
   "detection_strategy_id": "DET0406",
   "analytic_name": "Analytic 1135",
   "platforms": "Linux",
   "log_sources": "File Metadata (auditd:SYSCALL) | Command Execution (auditd:EXECVE)",
   "log_sources_ja": "ファイルメタデータ (auditd:SYSCALL) | コマンド実行 (auditd:EXECVE)",
   "tuning": "XattrNamespaces | PayloadSizeThreshold | CorrelationWindow",
   "detection_logic_en": "Abuse of extended attributes (xattrs) to embed hidden payloads into legitimate files. Defender perspective: detect anomalous use of setfattr or getfattr commands, or direct syscalls (setxattr, getxattr) where attributes are unusually large or contain encoded data. Behavior chain includes: (1) execution of setfattr with suspicious namespaces (user., trusted.), (2) file metadata modification inconsistent with file size/hash, and (3) subsequent process execution reading attributes followed by decoding activity."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1564.014",
   "technique_ja": "拡張属性",
   "technique_en": "Extended Attributes",
   "analytic_id": "AN1136",
   "detection_strategy_id": "DET0406",
   "analytic_name": "Analytic 1136",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Metadata (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイルメタデータ (macos:unifiedlog)",
   "tuning": "WatchedXattrKeys | EntropyThreshold | ProcessContext",
   "detection_logic_en": "Abuse of extended attributes (xattrs) to hide payloads in com.apple.* or custom keys. Defender perspective: monitor suspicious use of xattr command with -w (write) and -p (print) flags, especially when followed by execution of interpreters like bash, Python, or osascript. Behavior chain includes: (1) suspicious file modification with new com.apple.* attributes, (2) attribute content inconsistent with expected metadata tags (e.g., high entropy), (3) subsequent process execution correlated with extraction of the attribute."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1574",
   "technique_ja": "実行フローの乗っ取り",
   "technique_en": "Hijack Execution Flow",
   "analytic_id": "AN0609",
   "detection_strategy_id": "DET0218",
   "analytic_name": "Analytic 0609",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Security) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "ServiceBaseline | AllowedDllPaths | TimeWindow",
   "detection_logic_en": "Unusual modifications to service binary paths, registry keys, or DLL load paths resulting in alternate execution flow. Defender observes registry key modifications, suspicious file writes into system directories, and processes loading libraries from abnormal paths."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1574",
   "technique_ja": "実行フローの乗っ取り",
   "technique_en": "Hijack Execution Flow",
   "analytic_id": "AN0610",
   "detection_strategy_id": "DET0218",
   "analytic_name": "Analytic 0610",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Service Metadata (linux:syslog) | Process Creation (linux:osquery)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | サービスメタデータ (linux:syslog) | プロセス生成 (linux:osquery)",
   "tuning": "MonitoredDirectories | EnvVarMonitors",
   "detection_logic_en": "Adversary manipulation of shared library paths, environment variables, or replacement of service binaries. Defender observes suspicious modifications in /etc/ld.so.preload, service config changes, or file writes replacing existing executables."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1574",
   "technique_ja": "実行フローの乗っ取り",
   "technique_en": "Hijack Execution Flow",
   "analytic_id": "AN0611",
   "detection_strategy_id": "DET0218",
   "analytic_name": "Analytic 0611",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:unifiedlog) | Module Load (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog) | モジュール読み込み (macos:unifiedlog)",
   "tuning": "AllowedDylibPaths | PlistMonitors",
   "detection_logic_en": "Abuse of DYLD_INSERT_LIBRARIES or hijacking framework paths for malicious libraries. Defender observes processes invoking abnormal dylibs, modified plist files, or persistence entries pointing to altered binaries."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1574.001",
   "technique_ja": "DLL",
   "technique_en": "DLL",
   "analytic_id": "AN0577",
   "detection_strategy_id": "DET0201",
   "analytic_name": "Analytic 0577",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "AllowedDllPaths | ProcessAllowList | TimeWindow | HashBaseline",
   "detection_logic_en": "DLL hijacking behaviors including unexpected DLL loads from non-standard directories, replacement of DLLs, phantom DLL insertion, redirection file creation, and substitution of legitimate DLLs. Defender correlates file system modifications, registry changes, and module load telemetry to detect abnormal DLL behavior in trusted processes."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1574.004",
   "technique_ja": "Dylibハイジャック",
   "technique_en": "Dylib Hijacking",
   "analytic_id": "AN0435",
   "detection_strategy_id": "DET0152",
   "analytic_name": "Analytic 0435",
   "platforms": "macOS",
   "log_sources": "Module Load (macos:unifiedlog) | File Creation (macos:unifiedlog) | File Modification (macos:unifiedlog)",
   "log_sources_ja": "モジュール読み込み (macos:unifiedlog) | ファイル作成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog)",
   "tuning": "MonitoredDirectories | BaselineDylibs | CorrelationWindow",
   "detection_logic_en": "Detection focuses on adversaries placing or modifying malicious dylibs in locations searched by legitimate applications. From the defender’s perspective, observable patterns include unexpected creation or modification of dylib files in application bundle paths, unusual module loads by processes compared to historical baselines, and execution of applications loading dylibs from suspicious directories (e.g., /tmp, user-controlled paths). Correlation across file system changes, process execution, and module loads provides high-fidelity detection."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1574.005",
   "technique_ja": "実行可能インストーラのファイル権限の弱点",
   "technique_en": "Executable Installer File Permissions Weakness",
   "analytic_id": "AN0108",
   "detection_strategy_id": "DET0038",
   "analytic_name": "Analytic 0108",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "MonitoredDirectories | HashBaseline | TimeWindow | UserContext",
   "detection_logic_en": "Executables written or modified in installer directories (e.g., %TEMP% subdirectories or Program Files installer paths) followed by execution under elevated context. Defender observes abnormal file replacement activity, process creation by installer processes pointing to attacker-supplied binaries, and unexpected module loads in elevated processes."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1574.006",
   "technique_ja": "動的リンカーハイジャック",
   "technique_en": "Dynamic Linker Hijacking",
   "analytic_id": "AN1209",
   "detection_strategy_id": "DET0435",
   "analytic_name": "Analytic 1209",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Creation (auditd:PATH) | Process Metadata (linux:osquery)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル作成 (auditd:PATH) | プロセスメタデータ (linux:osquery)",
   "tuning": "WatchedEnvVars | MonitoredDirectories | CorrelationWindow",
   "detection_logic_en": "Detection focuses on identifying abuse of LD_PRELOAD and related linker variables. Defender perspective: monitor unexpected setting or modification of LD_PRELOAD in shell initialization scripts or environment exports, file creation of suspicious shared libraries, and correlation of these modifications with anomalous process execution. Key signals include execve events with LD_PRELOAD defined, newly created .so files in user directories, and processes hooking libc functions exhibiting abnormal behavior."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1574.006",
   "technique_ja": "動的リンカーハイジャック",
   "technique_en": "Dynamic Linker Hijacking",
   "analytic_id": "AN1210",
   "detection_strategy_id": "DET0435",
   "analytic_name": "Analytic 1210",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:unifiedlog) | Module Load (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog) | モジュール読み込み (macos:unifiedlog)",
   "tuning": "WatchedEnvVars | BaselineDylibs | MonitoredDirectories",
   "detection_logic_en": "Detection centers on DYLD_INSERT_LIBRARIES and DYLD_LIBRARY_PATH abuse. Defender perspective: monitor for modification of these environment variables in shell or plist files, file creation of dylibs in user-controlled paths, and correlation of environment variable usage with unexpected module loads by user applications. Suspicious indicators include processes with DYLD_INSERT_LIBRARIES set, execution of applications loading untrusted dylibs, and anomalies in module load history."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1574.007",
   "technique_ja": "PATH環境変数によるパス横取り",
   "technique_en": "Path Interception by PATH Environment Variable",
   "analytic_id": "AN0009",
   "detection_strategy_id": "DET0004",
   "analytic_name": "Analytic 0009",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "MonitoredRegistryKeys | SuspiciousBinaryList | TimeWindow",
   "detection_logic_en": "Abnormal modification of the PATH environment variable or registry keys controlling system paths, combined with execution of binaries named after legitimate system tools from user-writable directories. Defender correlates registry modifications, file creation of suspicious binaries, and process execution paths inconsistent with baseline system directories."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1574.007",
   "technique_ja": "PATH環境変数によるパス横取り",
   "technique_en": "Path Interception by PATH Environment Variable",
   "analytic_id": "AN0010",
   "detection_strategy_id": "DET0004",
   "analytic_name": "Analytic 0010",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (linux:osquery)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (linux:osquery)",
   "tuning": "MonitoredShellConfigs | AllowedUserBins",
   "detection_logic_en": "User modification of the $PATH environment variable in shell configuration files or direct runtime PATH changes, followed by execution of binaries from user-controlled directories. Defender observes file edits to ~/.bashrc, ~/.profile, or /etc/paths.d and process execution resolving to unexpected binary locations."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1574.007",
   "technique_ja": "PATH環境変数によるパス横取り",
   "technique_en": "Path Interception by PATH Environment Variable",
   "analytic_id": "AN0011",
   "detection_strategy_id": "DET0004",
   "analytic_name": "Analytic 0011",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "WatchedPathsDirs | TrustedExecutables",
   "detection_logic_en": "Modification of PATH or HOME environment variables through shell config files, launchctl, or /etc/paths.d entries, combined with process execution from attacker-controlled directories. Defender correlates file changes in /etc/paths.d with process execution resolving to malicious binaries."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1574.008",
   "technique_ja": "検索順ハイジャックによるパス横取り",
   "technique_en": "Path Interception by Search Order Hijacking",
   "analytic_id": "AN1560",
   "detection_strategy_id": "DET0564",
   "analytic_name": "Analytic 1560",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "SuspiciousBinaryList | MonitoredDirectories | TimeWindow | ParentProcessBaseline",
   "detection_logic_en": "Processes executing binaries named after legitimate system utilities (e.g., net.exe, findstr.exe, python.exe) from non-standard or application-specific directories, combined with file creation or modification events for such binaries. Defender correlates file writes in vulnerable directories, process execution paths inconsistent with baseline system paths, and abnormal parent-child relationships in process lineage."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1574.009",
   "technique_ja": "引用符なしパスによるパス横取り",
   "technique_en": "Path Interception by Unquoted Path",
   "analytic_id": "AN0176",
   "detection_strategy_id": "DET0064",
   "analytic_name": "Analytic 0176",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon)",
   "tuning": "MonitoredServices | SuspiciousBinaryList | TimeWindow | BaselineServiceConfig",
   "detection_logic_en": "Unquoted service or shortcut paths that contain spaces and allow path interception by higher-level executables. Defender observes registry service configurations with unquoted paths, file creation of executables in parent directories of unquoted paths, and subsequent process execution from unexpected locations."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1574.010",
   "technique_ja": "サービスのファイル権限の弱点",
   "technique_en": "Services File Permissions Weakness",
   "analytic_id": "AN1211",
   "detection_strategy_id": "DET0436",
   "analytic_name": "Analytic 1211",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon) | Service Creation (WinEventLog:System) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon) | サービス作成 (WinEventLog:System) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "MonitoredServices | HashBaseline | TimeWindow | PrivilegedAccounts",
   "detection_logic_en": "Modification or replacement of service executables due to weak file or directory permissions. Defender observes file writes to service binary paths, unexpected modifications of executables associated with registered services, and subsequent service execution of attacker-supplied binaries under elevated permissions."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1574.011",
   "technique_ja": "サービスのレジストリ権限の弱点",
   "technique_en": "Services Registry Permissions Weakness",
   "analytic_id": "AN1195",
   "detection_strategy_id": "DET0427",
   "analytic_name": "Analytic 1195",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Service Modification (WinEventLog:System) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | サービス変更 (WinEventLog:System) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "MonitoredServiceKeys | BaselineServiceConfig | TimeWindow | PrivilegedAccounts",
   "detection_logic_en": "Unauthorized modification of service-related registry keys such as ImagePath, FailureCommand, ServiceDll, or Performance/Parameters keys. Defender correlates registry modifications, anomalous service metadata changes, and subsequent service process executions that deviate from baseline configurations."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1574.012",
   "technique_ja": "COR_PROFILER",
   "technique_en": "COR_PROFILER",
   "analytic_id": "AN1319",
   "detection_strategy_id": "DET0479",
   "analytic_name": "Analytic 1319",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "AllowedProfilers | ProcessScope | TimeWindow | ProfilerDllPaths",
   "detection_logic_en": "Modification of COR_PROFILER-related environment variables or Registry keys (COR_ENABLE_PROFILING, COR_PROFILER, COR_PROFILER_PATH), combined with anomalous .NET process creation or unmanaged DLL loads. Defender observes registry modifications, suspicious process creation with altered environment variables, and profiler DLLs loaded unexpectedly into .NET CLR processes."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1574.013",
   "technique_ja": "KernelCallbackTable",
   "technique_en": "KernelCallbackTable",
   "analytic_id": "AN1593",
   "detection_strategy_id": "DET0577",
   "analytic_name": "Analytic 1593",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Kernel-Process)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Kernel-Process)",
   "tuning": "MonitoredProcesses | CallbackFunctions | TimeWindow | AccessMaskThresholds",
   "detection_logic_en": "Unexpected modification of the KernelCallbackTable in a process’s PEB followed by invocation of modified callback functions (e.g., fnCOPYDATA) through Windows messages. Defender observes suspicious API call chains such as NtQueryInformationProcess → WriteProcessMemory → abnormal GUI callback execution, often correlating to anomalous process behavior such as network activity or code injection."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1574.014",
   "technique_ja": "AppDomainManager",
   "technique_en": "AppDomainManager",
   "analytic_id": "AN1433",
   "detection_strategy_id": "DET0517",
   "analytic_name": "Analytic 1433",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "TargetProcesses | AssemblyWhitelist | ConfigFilePaths | TimeWindow",
   "detection_logic_en": "Detection focuses on unauthorized manipulation of .NET AppDomainManager behavior. Defenders may observe suspicious creation of new AppDomains within trusted processes, anomalous loading of assemblies via non-standard configuration files, or registry/environment variable changes redirecting AppDomainManager to malicious assemblies. Correlated events include config file tampering, new process creation of .NET host processes (e.g., w3wp.exe, powershell.exe) with modified runtime parameters, and module loads of unusual or unsigned .NET DLLs."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1612",
   "technique_ja": "ホスト上でのイメージビルド",
   "technique_en": "Build Image on Host",
   "analytic_id": "AN1261",
   "detection_strategy_id": "DET0459",
   "analytic_name": "Analytic 1261",
   "platforms": "Containers",
   "log_sources": "Image Creation (docker:daemon) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "イメージ作成 (docker:daemon) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "RegistryAllowList | NewImageThreshold | TimeWindow",
   "detection_logic_en": "Detection of container image build activity directly on the host using Docker or Kubernetes APIs. Defenders may observe Docker build requests, anomalous Dockerfile instructions (such as downloading code from unknown IPs), or creation of new images followed by immediate deployment. This behavior chain typically consists of an unexpected image creation event correlated with outbound network communication to non-standard or untrusted destinations."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1620",
   "technique_ja": "リフレクティブコードロード",
   "technique_en": "Reflective Code Loading",
   "analytic_id": "AN0838",
   "detection_strategy_id": "DET0300",
   "analytic_name": "Analytic 0838",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-DotNETRuntime) | Script Execution (etw:Microsoft-Antimalware-Scan-Interface) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-DotNETRuntime) | スクリプト実行 (etw:Microsoft-Antimalware-Scan-Interface) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "ParentProcessWhitelist | MemoryRegionPermissions",
   "detection_logic_en": "Detect anomalous chains of memory allocation and execution inside the same process (e.g., VirtualAlloc → memcpy → VirtualProtect → CreateThread). Unlike process injection, reflective code loading does not perform cross-process memory writes — the suspicious activity occurs entirely within the process’s own PID context."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1620",
   "technique_ja": "リフレクティブコードロード",
   "technique_en": "Reflective Code Loading",
   "analytic_id": "AN0839",
   "detection_strategy_id": "DET0300",
   "analytic_name": "Analytic 0839",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | OS API Execution (auditd:MMAP)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | OS API実行 (auditd:MMAP)",
   "tuning": "ProcessNameScope | RWXMemoryThreshold",
   "detection_logic_en": "Monitor for in-process mmap + mprotect + execve/execveat activity where memory permissions are changed from writable to executable inside the same process without a corresponding ELF on disk."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1620",
   "technique_ja": "リフレクティブコードロード",
   "technique_en": "Reflective Code Loading",
   "analytic_id": "AN0840",
   "detection_strategy_id": "DET0300",
   "analytic_name": "Analytic 0840",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Module Load (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | モジュール読み込み (macos:unifiedlog)",
   "tuning": "ApplicationScope | ExecutionTimeWindow",
   "detection_logic_en": "Suspicious calls to dlopen(), dlsym(), or mmap with RWX flags in processes that do not typically perform dynamic module loading. Monitor anonymous memory regions executed by user processes."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1622",
   "technique_ja": "デバッガ回避",
   "technique_en": "Debugger Evasion",
   "analytic_id": "AN1045",
   "detection_strategy_id": "DET0371",
   "analytic_name": "Analytic 1045",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Kernel-Process)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Kernel-Process)",
   "tuning": "ApiCallFrequencyThreshold | ProcessAllowList",
   "detection_logic_en": "Monitor for suspicious use of Windows API calls such as IsDebuggerPresent() and NtQueryInformationProcess(), or processes manually checking the BeingDebugged flag in the Process Environment Block (PEB). Detect sequences of OutputDebugStringW() calls in short intervals that may indicate debugger flooding attempts."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1622",
   "technique_ja": "デバッガ回避",
   "technique_en": "Debugger Evasion",
   "analytic_id": "AN1046",
   "detection_strategy_id": "DET0371",
   "analytic_name": "Analytic 1046",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL)",
   "tuning": "MonitoredPaths | SyscallThreshold",
   "detection_logic_en": "Monitor access to /proc/self/status where TracerPID field is queried, as this is a common technique for debugger detection. Detect processes that attempt to trigger exceptions intentionally and monitor whether exception handling indicates presence of a debugger."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1622",
   "technique_ja": "デバッガ回避",
   "technique_en": "Debugger Evasion",
   "analytic_id": "AN1047",
   "detection_strategy_id": "DET0371",
   "analytic_name": "Analytic 1047",
   "platforms": "macOS",
   "log_sources": "OS API Execution (macos:unifiedlog)",
   "log_sources_ja": "OS API実行 (macos:unifiedlog)",
   "tuning": "PtraceInvocationThreshold | DevToolExclusionList",
   "detection_logic_en": "Detect suspicious calls to sysctl or ptrace API used to determine if a process is being debugged. Monitor for processes that flood OutputDebugString equivalents or generate abnormal exceptions to evade analysis."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1678",
   "technique_ja": "実行遅延",
   "technique_en": "Delay Execution",
   "analytic_id": "AN1048",
   "detection_strategy_id": "DET0372",
   "analytic_name": "Analytic 1048",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | ParentProcessName | SleepFunctionPattern",
   "detection_logic_en": "Correlated use of sleep/delay mechanisms (e.g., kernel32!Sleep, NTDLL APIs) in short-lived processes, combined with parent processes invoking suspicious scripts (e.g., wscript, powershell) with minimal user interaction."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1678",
   "technique_ja": "実行遅延",
   "technique_en": "Delay Execution",
   "analytic_id": "AN1049",
   "detection_strategy_id": "DET0372",
   "analytic_name": "Analytic 1049",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Script Execution (auditd:PROCTITLE)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | スクリプト実行 (auditd:PROCTITLE)",
   "tuning": "CommandLineRegex | TimeBetweenSyscalls | UserContext",
   "detection_logic_en": "Shell scripts or binaries invoking repeated 'sleep', 'ping', or low-level syscalls (e.g., nanosleep) in short-lived execution chains with no user or system interaction. Frequently seen in malicious cron jobs or payload stagers."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1678",
   "technique_ja": "実行遅延",
   "technique_en": "Delay Execution",
   "analytic_id": "AN1050",
   "detection_strategy_id": "DET0372",
   "analytic_name": "Analytic 1050",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Module Load (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | モジュール読み込み (macos:unifiedlog)",
   "tuning": "ScriptPattern | UserContext | DelayDurationThreshold",
   "detection_logic_en": "Execution of AppleScript, bash, or launchd jobs that invoke delay functions (e.g., sleep, delay in AppleScript) with limited parent interaction and staged follow-on commands."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1679",
   "technique_ja": "選択的除外",
   "technique_en": "Selective Exclusion",
   "analytic_id": "AN2030",
   "detection_strategy_id": "DET0897",
   "analytic_name": "Analytic 2030",
   "platforms": "Windows",
   "log_sources": "Command Execution (WinEventLog:PowerShell) | Process Creation (WinEventLog:Security) | File Modification (WinEventLog:Security)",
   "log_sources_ja": "コマンド実行 (WinEventLog:PowerShell) | プロセス生成 (WinEventLog:Security) | ファイル変更 (WinEventLog:Security)",
   "tuning": "TimeWindow | DiscoveryActivityThreshold | ExclusionTargetList | AuthorizedExclusionModifiers",
   "detection_logic_en": "A process with no prior history or outside of known whitelisted tools initiates file or registry modifications to configure exclusion rules for antivirus, backup, or file-handling systems. Or a file system enumeration for specific file names andcritical extensions like .dll, .exe, .sys, or specific directories such as 'Program Files' or security tool paths or system component discovery for the exclusion of the files or components."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1684",
   "technique_ja": "ソーシャルエンジニアリング",
   "technique_en": "Social Engineering",
   "analytic_id": "AN2037",
   "detection_strategy_id": "DET0899",
   "analytic_name": "Analytic 2037",
   "platforms": "Linux",
   "log_sources": "Network Connection Creation (NSM:Connections) | Command Execution (auditd:EXECVE) | File Modification (auditd:PATH)",
   "log_sources_ja": "ネットワーク接続確立 (NSM:Connections) | コマンド実行 (auditd:EXECVE) | ファイル変更 (auditd:PATH)",
   "tuning": "RemoteScriptExecutionPatterns | TicketToExecutionWindow",
   "detection_logic_en": "Detects users executing commands copied from chats, tickets, or emails, including curl|bash patterns, shell script launches from temp directories, credential changes, or SSH key additions shortly after communication events."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1684",
   "technique_ja": "ソーシャルエンジニアリング",
   "technique_en": "Social Engineering",
   "analytic_id": "AN2035",
   "detection_strategy_id": "DET0899",
   "analytic_name": "Analytic 2035",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Logon Session Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ログオンセッション作成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "EmailToExecutionWindow | OfficeChildProcessAllowlist | NewLogonWindow",
   "detection_logic_en": "Detects user execution of newly received content or instructions shortly after external communication, including script launches, Office child process spawning, browser-to-script execution chains, or credential prompts followed by new logon sessions."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1684",
   "technique_ja": "ソーシャルエンジニアリング",
   "technique_en": "Social Engineering",
   "analytic_id": "AN2034",
   "detection_strategy_id": "DET0899",
   "analytic_name": "Analytic 2034",
   "platforms": "SaaS",
   "log_sources": "User Account Authentication (saas:okta) | Application Log Content (saas:slack) | Application Log Content (saas:zoom)",
   "log_sources_ja": "ユーザーアカウント認証 (saas:okta) | アプリケーションログ内容 (saas:slack) | アプリケーションログ内容 (saas:zoom)",
   "tuning": "RequesterNoveltyDays | GeoVelocityThreshold | AfterHoursDefinition",
   "detection_logic_en": "Detects consent grants, password resets, role changes, external sharing, or token creation shortly after user interaction with messages, invites, or help desk workflows. Emphasis is placed on unusual requester relationships, new device context, or off-hours approvals."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1684",
   "technique_ja": "ソーシャルエンジニアリング",
   "technique_en": "Social Engineering",
   "analytic_id": "AN2033",
   "detection_strategy_id": "DET0899",
   "analytic_name": "Analytic 2033",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified) | Application Log Content (m365:exchange) | Application Log Content (m365:teams)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | アプリケーションログ内容 (m365:exchange) | アプリケーションログ内容 (m365:teams)",
   "tuning": "ActionAfterMessageWindow | TrustedDomainAllowlist | ApprovalAmountThreshold",
   "detection_logic_en": "Detects suspicious inbound communications or collaboration requests followed by rapid sensitive user actions such as file sharing changes, macro enablement, OAuth consent, credential submission, or financial workflow approvals that deviate from historical relationships or normal approval patterns.\n      "
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1684",
   "technique_ja": "ソーシャルエンジニアリング",
   "technique_en": "Social Engineering",
   "analytic_id": "AN2036",
   "detection_strategy_id": "DET0899",
   "analytic_name": "Analytic 2036",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Network Connection Creation (NSM:Connections) | File Access (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ネットワーク接続確立 (NSM:Connections) | ファイルアクセス (macos:unifiedlog)",
   "tuning": "DownloadToExecutionWindow | InstallerParentAllowlist",
   "detection_logic_en": "Detects user-authorized execution of downloaded content or scripts after communication prompts, including browser downloads followed by osascript, shell, or installer execution and subsequent network activity."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1684.001",
   "technique_ja": "なりすまし",
   "technique_en": "Impersonation",
   "analytic_id": "AN0792",
   "detection_strategy_id": "DET0286",
   "analytic_name": "Analytic 0792",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Application Log Content (m365:unified)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | アプリケーションログ内容 (m365:unified)",
   "tuning": "KeywordList | GeoLocationBaseline",
   "detection_logic_en": "Monitor for anomalous email activity originating from Windows-hosted applications (e.g., Outlook) where the sending account name or display name does not match the underlying SMTP address. Detect abnormal volume of outbound messages containing sensitive keywords (e.g., 'payment', 'wire transfer') or anomalous login locations for accounts associated with email sending activity."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1684.001",
   "technique_ja": "なりすまし",
   "technique_en": "Impersonation",
   "analytic_id": "AN0793",
   "detection_strategy_id": "DET0286",
   "analytic_name": "Analytic 0793",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | Application Log Content (Application:Mail)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | アプリケーションログ内容 (Application:Mail)",
   "tuning": "KnownRelayHosts",
   "detection_logic_en": "Monitor mail server logs (Postfix, Sendmail, Exim) for anomalous From headers mismatching authenticated SMTP identities. Detect abnormal relay attempts, spoofed envelope-from values, or large-scale outbound campaigns targeting internal users."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1684.001",
   "technique_ja": "なりすまし",
   "technique_en": "Impersonation",
   "analytic_id": "AN0794",
   "detection_strategy_id": "DET0286",
   "analytic_name": "Analytic 0794",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog)",
   "tuning": "TrustedMailClients",
   "detection_logic_en": "Monitor Mail.app activity or unified logs for anomalous SMTP usage, including mismatches between display name and authenticated AppleID or Exchange credentials. Detect use of third-party mail utilities that attempt to send on behalf of corporate identities."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1684.001",
   "technique_ja": "なりすまし",
   "technique_en": "Impersonation",
   "analytic_id": "AN0795",
   "detection_strategy_id": "DET0286",
   "analytic_name": "Analytic 0795",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (gcp:workspaceaudit)",
   "log_sources_ja": "アプリケーションログ内容 (gcp:workspaceaudit)",
   "tuning": "DelegationBaseline",
   "detection_logic_en": "Monitor SaaS mail platforms (Google Workspace, M365, Okta-integrated apps) for SendAs/SendOnBehalfOf operations where the delegated permissions are unusual or newly granted. Detect impersonation attempts where adversaries configure rules to auto-forward or auto-reply with impersonated content."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1684.001",
   "technique_ja": "なりすまし",
   "technique_en": "Impersonation",
   "analytic_id": "AN0796",
   "detection_strategy_id": "DET0286",
   "analytic_name": "Analytic 0796",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified)",
   "tuning": "MacroExecutionThreshold",
   "detection_logic_en": "Monitor Office Suite applications (Outlook, Word mail merge, Excel macros) for abnormal automated message sending, especially when macros or scripts trigger email delivery. Detect patterns of impersonation language (urgent, payment, executive request) combined with anomalous execution of Office macros."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1684.002",
   "technique_ja": "メールスプーフィング",
   "technique_en": "Email Spoofing",
   "analytic_id": "AN1202",
   "detection_strategy_id": "DET0431",
   "analytic_name": "Analytic 1202",
   "platforms": "Windows",
   "log_sources": "Application Log Content (m365:messagetrace)",
   "log_sources_ja": "アプリケーションログ内容 (m365:messagetrace)",
   "tuning": "SpoofScoreThreshold | MonitoredDomains",
   "detection_logic_en": "Monitor email message traces and headers for failed SPF, DKIM, or DMARC checks indicating spoofed sender identities. Correlate abnormal sender domains or mismatched return-paths with elevated spoofing likelihood."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1684.002",
   "technique_ja": "メールスプーフィング",
   "technique_en": "Email Spoofing",
   "analytic_id": "AN1203",
   "detection_strategy_id": "DET0431",
   "analytic_name": "Analytic 1203",
   "platforms": "Linux",
   "log_sources": "Application Log Content (linux:syslog)",
   "log_sources_ja": "アプリケーションログ内容 (linux:syslog)",
   "tuning": "SenderDomainWhitelist | TimeWindow",
   "detection_logic_en": "Detects spoofed emails by analyzing mail server logs (e.g., Postfix, Sendmail) for mismatched header fields, failed SPF/DKIM checks, and anomalies in SMTP proxy logs. Defender observes discrepancies between sending domain, return-path domain, and message metadata."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1684.002",
   "technique_ja": "メールスプーフィング",
   "technique_en": "Email Spoofing",
   "analytic_id": "AN1204",
   "detection_strategy_id": "DET0431",
   "analytic_name": "Analytic 1204",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog)",
   "tuning": "RecipientSensitivity | HeaderMismatchTolerance",
   "detection_logic_en": "Detects suspicious inbound mail traffic where SPF/DKIM/DMARC authentication fails or where sender and return-path domains mismatch, observable in Apple Mail unified logs or MDM-controlled logging pipelines."
  },
  {
   "tactic_id": "TA0005",
   "tactic_ja": "ステルス",
   "technique_id": "T1684.002",
   "technique_ja": "メールスプーフィング",
   "technique_en": "Email Spoofing",
   "analytic_id": "AN1205",
   "detection_strategy_id": "DET0431",
   "analytic_name": "Analytic 1205",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (saas:email)",
   "log_sources_ja": "アプリケーションログ内容 (saas:email)",
   "tuning": "MessageVolumeThreshold | TargetedUserGroups",
   "detection_logic_en": "Correlates Office 365 or Google Workspace audit logs for spoofed sender addresses, failed email authentication, and anomalies in message delivery metadata. Defender observes failed SPF/DKIM checks and domain mismatches tied to suspicious campaigns."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1112",
   "technique_ja": "レジストリの変更",
   "technique_en": "Modify Registry",
   "analytic_id": "AN0781",
   "detection_strategy_id": "DET0280",
   "analytic_name": "Analytic 0781",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "RegistryKeyPathPatterns | ParentProcessAllowList | TimeWindow | SignatureCheck",
   "detection_logic_en": "Behavior chain involving abnormal registry modifications via CLI, PowerShell, WMI, or direct API calls, especially targeting persistence, privilege escalation, or defense evasion keys, potentially followed by service restart or process execution. Such as editing Notify/Userinit/Startup keys, or disabling SafeDllSearchMode."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1207",
   "technique_ja": "不正なドメインコントローラ",
   "technique_en": "Rogue Domain Controller",
   "analytic_id": "AN0770",
   "detection_strategy_id": "DET0276",
   "analytic_name": "Analytic 0770",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Creation (WinEventLog:Security) | Active Directory Credential Request (WinEventLog:Security) | Active Directory Object Access (WinEventLog:Security) | Active Directory Object Modification (m365:dirsync) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "Active Directoryオブジェクト作成 (WinEventLog:Security) | Active Directory資格情報要求 (WinEventLog:Security) | Active Directoryオブジェクトアクセス (WinEventLog:Security) | Active Directoryオブジェクト変更 (m365:dirsync) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TimeWindow | AllowedReplicationPartners | SuspiciousSPNs | NonDCObjectCreationAlert",
   "detection_logic_en": "Detection of rogue Domain Controller registration and Active Directory replication abuse by correlating: (1) creation/modification of nTDSDSA and server objects in the Configuration partition, (2) unexpected usage of Directory Replication Service SPNs (GC/ or E3514235-4B06-11D1-AB04-00C04FC2DCD2), (3) replication RPC calls (DrsAddEntry, DrsReplicaAdd, GetNCChanges) originating from non-DC hosts, and (4) Kerberos authentication by non-DC machines using DRS-related SPNs. These events in combination, especially from hosts outside the Domain Controllers OU, may indicate DCShadow or rogue DC activity."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1222",
   "technique_ja": "ファイル/ディレクトリ権限の変更",
   "technique_en": "File and Directory Permissions Modification",
   "analytic_id": "AN0834",
   "detection_strategy_id": "DET0299",
   "analytic_name": "Analytic 0834",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Metadata (WinEventLog:Security) | Active Directory Object Modification (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイルメタデータ (WinEventLog:Security) | Active Directoryオブジェクト変更 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "TimeWindow | SensitivePathList | TrustedUserContext | BusinessHoursThreshold",
   "detection_logic_en": "Sequential behavioral chain of privilege escalation through permission modification: (1) Process creation of permission-modifying utilities (icacls, takeown, attrib, cacls), (2) Correlation with unusual user context or timing, (3) DACL modification events targeting sensitive files/directories, (4) Subsequent file access or modification attempts indicating successful privilege bypass"
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1222",
   "technique_ja": "ファイル/ディレクトリ権限の変更",
   "technique_en": "File and Directory Permissions Modification",
   "analytic_id": "AN0835",
   "detection_strategy_id": "DET0299",
   "analytic_name": "Analytic 0835",
   "platforms": "Linux",
   "log_sources": "File Metadata (auditd:SYSCALL) | Command Execution (auditd:PROCTITLE)",
   "log_sources_ja": "ファイルメタデータ (auditd:SYSCALL) | コマンド実行 (auditd:PROCTITLE)",
   "tuning": "SuspiciousPermissionValues | CriticalPathPatterns | AuthorizedAdminUsers | AnomalyThreshold",
   "detection_logic_en": "Behavioral sequence of unauthorized privilege escalation via permission modification: (1) chmod/chown/setfacl process execution with suspicious parameters, (2) Targeting of critical system files or unusual permission values, (3) Correlation with non-privileged user context or unusual timing patterns, (4) Follow-on file access indicating successful permission bypass"
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1222",
   "technique_ja": "ファイル/ディレクトリ権限の変更",
   "technique_en": "File and Directory Permissions Modification",
   "analytic_id": "AN0836",
   "detection_strategy_id": "DET0299",
   "analytic_name": "Analytic 0836",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Metadata (fs:fsevents)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイルメタデータ (fs:fsevents)",
   "tuning": "SIPProtectedPaths | SuspiciousFlagCombinations | XattrMonitoringScope | UnifiedLogRetention",
   "detection_logic_en": "macOS-specific permission modification behavioral chain: (1) chmod/chown/chflags process execution, (2) System Integrity Protection (SIP) bypass attempts, (3) Extended attribute (xattr) modifications, (4) Unified log correlation with file system events, (5) Subsequent access to previously restricted resources"
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1222",
   "technique_ja": "ファイル/ディレクトリ権限の変更",
   "technique_en": "File and Directory Permissions Modification",
   "analytic_id": "AN0837",
   "detection_strategy_id": "DET0299",
   "analytic_name": "Analytic 0837",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:shell) | File Metadata (esxi:hostd) | Active Directory Object Modification (esxi:vpxd)",
   "log_sources_ja": "コマンド実行 (esxi:shell) | ファイルメタデータ (esxi:hostd) | Active Directoryオブジェクト変更 (esxi:vpxd)",
   "tuning": "AuthorizedSSHUsers | CriticalVMFSPaths | ShellAccessTimeWindow | vCenterIntegrationScope",
   "detection_logic_en": "ESXi hypervisor permission modification behavioral chain: (1) SSH access to ESXi host, (2) chmod/chown execution on VMFS datastore files or system configuration, (3) Modification of VM configuration files (.vmx) or virtual disk permissions, (4) Hostd service log correlation, (5) vCenter permission change events if centrally managed"
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1222.001",
   "technique_ja": "Windows権限",
   "technique_en": "Windows Permissions",
   "analytic_id": "AN1177",
   "detection_strategy_id": "DET0418",
   "analytic_name": "Analytic 1177",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Active Directory Object Modification (WinEventLog:Security) | File Metadata (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | WMI Creation (WinEventLog:WMI)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | Active Directoryオブジェクト変更 (WinEventLog:Security) | ファイルメタデータ (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | WMI作成 (WinEventLog:WMI)",
   "tuning": "TemporalCorrelationWindow | SensitivePathWhitelist | AuthorizedAdministratorAccounts | SuspiciousCommandLinePatterns | BusinessHoursThreshold | PowerShellScriptBlockSizeThreshold | FileAccessFrequencyBaseline | WMIMethodInvocationWhitelist",
   "detection_logic_en": "Multi-stage Windows DACL manipulation behavioral chain: (1) Process creation of permission-modifying utilities (icacls.exe, takeown.exe, attrib.exe, cacls.exe) or PowerShell ACL cmdlets, (2) Command-line analysis revealing privilege escalation intent through suspicious parameters (/grant, /takeown, /T, Set-Acl), (3) DACL modification events (4670) correlating with process execution, (4) Subsequent file access attempts (4663) indicating successful permission bypass, (5) Potential follow-on persistence or lateral movement activities"
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1222.002",
   "technique_ja": "LinuxとMacの権限",
   "technique_en": "Linux and Mac Permissions",
   "analytic_id": "AN0998",
   "detection_strategy_id": "DET0351",
   "analytic_name": "Analytic 0998",
   "platforms": "Linux",
   "log_sources": "File Metadata (auditd:SYSCALL) | Command Execution (auditd:PROCTITLE) | Process Creation (linux:osquery)",
   "log_sources_ja": "ファイルメタデータ (auditd:SYSCALL) | コマンド実行 (auditd:PROCTITLE) | プロセス生成 (linux:osquery)",
   "tuning": "SuspiciousPermissionValues | CriticalSystemPaths | AuthorizedSystemAdministrators | TemporalCorrelationWindow | RecursiveOperationThreshold | ACLComplexityBaseline | FileAccessFrequencyBaseline",
   "detection_logic_en": "Linux permission escalation behavioral chain: (1) Process creation of permission modification utilities (chmod, chown, chgrp, setfacl) with suspicious parameters indicating privilege escalation intent, (2) System call analysis revealing direct file metadata manipulation (chmod, fchmod, chown, fchown syscalls), (3) Extended attribute and ACL modifications targeting critical system paths, (4) Temporal correlation with subsequent file access or process execution from modified locations, (5) Anomalous permission patterns deviating from system baselines"
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1222.002",
   "technique_ja": "LinuxとMacの権限",
   "technique_en": "Linux and Mac Permissions",
   "analytic_id": "AN0999",
   "detection_strategy_id": "DET0351",
   "analytic_name": "Analytic 0999",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (fs:fsevents) | File Metadata (OpenBSM:AuditTrail)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (fs:fsevents) | ファイルメタデータ (OpenBSM:AuditTrail)",
   "tuning": "SIPProtectedPaths | SuspiciousFileFlags | CriticalExtendedAttributes | GatekeeperBypassIndicators | ApplicationBundleMonitoring | UnifiedLogRetentionPeriod | FSEventsFilteringThreshold",
   "detection_logic_en": "macOS permission and attribute manipulation behavioral chain: (1) Process execution of permission utilities (chmod, chown, chgrp) or macOS-specific tools (chflags) with suspicious parameters, (2) System Integrity Protection (SIP) bypass attempts through permission modifications, (3) File flags manipulation (uchg, schg, hidden) for evasion or persistence, (4) Extended attribute (xattr) modifications affecting security metadata, (5) Unified log correlation with file system events and subsequent access patterns, (6) Gatekeeper and code signing bypass through permission/attribute manipulation"
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1484",
   "technique_ja": "ドメイン/テナントポリシーの変更",
   "technique_en": "Domain or Tenant Policy Modification",
   "analytic_id": "AN0755",
   "detection_strategy_id": "DET0270",
   "analytic_name": "Analytic 0755",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Modification (WinEventLog:Security) | File Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (WinEventLog:Security) | ファイル変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "ObjectDN | AttributeModified | TimeWindow | UserContext",
   "detection_logic_en": "Adversary modifies Group Policy Objects (GPOs), domain trust, or directory service objects via GUI, CLI, or programmatic APIs. Behavior includes creation/modification of GPOs, delegation permissions, trust objects, or rogue domain controller registration."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1484",
   "technique_ja": "ドメイン/テナントポリシーの変更",
   "technique_en": "Domain or Tenant Policy Modification",
   "analytic_id": "AN0756",
   "detection_strategy_id": "DET0270",
   "analytic_name": "Analytic 0756",
   "platforms": "Identity Provider",
   "log_sources": "Application Log Content (m365:unified) | User Account Authentication (azure:signinlogs)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | ユーザーアカウント認証 (azure:signinlogs)",
   "tuning": "OperationName | InitiatedBy | UserAgent | TimeWindow",
   "detection_logic_en": "Adversary modifies tenant policy through changes to federation configuration, trust settings, or identity provider additions in Microsoft 365/AzureAD via Portal, PowerShell, or Graph API. Includes setting authentication to federated or updating federated domains."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1484.001",
   "technique_ja": "グループポリシーの変更",
   "technique_en": "Group Policy Modification",
   "analytic_id": "AN0854",
   "detection_strategy_id": "DET0305",
   "analytic_name": "Analytic 0854",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Modification (WinEventLog:Security) | File Modification (WinEventLog:Security) | User Account Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (WinEventLog:Security) | ファイル変更 (WinEventLog:Security) | ユーザーアカウント変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "ObjectDN | TargetFilename | TimeWindow | UserContext | CommandLine",
   "detection_logic_en": "Adversary modifies GPO containers or files under SYSVOL using LDAP, ADSI, PowerShell (e.g., New-GPOImmediateTask) or GUI tools. This includes directory object changes (e.g., gPCFileSysPath), delegation assignments (SeEnableDelegationPrivilege), and SYSVOL file writes (ScheduledTasks.xml, GptTmpl.inf)."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1484.002",
   "technique_ja": "信頼関係の変更",
   "technique_en": "Trust Modification",
   "analytic_id": "AN1259",
   "detection_strategy_id": "DET0458",
   "analytic_name": "Analytic 1259",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Modification (WinEventLog:Security) | User Account Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (WinEventLog:Security) | ユーザーアカウント変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "ObjectType | AttributeModified | TimeWindow | UserContext",
   "detection_logic_en": "Adversary modifies Active Directory domain trust settings via `netdom`, `nltest`, or PowerShell to add new domain trust or alter federation. Modifications occur in AD object attributes like trustDirection, trustType, trustAttributes, often paired with SeEnableDelegationPrivilege or certificate injection."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1484.002",
   "technique_ja": "信頼関係の変更",
   "technique_en": "Trust Modification",
   "analytic_id": "AN1260",
   "detection_strategy_id": "DET0458",
   "analytic_name": "Analytic 1260",
   "platforms": "Identity Provider",
   "log_sources": "Application Log Content (m365:unified) | Command Execution (azure:signinlogs)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | コマンド実行 (azure:signinlogs)",
   "tuning": "OperationName | InitiatedBy | UserAgent | TimeWindow",
   "detection_logic_en": "Adversary adds federated identity provider (IdP) or modifies tenant domain authentication from Managed to Federated. Detected via API, PowerShell, or Admin Portal through federation events like `Set domain authentication`, `Add federated identity provider`, or `Update-MsolFederatedDomain`."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1553",
   "technique_ja": "信頼制御の破壊",
   "technique_en": "Subvert Trust Controls",
   "analytic_id": "AN1246",
   "detection_strategy_id": "DET0452",
   "analytic_name": "Analytic 1246",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TrustedPublisherList | FilePathAllowList | TimeWindow",
   "detection_logic_en": "Detection correlates abnormal installation or modification of root or code-signing certificates, creation/modification of suspicious registry keys for trust providers, and unusual module loads from non-standard locations. Identifies unsigned or improperly signed executables bypassing trust prompts, combined with persistence artifacts."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1553",
   "technique_ja": "信頼制御の破壊",
   "technique_en": "Subvert Trust Controls",
   "analytic_id": "AN1247",
   "detection_strategy_id": "DET0452",
   "analytic_name": "Analytic 1247",
   "platforms": "Linux",
   "log_sources": "File Metadata (auditd:SYSCALL) | Command Execution (auditd:EXECVE)",
   "log_sources_ja": "ファイルメタデータ (auditd:SYSCALL) | コマンド実行 (auditd:EXECVE)",
   "tuning": "CertificatePathList | RegexPatterns",
   "detection_logic_en": "Detection monitors extended attribute manipulation (xattr) to strip quarantine or trust metadata, anomalous installation of root certificates in /etc/ssl or /usr/local/share/ca-certificates, and unauthorized modification of system trust stores. Correlates with unexpected process execution involving package managers or custom certificate utilities."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1553",
   "technique_ja": "信頼制御の破壊",
   "technique_en": "Subvert Trust Controls",
   "analytic_id": "AN1248",
   "detection_strategy_id": "DET0452",
   "analytic_name": "Analytic 1248",
   "platforms": "macOS",
   "log_sources": "File Metadata (macos:unifiedlog) | Command Execution (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "ファイルメタデータ (macos:unifiedlog) | コマンド実行 (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "QuarantineBypassAllowList | CertificateAuthorityList",
   "detection_logic_en": "Detection monitors modification of code signing attributes, Gatekeeper/quarantine flags, and insertion of new trust certificates via security add-trusted-cert. Identifies adversary use of xattr to strip quarantine flags from downloaded binaries. Correlates with abnormal module loads bypassing SIP protections."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1553.001",
   "technique_ja": "Gatekeeperバイパス",
   "technique_en": "Gatekeeper Bypass",
   "analytic_id": "AN0800",
   "detection_strategy_id": "DET0288",
   "analytic_name": "Analytic 0800",
   "platforms": "macOS",
   "log_sources": "File Metadata (macos:unifiedlog) | Process Creation (macos:unifiedlog) | File Modification (macos:osquery)",
   "log_sources_ja": "ファイルメタデータ (macos:unifiedlog) | プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:osquery)",
   "tuning": "QuarantineBypassAllowList | CertificateAuthorityList | TimeWindow",
   "detection_logic_en": "Correlates suspicious removal or modification of the com.apple.quarantine extended attribute, manipulation of LSFileQuarantineEnabled values in Info.plist, and unexpected process execution of unsigned or non-notarized binaries. Also monitors abnormal trust validation failures in unified logs and unusual activity in QuarantineEvents database entries."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1553.002",
   "technique_ja": "コード署名",
   "technique_en": "Code Signing",
   "analytic_id": "AN0643",
   "detection_strategy_id": "DET0230",
   "analytic_name": "Analytic 0643",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "AllowedCertificateAuthorities | TimeWindow | CertificateAgeThreshold",
   "detection_logic_en": "Detects execution of binaries signed with unusual or recently issued certificates, correlation of process execution with abnormal publisher metadata, and mismatched certificate chains. Monitors for revoked or unknown code signing certificates used in high-privilege contexts."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1553.002",
   "technique_ja": "コード署名",
   "technique_en": "Code Signing",
   "analytic_id": "AN0644",
   "detection_strategy_id": "DET0230",
   "analytic_name": "Analytic 0644",
   "platforms": "macOS",
   "log_sources": "File Metadata (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ファイルメタデータ (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "DeveloperIDAllowList | TimeWindow",
   "detection_logic_en": "Monitors Gatekeeper, spctl, and unified log entries for binaries executed with unexpected or untrusted signatures. Correlates file metadata changes with process launches where signature validation is skipped, altered, or fails but the process still executes."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1553.003",
   "technique_ja": "SIPと信頼プロバイダの乗っ取り",
   "technique_en": "SIP and Trust Provider Hijacking",
   "analytic_id": "AN1222",
   "detection_strategy_id": "DET0442",
   "analytic_name": "Analytic 1222",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Module Load (WinEventLog:Sysmon) | File Modification (WinEventLog:CodeIntegrity)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:CodeIntegrity)",
   "tuning": "RegistryPathBaselines | TimeWindow",
   "detection_logic_en": "Detection of anomalous registry modifications to Subject Interface Packages (SIPs) or trust provider DLL mappings, unexpected loading of non-Microsoft cryptographic modules, or attempts to redirect WinVerifyTrust validation logic. Defender view focuses on registry tampering, suspicious DLL loads into trusted processes, and abnormal trust validation failures correlated across event streams."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1553.004",
   "technique_ja": "ルート証明書のインストール",
   "technique_en": "Install Root Certificate",
   "analytic_id": "AN0153",
   "detection_strategy_id": "DET0056",
   "analytic_name": "Analytic 0153",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Windows Registry Key Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | Windowsレジストリキー作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TrustedRootHashList | MonitoredProcesses | TimeWindow",
   "detection_logic_en": "Detection of unauthorized modifications to Windows root certificate stores by monitoring registry keys, certificate installation processes, and creation of new certificate entries not in baseline trusted lists."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1553.004",
   "technique_ja": "ルート証明書のインストール",
   "technique_en": "Install Root Certificate",
   "analytic_id": "AN0154",
   "detection_strategy_id": "DET0056",
   "analytic_name": "Analytic 0154",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Command Execution (auditd:EXECVE)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | コマンド実行 (auditd:EXECVE)",
   "tuning": "CertificatePaths | AdminAccounts",
   "detection_logic_en": "Detection of unexpected additions or modifications to system-wide certificate stores or execution of commands adding certificates to trusted stores."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1553.004",
   "technique_ja": "ルート証明書のインストール",
   "technique_en": "Install Root Certificate",
   "analytic_id": "AN0155",
   "detection_strategy_id": "DET0056",
   "analytic_name": "Analytic 0155",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Modification (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル変更 (macos:osquery)",
   "tuning": "MonitoredCommands | KeychainBaseline",
   "detection_logic_en": "Detection of malicious certificate installation via monitoring execution of the `security add-trusted-cert` command and modifications to system keychains."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1553.005",
   "technique_ja": "Mark-of-the-Webバイパス",
   "technique_en": "Mark-of-the-Web Bypass",
   "analytic_id": "AN0712",
   "detection_strategy_id": "DET0257",
   "analytic_name": "Analytic 0712",
   "platforms": "Windows",
   "log_sources": "File Access (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイルアクセス (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon)",
   "tuning": "WatchedExtensions | TimeWindow | TrustedExtractionTools",
   "detection_logic_en": "Detects extraction or mounting of container/archive files (e.g., .iso, .vhd, .zip) that originated from the Internet but whose contained files lack Zone.Identifier MOTW tagging. Correlates file creation metadata with subsequent execution of unsigned or untrusted binaries launched outside SmartScreen or Protected View."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1553.006",
   "technique_ja": "コード署名ポリシーの変更",
   "technique_en": "Code Signing Policy Modification",
   "analytic_id": "AN1446",
   "detection_strategy_id": "DET0523",
   "analytic_name": "Analytic 1446",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Security)",
   "tuning": "MonitoredExecutables | RegistryPaths | TimeWindow",
   "detection_logic_en": "Monitors execution of administrative utilities (e.g., bcdedit.exe) or registry modifications that disable Driver Signature Enforcement (DSE) or enable Test Signing. Correlates command-line activity, registry changes, and subsequent process executions that bypass signing enforcement."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1553.006",
   "technique_ja": "コード署名ポリシーの変更",
   "technique_en": "Code Signing Policy Modification",
   "analytic_id": "AN1447",
   "detection_strategy_id": "DET0523",
   "analytic_name": "Analytic 1447",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Windows Registry Key Modification (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | Windowsレジストリキー変更 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "PolicyPaths | AllowedUsers | TimeWindow",
   "detection_logic_en": "Detects modification of System Integrity Protection (SIP) or code signing enforcement policies through csrutil or kernel variable tampering. Correlates execution of csrutil disable commands with subsequent policy state changes and anomalous unsigned process executions."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556",
   "technique_ja": "認証プロセスの変更",
   "technique_en": "Modify Authentication Process",
   "analytic_id": "AN0287",
   "detection_strategy_id": "DET0104",
   "analytic_name": "Analytic 0287",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Process Access (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "MonitoredRegistryKeys | TimeWindow",
   "detection_logic_en": "Detects modification of LSASS and authentication DLLs, suspicious registry changes to password filter packages, and abnormal process access to lsass.exe. Correlates registry modifications, DLL loads, and process handle access events."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556",
   "technique_ja": "認証プロセスの変更",
   "technique_en": "Modify Authentication Process",
   "analytic_id": "AN0288",
   "detection_strategy_id": "DET0104",
   "analytic_name": "Analytic 0288",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "WatchedPaths",
   "detection_logic_en": "Detects modification of PAM configuration files, unauthorized new PAM modules, and suspicious process execution accessing PAM-related binaries. Correlates file modification events in /etc/pam.d/ with process execution of unauthorized binaries."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556",
   "technique_ja": "認証プロセスの変更",
   "technique_en": "Modify Authentication Process",
   "analytic_id": "AN0289",
   "detection_strategy_id": "DET0104",
   "analytic_name": "Analytic 0289",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | Process Access (macos:osquery)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | プロセスアクセス (macos:osquery)",
   "tuning": "PluginPaths",
   "detection_logic_en": "Detects unauthorized additions or changes to /Library/Security/SecurityAgentPlugins and suspicious process activity attempting to hook authentication APIs. Correlates file modifications with abnormal plugin loads in authentication flows."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556",
   "technique_ja": "認証プロセスの変更",
   "technique_en": "Modify Authentication Process",
   "analytic_id": "AN0290",
   "detection_strategy_id": "DET0104",
   "analytic_name": "Analytic 0290",
   "platforms": "Identity Provider",
   "log_sources": "Cloud Service Modification (azure:policy) | User Account Modification (m365:unified)",
   "log_sources_ja": "クラウドサービス変更 (azure:policy) | ユーザーアカウント変更 (m365:unified)",
   "tuning": "PolicyBaseline",
   "detection_logic_en": "Detects suspicious configuration changes in IdP authentication flows such as enabling reversible password encryption, MFA bypass, or policy weakening. Correlates policy modification events with unusual administrative activity."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556",
   "technique_ja": "認証プロセスの変更",
   "technique_en": "Modify Authentication Process",
   "analytic_id": "AN0291",
   "detection_strategy_id": "DET0104",
   "analytic_name": "Analytic 0291",
   "platforms": "IaaS",
   "log_sources": "User Account Modification (AWS:CloudTrail) | Cloud Service Modification (AWS:CloudTrail)",
   "log_sources_ja": "ユーザーアカウント変更 (AWS:CloudTrail) | クラウドサービス変更 (AWS:CloudTrail)",
   "tuning": "ApprovedAccounts",
   "detection_logic_en": "Detects unauthorized changes to IAM authentication configurations such as disabling MFA, creating backdoor access keys, or altering trust policies. Correlates identity policy updates with unusual login behavior."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.001",
   "technique_ja": "ドメインコントローラ認証",
   "technique_en": "Domain Controller Authentication",
   "analytic_id": "AN0757",
   "detection_strategy_id": "DET0271",
   "analytic_name": "Analytic 0757",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Logon Session Creation (WinEventLog:Security) | File Modification (WinEventLog:System)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ログオンセッション作成 (WinEventLog:Security) | ファイル変更 (WinEventLog:System)",
   "tuning": "MonitoredDLLs | TimeWindow | UserContext",
   "detection_logic_en": "Detects anomalous process access to LSASS on domain controllers, suspicious module loads of authentication DLLs, and registry or file modifications indicative of Skeleton Key–style patching. Correlates LSASS access attempts with subsequent abnormal logon activity patterns."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.002",
   "technique_ja": "パスワードフィルタDLL",
   "technique_en": "Password Filter DLL",
   "analytic_id": "AN1303",
   "detection_strategy_id": "DET0472",
   "analytic_name": "Analytic 1303",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "RegistryPath | AllowedDLLs | TimeWindow | FilePathPatterns",
   "detection_logic_en": "Detects suspicious registration of new password filter DLLs into the authentication process. Correlates registry modifications to LSASS Notification Packages with subsequent DLL creation and loading events. Observes anomalous file placement of DLLs in system directories followed by LSASS loading the new filter during logon/password change activity."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.003",
   "technique_ja": "プラガブル認証モジュール（PAM）",
   "technique_en": "Pluggable Authentication Modules",
   "analytic_id": "AN1250",
   "detection_strategy_id": "DET0454",
   "analytic_name": "Analytic 1250",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Logon Session Creation (NSM:Connections)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | ログオンセッション作成 (NSM:Connections)",
   "tuning": "MonitoredPaths | TimeWindow | BaselineAccounts",
   "detection_logic_en": "Detects unauthorized modifications to PAM configuration files or shared object modules. Correlates file modification events under /etc/pam.d/ or /lib/security/ with unusual authentication activity such as multiple simultaneous logins, off-hours logins, or logons without corresponding physical/VPN access."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.003",
   "technique_ja": "プラガブル認証モジュール（PAM）",
   "technique_en": "Pluggable Authentication Modules",
   "analytic_id": "AN1251",
   "detection_strategy_id": "DET0454",
   "analytic_name": "Analytic 1251",
   "platforms": "macOS",
   "log_sources": "Logon Session Creation (macos:unifiedlog) | File Modification (macos:osquery)",
   "log_sources_ja": "ログオンセッション作成 (macos:unifiedlog) | ファイル変更 (macos:osquery)",
   "tuning": "WatchedPlugins | CorrelatedSources",
   "detection_logic_en": "Detects suspicious changes to macOS authorization and PAM plugin files. Correlates file modifications under /etc/pam.d/ or /Library/Security/SecurityAgentPlugins with unexpected authentication attempts or anomalous account usage."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.004",
   "technique_ja": "ネットワークデバイス認証",
   "technique_en": "Network Device Authentication",
   "analytic_id": "AN0758",
   "detection_strategy_id": "DET0272",
   "analytic_name": "Analytic 0758",
   "platforms": "Network Devices",
   "log_sources": "File Modification (networkconfig) | User Account Authentication (network:auth)",
   "log_sources_ja": "ファイル変更 (networkconfig) | ユーザーアカウント認証 (network:auth)",
   "tuning": "BaselineChecksums | AuthFailureThreshold | VerificationInterval",
   "detection_logic_en": "Detects unauthorized modification of network device authentication by correlating OS image file changes, checksum mismatches, or memory verification failures with anomalous authentication events. Focus is on behaviors where patched images introduce hardcoded passwords or bypass native authentication."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.005",
   "technique_ja": "可逆暗号化",
   "technique_en": "Reversible Encryption",
   "analytic_id": "AN1621",
   "detection_strategy_id": "DET0589",
   "analytic_name": "Analytic 1621",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "MonitoredOUs | TimeWindow | SuspiciousCmdletList",
   "detection_logic_en": "Detects enabling of reversible password encryption in Active Directory or Group Policy, suspicious PowerShell commands modifying AD user properties, and unusual account configuration changes correlated with policy modifications. Multi-event correlation links Group Policy edits, PowerShell command execution, and user account property changes to identify tampering with authentication encryption settings."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0543",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0543",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Modification (WinEventLog:Security) | Script Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (WinEventLog:Security) | スクリプト実行 (WinEventLog:PowerShell)",
   "tuning": "WatchedAttributes | TimeWindow",
   "detection_logic_en": "Detects registry and Group Policy modifications that disable or weaken MFA, suspicious PowerShell usage modifying MFA-related attributes, and anomalous login sessions succeeding without expected MFA challenge."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0544",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0544",
   "platforms": "Identity Provider",
   "log_sources": "Application Log Content (azure:signinlogs) | User Account Modification (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (azure:signinlogs) | ユーザーアカウント変更 (m365:unified)",
   "tuning": "PrivilegedRoles",
   "detection_logic_en": "Detects conditional access policy changes, exclusion of accounts from MFA enforcement, or registration of new MFA factors by non-admin or anomalous users."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0545",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0545",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Modification (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス変更 (AWS:CloudTrail)",
   "tuning": "MonitoredServices",
   "detection_logic_en": "Detects API calls to cloud secrets/MFA configurations where MFA enforcement policies are disabled or bypassed."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0546",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0546",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | User Account Authentication (NSM:Connections)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | ユーザーアカウント認証 (NSM:Connections)",
   "tuning": "MFAHooks",
   "detection_logic_en": "Detects PAM module modifications or removal of MFA hooks in /etc/pam.d/ configurations, correlated with successful authentications lacking MFA prompts."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0547",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0547",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | User Account Authentication (macos:unifiedlog)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | ユーザーアカウント認証 (macos:unifiedlog)",
   "tuning": "WatchedPluginPaths",
   "detection_logic_en": "Detects modifications to authorization plugins responsible for MFA enforcement and correlates with suspicious login sessions missing MFA prompts."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0548",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0548",
   "platforms": "SaaS",
   "log_sources": "User Account Modification (saas:zoom)",
   "log_sources_ja": "ユーザーアカウント変更 (saas:zoom)",
   "tuning": "AcceptedFactors",
   "detection_logic_en": "Detects suspicious MFA method changes, such as registration of weaker factors (e.g., SMS), or removal of MFA requirements for specific accounts or groups."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0549",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0549",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified)",
   "tuning": "MonitoredPolicies",
   "detection_logic_en": "Detects MFA bypass attempts by modifying tenant-wide authentication policies or excluding high-value accounts from MFA enforcement."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.007",
   "technique_ja": "ハイブリッドID",
   "technique_en": "Hybrid Identity",
   "analytic_id": "AN0814",
   "detection_strategy_id": "DET0293",
   "analytic_name": "Analytic 0814",
   "platforms": "Windows",
   "log_sources": "Module Load (WinEventLog:Sysmon) | Active Directory Object Modification (WinEventLog:Security) | Logon Session Creation (WinEventLog:Security)",
   "log_sources_ja": "モジュール読み込み (WinEventLog:Sysmon) | Active Directoryオブジェクト変更 (WinEventLog:Security) | ログオンセッション作成 (WinEventLog:Security)",
   "tuning": "WatchedServices | TimeWindow",
   "detection_logic_en": "Detects injection or tampering of DLLs in hybrid identity agents (e.g., AzureADConnectAuthenticationAgentService), registry or configuration changes tied to PTA/AD FS, and anomalous LSASS or AD FS module loads correlated with authentication anomalies."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.007",
   "technique_ja": "ハイブリッドID",
   "technique_en": "Hybrid Identity",
   "analytic_id": "AN0815",
   "detection_strategy_id": "DET0293",
   "analytic_name": "Analytic 0815",
   "platforms": "Identity Provider",
   "log_sources": "Application Log Content (azure:signinlogs) | User Account Modification (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (azure:signinlogs) | ユーザーアカウント変更 (m365:unified)",
   "tuning": "PrivilegedRoles",
   "detection_logic_en": "Detects registration of new PTA agents, conditional access changes disabling hybrid MFA enforcement, or suspicious updates to AD FS token-signing configurations."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.007",
   "technique_ja": "ハイブリッドID",
   "technique_en": "Hybrid Identity",
   "analytic_id": "AN0816",
   "detection_strategy_id": "DET0293",
   "analytic_name": "Analytic 0816",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Modification (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス変更 (AWS:CloudTrail)",
   "tuning": "MonitoredFederations",
   "detection_logic_en": "Detects API calls registering or updating hybrid identity connectors, modification of cloud-to-on-premises federation trust, and unusual token issuance logs."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.007",
   "technique_ja": "ハイブリッドID",
   "technique_en": "Hybrid Identity",
   "analytic_id": "AN0817",
   "detection_strategy_id": "DET0293",
   "analytic_name": "Analytic 0817",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified)",
   "tuning": "PolicyScope",
   "detection_logic_en": "Detects tenant-wide authentication or conditional access changes that weaken hybrid identity enforcement, including disabling AD FS or bypassing hybrid MFA policies."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.007",
   "technique_ja": "ハイブリッドID",
   "technique_en": "Hybrid Identity",
   "analytic_id": "AN0818",
   "detection_strategy_id": "DET0293",
   "analytic_name": "Analytic 0818",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (saas:okta)",
   "log_sources_ja": "アプリケーションログ内容 (saas:okta)",
   "tuning": "FederationEndpoints",
   "detection_logic_en": "Detects suspicious changes to SAML/OAuth federation configurations, such as new signing certificates, altered endpoints, or claims issuance rules granting elevated privileges."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.008",
   "technique_ja": "ネットワークプロバイダDLL",
   "technique_en": "Network Provider DLL",
   "analytic_id": "AN1598",
   "detection_strategy_id": "DET0580",
   "analytic_name": "Analytic 1598",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "MonitoredRegistryKeys | SuspiciousDLLPaths | TimeWindow",
   "detection_logic_en": "Detects registration of new or modified network provider DLLs via registry changes, anomalous file creation of DLLs in system directories, and suspicious process activity (mpnotify.exe interacting with non-standard DLLs). Multi-event correlation ties registry modification events to subsequent DLL loads during user logon activity."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.009",
   "technique_ja": "条件付きアクセスポリシー",
   "technique_en": "Conditional Access Policies",
   "analytic_id": "AN0087",
   "detection_strategy_id": "DET0030",
   "analytic_name": "Analytic 0087",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Modification (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス変更 (AWS:CloudTrail)",
   "tuning": "MonitoredIAMConditions | TimeWindow | PrivilegedAccounts",
   "detection_logic_en": "Detects modifications to IAM conditions or policies that alter authentication behavior, such as adding permissive trusted IPs, removing MFA requirements, or changing regional access restrictions. Behavioral detection focuses on anomalous policy updates tied to privileged accounts and subsequent suspicious logon activity from previously blocked regions or devices."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1556.009",
   "technique_ja": "条件付きアクセスポリシー",
   "technique_en": "Conditional Access Policies",
   "analytic_id": "AN0088",
   "detection_strategy_id": "DET0030",
   "analytic_name": "Analytic 0088",
   "platforms": "Identity Provider",
   "log_sources": "Active Directory Object Modification (azure:activity) | Application Log Content (saas:okta)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (azure:activity) | アプリケーションログ内容 (saas:okta)",
   "tuning": "TargetedApplications | RiskThresholds | UserContext",
   "detection_logic_en": "Detects suspicious updates to conditional access or MFA enforcement policies in identity providers such as Entra ID, Okta, or JumpCloud. Focus is on removal of policy blocks, addition of broad exclusions, or registration of adversary-controlled MFA methods, followed by anomalous login activity that takes advantage of the modified policies."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1578",
   "technique_ja": "クラウドコンピュートインフラの変更",
   "technique_en": "Modify Cloud Compute Infrastructure",
   "analytic_id": "AN0861",
   "detection_strategy_id": "DET0308",
   "analytic_name": "Analytic 0861",
   "platforms": "IaaS",
   "log_sources": "Instance Start (AWS:CloudTrail) | Instance Stop (AWS:CloudTrail) | Volume Modification (AWS:CloudTrail) | Volume Deletion (AWS:CloudTrail) | Volume Creation (AWS:CloudTrail) | Snapshot Creation (AWS:CloudTrail) | Snapshot Deletion (AWS:CloudTrail) | Snapshot Modification (AWS:CloudTrail) | Cloud Service Metadata (AWS:CloudWatch)",
   "log_sources_ja": "インスタンス起動 (AWS:CloudTrail) | インスタンス停止 (AWS:CloudTrail) | ボリューム変更 (AWS:CloudTrail) | ボリューム削除 (AWS:CloudTrail) | ボリューム作成 (AWS:CloudTrail) | スナップショット作成 (AWS:CloudTrail) | スナップショット削除 (AWS:CloudTrail) | スナップショット変更 (AWS:CloudTrail) | クラウドサービスメタデータ (AWS:CloudWatch)",
   "tuning": "ChangeWindow | UserContext | RateThreshold | GeoLocation",
   "detection_logic_en": "Detection focuses on identifying unauthorized or anomalous changes to compute infrastructure components. Defender perspective: monitor for creation, deletion, or modification of instances, volumes, and snapshots outside of approved change management windows; correlate abnormal activity such as rapid snapshot creation followed by new instance mounts, or repeated infrastructure changes by rarely used accounts. Flagging activity linked to unusual geolocation, API client, or automation script is suspicious."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1578.001",
   "technique_ja": "スナップショットの作成",
   "technique_en": "Create Snapshot",
   "analytic_id": "AN1187",
   "detection_strategy_id": "DET0423",
   "analytic_name": "Analytic 1187",
   "platforms": "IaaS",
   "log_sources": "Snapshot Creation (AWS:CloudTrail) | Snapshot Metadata (AWS:CloudTrail)",
   "log_sources_ja": "スナップショット作成 (AWS:CloudTrail) | スナップショットメタデータ (AWS:CloudTrail)",
   "tuning": "UserContext | TimeWindow | GeoLocation | VolumeSensitivity",
   "detection_logic_en": "Detection focuses on correlating snapshot creation events with subsequent instance creation and mounting activities. From a defender perspective, suspicious sequences include snapshot creation by unexpected or newly created IAM users, snapshots created from sensitive volumes without preceding change-control activity, or snapshots immediately followed by mounting to unauthorized instances. Cross-referencing with user behavior, IP geolocation, and automation context helps distinguish benign backup operations from adversary-driven snapshot exploitation."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1578.002",
   "technique_ja": "クラウドインスタンスの作成",
   "technique_en": "Create Cloud Instance",
   "analytic_id": "AN1242",
   "detection_strategy_id": "DET0449",
   "analytic_name": "Analytic 1242",
   "platforms": "IaaS",
   "log_sources": "Instance Start (AWS:CloudTrail) | Instance Metadata (AWS:CloudTrail) | Instance Creation (azure:activity)",
   "log_sources_ja": "インスタンス起動 (AWS:CloudTrail) | インスタンスメタデータ (AWS:CloudTrail) | インスタンス作成 (azure:activity)",
   "tuning": "UserContext | GeoLocation | RateThreshold | TaggingPolicy",
   "detection_logic_en": "Detection focuses on abnormal or unauthorized cloud instance creation events. From a defender’s perspective, suspicious behavior includes VM/instance creation by rarely used or newly created accounts, creation events from unusual geolocations, or rapid sequences of snapshot creation followed by instance creation and mounting. Unexpected network or IAM policy changes applied to new instances can indicate adversarial use rather than legitimate provisioning."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1578.003",
   "technique_ja": "クラウドインスタンスの削除",
   "technique_en": "Delete Cloud Instance",
   "analytic_id": "AN0234",
   "detection_strategy_id": "DET0084",
   "analytic_name": "Analytic 0234",
   "platforms": "IaaS",
   "log_sources": "Instance Stop (AWS:CloudTrail) | Instance Metadata (AWS:CloudTrail) | Instance Deletion (azure:activity)",
   "log_sources_ja": "インスタンス停止 (AWS:CloudTrail) | インスタンスメタデータ (AWS:CloudTrail) | インスタンス削除 (azure:activity)",
   "tuning": "UserContext | TimeWindow | GeoLocation | RateThreshold",
   "detection_logic_en": "Defenders can detect suspicious cloud instance deletions by correlating events across authentication, instance lifecycle, and account activity. From a defender’s perspective, behaviors of interest include instances deleted shortly after creation, deletions initiated by new or rarely used accounts, deletions following snapshot creation, and deletions originating from anomalous geolocations or access keys. These may indicate adversarial attempts to destroy forensic evidence or evade detection."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1578.004",
   "technique_ja": "クラウドインスタンスの復元",
   "technique_en": "Revert Cloud Instance",
   "analytic_id": "AN0953",
   "detection_strategy_id": "DET0337",
   "analytic_name": "Analytic 0953",
   "platforms": "IaaS",
   "log_sources": "Instance Modification (AWS:CloudTrail) | Instance Start (AWS:CloudTrail) | Instance Stop (AWS:CloudTrail)",
   "log_sources_ja": "インスタンス変更 (AWS:CloudTrail) | インスタンス起動 (AWS:CloudTrail) | インスタンス停止 (AWS:CloudTrail)",
   "tuning": "UserContext | TimeWindow | GeoLocation | ChangeTags",
   "detection_logic_en": "Defenders can detect suspicious reversion of cloud compute instances by monitoring for unusual snapshot restores, rollback actions, or ephemeral storage resets that occur outside expected administrative workflows. From a defender’s perspective, relevant detection chains include: a snapshot restore triggered by a new or rarely used account, a sequence of snapshot creation immediately followed by a restore and instance start, or rollbacks performed from anomalous geographic or network locations. These patterns may indicate attempts to remove forensic evidence or re-establish a clean execution state for persistence."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1578.005",
   "technique_ja": "クラウドコンピュート構成の変更",
   "technique_en": "Modify Cloud Compute Configurations",
   "analytic_id": "AN1356",
   "detection_strategy_id": "DET0492",
   "analytic_name": "Analytic 1356",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Modification (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス変更 (AWS:CloudTrail)",
   "tuning": "UserContext | TimeWindow | ChangeType | GeoLocation",
   "detection_logic_en": "Defenders should monitor for anomalous or unauthorized changes to cloud compute configurations that alter quotas, tenant-wide policies, subscription associations, or allowed deployment regions. From a defender’s perspective, suspicious behavior chains include a sudden increase in compute quota requests followed by new instance or resource creation, policy modifications that weaken security restrictions, or enabling previously unused/unsupported cloud regions. Correlation across identity, configuration, and subsequent provisioning logs is critical to distinguish legitimate administrative activity from adversarial abuse."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1599",
   "technique_ja": "ネットワーク境界のブリッジ",
   "technique_en": "Network Boundary Bridging",
   "analytic_id": "AN0015",
   "detection_strategy_id": "DET0006",
   "analytic_name": "Analytic 0015",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Flow (NSM:Flow) | Network Traffic Content (networkdevice:syslog)",
   "log_sources_ja": "ネットワークトラフィックフロー (NSM:Flow) | ネットワークトラフィック内容 (networkdevice:syslog)",
   "tuning": "TimeWindow | ApprovedChangeList | GeoLocation | TrafficVolumeThreshold",
   "detection_logic_en": "From a defender’s perspective, suspicious bridging is observed when network devices begin allowing traffic that contradicts existing segmentation or access policies. Observable behaviors include sudden modifications to ACLs or firewall rules, unusual cross-boundary traffic flows (e.g., east-west communications across separated VLANs), or simultaneous ingress/egress anomalies. Multi-event correlation is key: configuration changes on a router/firewall followed by unexpected traffic patterns, especially from unusual sources, is a strong indicator of compromise."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1599.001",
   "technique_ja": "NATトラバーサル",
   "technique_en": "Network Address Translation Traversal",
   "analytic_id": "AN0465",
   "detection_strategy_id": "DET0163",
   "analytic_name": "Analytic 0465",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Content (networkdevice:config) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィック内容 (networkdevice:config) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "TimeWindow | AuthorizedNATRules | TrafficVolumeThreshold | InterfaceScope",
   "detection_logic_en": "Defenders may observe unauthorized or anomalous changes to NAT configurations, including the addition of new translation rules or modifications to existing ones. Suspicious behaviors include sudden introduction of NAT mappings bridging segmented networks, new port address translation rules that obscure true source IPs, or traffic flows inconsistent with expected network design. Multi-event correlation includes detecting configuration changes on routers/firewalls, followed by traffic traversing unexpected internal/external address pairs."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1600",
   "technique_ja": "暗号化の脆弱化",
   "technique_en": "Weaken Encryption",
   "analytic_id": "AN0961",
   "detection_strategy_id": "DET0339",
   "analytic_name": "Analytic 0961",
   "platforms": "Network Devices",
   "log_sources": "File Modification (networkdevice:config) | Network Traffic Content (NSM:Flow) | Module Load (snmp:status)",
   "log_sources_ja": "ファイル変更 (networkdevice:config) | ネットワークトラフィック内容 (NSM:Flow) | モジュール読み込み (snmp:status)",
   "tuning": "CipherSuiteWhitelist | TimeWindow | AuthorizedFirmwareSources | TrafficEntropyThreshold",
   "detection_logic_en": "Defenders may observe unauthorized modifications to encryption-related configuration files, firmware, or crypto modules on network devices. Suspicious patterns include changes to cipher suite configurations, unexpected firmware updates affecting crypto libraries, disabling of hardware cryptographic accelerators, or reductions in key length policies. Correlating configuration changes with anomalies in encrypted traffic characteristics (e.g., weaker ciphers or sudden plaintext transmission) strengthens detection."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1600.001",
   "technique_ja": "鍵空間の縮小",
   "technique_en": "Reduce Key Space",
   "analytic_id": "AN0681",
   "detection_strategy_id": "DET0243",
   "analytic_name": "Analytic 0681",
   "platforms": "Network Devices",
   "log_sources": "File Modification (networkdevice:config) | Command Execution (networkdevice:cli) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ファイル変更 (networkdevice:config) | コマンド実行 (networkdevice:cli) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "AllowedKeyLengths | CipherSuiteBaseline | AuthorizedAdminAccounts | TimeWindow",
   "detection_logic_en": "Defenders may observe attempts to alter cryptographic settings on network devices that reduce key strength or allowable cipher suites. Suspicious indicators include configuration changes that downgrade encryption algorithms, key length parameters, or the disabling of strong encryption in favor of legacy ciphers. These activities often appear as CLI commands modifying crypto policies, firmware changes affecting crypto libraries, or unexpected updates to key management files. Correlation across device config logs and traffic analysis showing weaker ciphers provides higher confidence of malicious key space reduction."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1600.002",
   "technique_ja": "暗号ハードウェアの無効化",
   "technique_en": "Disable Crypto Hardware",
   "analytic_id": "AN1360",
   "detection_strategy_id": "DET0494",
   "analytic_name": "Analytic 1360",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:cli) | File Modification (networkdevice:config) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (networkdevice:cli) | ファイル変更 (networkdevice:config) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "AuthorizedAdminAccounts | BaselineThroughput | ApprovedFirmwareVersions | TimeWindow",
   "detection_logic_en": "Defenders may observe attempts to disable dedicated crypto hardware on network devices, often visible through anomalous CLI commands, unexpected firmware or configuration updates, and degraded encryption performance. Suspicious indicators include commands that alter hardware acceleration settings (e.g., disabling AES-NI or crypto engines), modification of system image files, or logs showing fallback from hardware to software encryption. Network traffic analysis may also reveal a sudden downgrade in throughput or cipher negotiation behavior consistent with the absence of hardware acceleration."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1601",
   "technique_ja": "システムイメージの変更",
   "technique_en": "Modify System Image",
   "analytic_id": "AN0482",
   "detection_strategy_id": "DET0170",
   "analytic_name": "Analytic 0482",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:cli) | File Modification (networkdevice:config)",
   "log_sources_ja": "コマンド実行 (networkdevice:cli) | ファイル変更 (networkdevice:config)",
   "tuning": "AuthorizedAdminAccounts | ApprovedFirmwareVersions | TimeWindow | ChecksumBaseline",
   "detection_logic_en": "Defenders may observe adversary attempts to alter or replace a network device’s operating system image through anomalous CLI commands, unexpected firmware updates, integrity check failures, or mismatches in version and checksum validation. Suspicious behavior includes modification of image files on storage, OS version output inconsistent with baselines, unexpected reloads or reboots after image replacement, and changes to boot configuration that load non-standard system images."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1601.001",
   "technique_ja": "システムイメージのパッチ",
   "technique_en": "Patch System Image",
   "analytic_id": "AN1293",
   "detection_strategy_id": "DET0469",
   "analytic_name": "Analytic 1293",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:cli) | File Modification (networkdevice:config) | Firmware Modification (firmware:runtime)",
   "log_sources_ja": "コマンド実行 (networkdevice:cli) | ファイル変更 (networkdevice:config) | ファームウェア変更 (firmware:runtime)",
   "tuning": "ApprovedFirmwareVersions | AuthorizedAdminAccounts | ChecksumBaseline | TimeWindow",
   "detection_logic_en": "Defenders may observe adversary attempts to patch system images by monitoring for anomalous file transfers (TFTP, SCP, FTP) of image files, unauthorized CLI commands altering boot system variables, integrity check mismatches between running and baseline OS images, and runtime memory manipulation attempts. Suspicious sequences include uploading a new image, modifying boot parameters, and subsequent reload/reboot of the device. In-memory patching attempts may manifest as debug commands or boot loader manipulation inconsistent with normal administrative activity."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1601.002",
   "technique_ja": "システムイメージのダウングレード",
   "technique_en": "Downgrade System Image",
   "analytic_id": "AN1570",
   "detection_strategy_id": "DET0569",
   "analytic_name": "Analytic 1570",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:cli) | File Modification (networkdevice:config) | File Metadata (networkdevice:syslog)",
   "log_sources_ja": "コマンド実行 (networkdevice:cli) | ファイル変更 (networkdevice:config) | ファイルメタデータ (networkdevice:syslog)",
   "tuning": "ApprovedFirmwareVersions | ChecksumBaseline | TimeWindow | AuthorizedAdminAccounts",
   "detection_logic_en": "Defenders may observe adversary attempts to downgrade system images by monitoring for anomalous file transfers of OS image files (via TFTP, FTP, SCP), configuration changes pointing boot system variables to older image files, unexpected OS version strings after reboot, and checksum mismatches against approved baseline images. Suspicious chains include transfer of an older image, alteration of boot configuration, and reboot/reload of the device. Adversaries may also tamper with CLI output to disguise downgrade attempts, requiring independent validation of OS version and integrity."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1647",
   "technique_ja": "plistファイルの変更",
   "technique_en": "Plist File Modification",
   "analytic_id": "AN0306",
   "detection_strategy_id": "DET0109",
   "analytic_name": "Analytic 0306",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | Process Creation (macos:unifiedlog) | Command Execution (macos:unifiedlog)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog) | コマンド実行 (macos:unifiedlog)",
   "tuning": "MonitoredDirectories | SuspiciousKeys | TimeWindow",
   "detection_logic_en": "Monitor for unexpected modifications of plist files in persistence or configuration directories (e.g., ~/Library/LaunchAgents, ~/Library/Preferences, /Library/LaunchDaemons). Detect when modifications are followed by execution of new or unexpected binaries. Track use of utilities such as defaults, plutil, or text editors making changes to Info.plist files. Correlate file modifications with subsequent process launches or service starts that reference the altered plist."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1666",
   "technique_ja": "クラウドリソース階層の変更",
   "technique_en": "Modify Cloud Resource Hierarchy",
   "analytic_id": "AN0442",
   "detection_strategy_id": "DET0155",
   "analytic_name": "Analytic 0442",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Modification (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス変更 (AWS:CloudTrail)",
   "tuning": "TimeWindow | PrivilegedRoleList | SubscriptionTransferPatterns",
   "detection_logic_en": "Monitor for unauthorized or unusual modifications to cloud resource hierarchies such as AWS Organizations or Azure Management Groups. Defenders may observe anomalous calls to APIs like `LeaveOrganization`, `CreateAccount`, `MoveAccount`, or Azure subscription transfers. Correlate account activity with administrative role assignments, tenant transfers, or new subscription creation that deviates from organizational baselines. Multi-event correlation should track role elevation followed by hierarchy modifications within a short time window."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685",
   "technique_ja": "ツールの無効化/変更",
   "technique_en": "Disable or Modify Tools",
   "analytic_id": "AN1369",
   "detection_strategy_id": "DET0497",
   "analytic_name": "Analytic 1369",
   "platforms": "Windows",
   "log_sources": "Service Creation (WinEventLog:System) | Process Termination (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "サービス作成 (WinEventLog:System) | プロセス終了 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "ProcessNameExclusions | TimeWindow | ServiceNames",
   "detection_logic_en": "Detection of adversary behavior that disables or modifies security tools, including killing AV/EDR processes, stopping services, altering Sysmon registry keys, or tampering with exclusion lists. Defenders observe process/service termination, registry modification, and abnormal absence of expected telemetry."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685",
   "technique_ja": "ツールの無効化/変更",
   "technique_en": "Disable or Modify Tools",
   "analytic_id": "AN1370",
   "detection_strategy_id": "DET0497",
   "analytic_name": "Analytic 1370",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Service Metadata (auditd:CONFIG_CHANGE)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | サービスメタデータ (auditd:CONFIG_CHANGE)",
   "tuning": "AgentServiceNames | AllowedAdminAccounts",
   "detection_logic_en": "Detects kill/systemctl/service commands against EDR, auditd, falco, osquery, rsyslog, journald, or agent processes; configuration edits disabling startup; module unload attempts; abrupt cessation of logs after privileged shell execution."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685",
   "technique_ja": "ツールの無効化/変更",
   "technique_en": "Disable or Modify Tools",
   "analytic_id": "AN1371",
   "detection_strategy_id": "DET0497",
   "analytic_name": "Analytic 1371",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Service Metadata (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | サービスメタデータ (macos:unifiedlog)",
   "tuning": "DaemonNames | TimeWindow",
   "detection_logic_en": "Detection of adversary disabling endpoint security tools by unloading launch agents/daemons, modifying configuration profiles, or disabling Gatekeeper/XProtect/logging settings, or removing endpoint agents followed by telemetry loss."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685",
   "technique_ja": "ツールの無効化/変更",
   "technique_en": "Disable or Modify Tools",
   "analytic_id": "AN1372",
   "detection_strategy_id": "DET0497",
   "analytic_name": "Analytic 1372",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Modification (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス変更 (AWS:CloudTrail)",
   "tuning": "APIActions | UserContext",
   "detection_logic_en": "Correlates control-plane API actions disabling cloud-native monitoring or sensor agents (CloudTrail, GuardDuty, Security Hub, Defender, monitoring agents), role abuse preceding disablement, or instance agent uninstall events"
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685",
   "technique_ja": "ツールの無効化/変更",
   "technique_en": "Disable or Modify Tools",
   "analytic_id": "AN1373",
   "detection_strategy_id": "DET0497",
   "analytic_name": "Analytic 1373",
   "platforms": "Containers",
   "log_sources": "Service Metadata (kubernetes:audit)",
   "log_sources_ja": "サービスメタデータ (kubernetes:audit)",
   "tuning": "NamespaceExclusions",
   "detection_logic_en": "Detects disabling container runtime security controls, removing sidecar sensors, modifying seccomp/AppArmor profiles, mounting host proc/sys paths to interfere with host logging, or killing in-container monitoring agents."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685",
   "technique_ja": "ツールの無効化/変更",
   "technique_en": "Disable or Modify Tools",
   "analytic_id": "AN1374",
   "detection_strategy_id": "DET0497",
   "analytic_name": "Analytic 1374",
   "platforms": "Network Devices",
   "log_sources": "Service Metadata (networkdevice:config) | Host Status (networkdevice:syslog)",
   "log_sources_ja": "サービスメタデータ (networkdevice:config) | ホスト状態 (networkdevice:syslog)",
   "tuning": "ConfigBaseline",
   "detection_logic_en": "Detects disabling AAA, syslog, SNMP traps, ACL logging, or security features on routers/switches/firewalls; correlates privileged login followed by configuration commit reducing visibility."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685",
   "technique_ja": "ツールの無効化/変更",
   "technique_en": "Disable or Modify Tools",
   "analytic_id": "AN2044",
   "detection_strategy_id": "DET0497",
   "analytic_name": "Analytic 2044",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:shell) | Service Modification (esxi:hostd)",
   "log_sources_ja": "コマンド実行 (esxi:shell) | サービス変更 (esxi:hostd)",
   "tuning": "ExpectedAdminIPs",
   "detection_logic_en": "Detects esxcli commands disabling syslog, firewall, lockdown mode, or stopping hostd/vpxa; correlates command execution with reduced forwarding activity."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685.001",
   "technique_ja": "Windowsイベントログの無効化/変更",
   "technique_en": "Disable or Modify Windows Event Log",
   "analytic_id": "AN0535",
   "detection_strategy_id": "DET0187",
   "analytic_name": "Analytic 0535",
   "platforms": "Windows",
   "log_sources": "Service Metadata (WinEventLog:System) | Application Log Content (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "サービスメタデータ (WinEventLog:System) | アプリケーションログ内容 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "AuthorizedAdminAccounts | TimeWindow | ServiceNames",
   "detection_logic_en": "Detection of attempts to disable or tamper with Windows Event Logging. This includes stopping or disabling the EventLog service, modifying registry keys related to EventLog and Autologger, using `auditpol` or `wevtutil` to disable categories or clear audit policies, and detecting suspicious gaps or resets in event logs. Defenders observe registry changes, service state changes, process execution of disabling commands, and anomalies in event record sequences."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685.002",
   "technique_ja": "クラウドログの無効化/変更",
   "technique_en": "Disable or Modify Cloud Log",
   "analytic_id": "AN0801",
   "detection_strategy_id": "DET0289",
   "analytic_name": "Analytic 0801",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Disable (AWS:CloudTrail) | Cloud Service Modification (gcp:config)",
   "log_sources_ja": "クラウドサービス無効化 (AWS:CloudTrail) | クラウドサービス変更 (gcp:config)",
   "tuning": "AdminRoles | RegionScope",
   "detection_logic_en": "Cloud API events where logging services are stopped, deleted, or modified in a way that disables audit visibility. Defender view: unauthorized StopLogging, DeleteTrail, or UpdateSink operations correlated with privileged user activity."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685.002",
   "technique_ja": "クラウドログの無効化/変更",
   "technique_en": "Disable or Modify Cloud Log",
   "analytic_id": "AN0802",
   "detection_strategy_id": "DET0289",
   "analytic_name": "Analytic 0802",
   "platforms": "Identity Provider",
   "log_sources": "Cloud Service Modification (azure:policy)",
   "log_sources_ja": "クラウドサービス変更 (azure:policy)",
   "tuning": "CriticalAccounts",
   "detection_logic_en": "Disabling or modifying sign-in or audit log collection for user activities. Defender view: policy or configuration updates removing logging coverage for critical accounts."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685.002",
   "technique_ja": "クラウドログの無効化/変更",
   "technique_en": "Disable or Modify Cloud Log",
   "analytic_id": "AN0803",
   "detection_strategy_id": "DET0289",
   "analytic_name": "Analytic 0803",
   "platforms": "Office Suite",
   "log_sources": "User Account Modification (m365:unified)",
   "log_sources_ja": "ユーザーアカウント変更 (m365:unified)",
   "tuning": "UserScope",
   "detection_logic_en": "Disabling mailbox or tenant-level audit logging, often using Set-MailboxAuditBypassAssociation or downgrading license tiers. Defender view: sudden absence of mailbox activity logging for monitored users."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685.002",
   "technique_ja": "クラウドログの無効化/変更",
   "technique_en": "Disable or Modify Cloud Log",
   "analytic_id": "AN0804",
   "detection_strategy_id": "DET0289",
   "analytic_name": "Analytic 0804",
   "platforms": "SaaS",
   "log_sources": "Cloud Service Disable (saas:audit)",
   "log_sources_ja": "クラウドサービス無効化 (saas:audit)",
   "tuning": "IntegrationScope",
   "detection_logic_en": "Disabling or altering security and audit logs in SaaS admin panels (e.g., Slack, Zoom, Salesforce). Defender view: API calls or admin console changes that stop event exports or logging integrations."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685.003",
   "technique_ja": "ツールUIの改変/偽装",
   "technique_en": "Modify or Spoof Tool UI",
   "analytic_id": "AN0868",
   "detection_strategy_id": "DET0311",
   "analytic_name": "Analytic 0868",
   "platforms": "Windows",
   "log_sources": "Service Creation (WinEventLog:System) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "サービス作成 (WinEventLog:System) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "ServiceNameList | FakeUIProcessPatterns",
   "detection_logic_en": "Detection of inconsistencies between reported sensor health and actual process/service state. For example, Windows Defender tray icon/UI showing healthy status while corresponding Defender services (WinDefend, MsMpEng) are stopped or disabled. Correlates process creation events with missing or terminated security processes and spoofed health events."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685.003",
   "technique_ja": "ツールUIの改変/偽装",
   "technique_en": "Modify or Spoof Tool UI",
   "analytic_id": "AN0869",
   "detection_strategy_id": "DET0311",
   "analytic_name": "Analytic 0869",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Host Status (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ホスト状態 (linux:syslog)",
   "tuning": "SecurityDaemonList",
   "detection_logic_en": "Monitoring for discrepancies between system daemon/service state and reported health messages (e.g., syslog shows AV/IDS daemon stopped, but spoofed messages claim it is still running). Detects userland processes impersonating AV/IDS command-line outputs or modifying log forwarding configurations."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685.003",
   "technique_ja": "ツールUIの改変/偽装",
   "technique_en": "Modify or Spoof Tool UI",
   "analytic_id": "AN0870",
   "detection_strategy_id": "DET0311",
   "analytic_name": "Analytic 0870",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Host Status (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ホスト状態 (macos:unifiedlog)",
   "tuning": "TrustedDaemonList",
   "detection_logic_en": "Detection of fake or spoofed macOS Security & Privacy GUIs showing healthy status after XProtect, Gatekeeper, or AV processes are disabled. Correlates user-space UI process creation with terminated or missing security daemons."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685.004",
   "technique_ja": "Linux監査システムログの無効化/変更",
   "technique_en": "Disable or Modify Linux Audit System Log",
   "analytic_id": "AN0171",
   "detection_strategy_id": "DET0062",
   "analytic_name": "Analytic 0171",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:EXECVE) | Process Modification (auditd:SYSCALL) | File Modification (auditd:FILE) | Service Metadata (linux:syslog)",
   "log_sources_ja": "コマンド実行 (auditd:EXECVE) | プロセス変更 (auditd:SYSCALL) | ファイル変更 (auditd:FILE) | サービスメタデータ (linux:syslog)",
   "tuning": "ServiceWhitelist | FilePathScope | TimeWindow",
   "detection_logic_en": "Disabling or modifying the Linux Audit system through process termination (auditd killed), service management (systemctl stop auditd), or tampering with rule/configuration files (/etc/audit/audit.rules, audit.conf). Defender view: suspicious execution of auditctl/systemctl commands, file modifications to audit rules, or sudden absence of audit logs correlated with privileged execution."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685.005",
   "technique_ja": "Windowsイベントログの消去",
   "technique_en": "Clear Windows Event Logs",
   "analytic_id": "AN1472",
   "detection_strategy_id": "DET0532",
   "analytic_name": "Analytic 1472",
   "platforms": "Windows",
   "log_sources": "Application Log Content (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | File Deletion (WinEventLog:Sysmon)",
   "log_sources_ja": "アプリケーションログ内容 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ファイル削除 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext | CommandLinePattern | TargetLogName",
   "detection_logic_en": "Detects behavioral sequence where an adversary gains elevated privileges and clears event logs using native binaries (e.g., wevtutil), PowerShell, or direct file deletion of .evtx files."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685.006",
   "technique_ja": "LinuxまたはMacシステムログの消去",
   "technique_en": "Clear Linux or Mac System Logs",
   "analytic_id": "AN1438",
   "detection_strategy_id": "DET0520",
   "analytic_name": "Analytic 1438",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Deletion (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル削除 (auditd:SYSCALL)",
   "tuning": "TimeWindow | LogFilePathPattern | UserContext",
   "detection_logic_en": "Detects log-clearing behavior by correlating suspicious command execution targeting log files under /var/log/, anomalous deletions or truncations of system logs, and unusual child processes (e.g., shell pipelines or redirections)."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1685.006",
   "technique_ja": "LinuxまたはMacシステムログの消去",
   "technique_en": "Clear Linux or Mac System Logs",
   "analytic_id": "AN1439",
   "detection_strategy_id": "DET0520",
   "analytic_name": "Analytic 1439",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (fs:fsusage)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (fs:fsusage)",
   "tuning": "TimeWindow | LogFilePathPattern | UserContext",
   "detection_logic_en": "Detects adversary clearing log files on macOS by correlating calls to shell utilities (e.g., echo >, rm, truncate) targeting files in /var/log/ with unusual context (non-administrative users or abnormal process lineage)."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1686",
   "technique_ja": "システムファイアウォールの無効化/変更",
   "technique_en": "Disable or Modify System Firewall",
   "analytic_id": "AN0406",
   "detection_strategy_id": "DET0145",
   "analytic_name": "Analytic 0406",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "MonitoredCommands | AlertThreshold",
   "detection_logic_en": "Detection of firewall tampering by monitoring processes executing netsh, PowerShell Set-NetFirewallProfile, or sc stop mpssvc. Registry modifications under HKLM\\SYSTEM\\CurrentControlSet\\Services\\SharedAccess\\Parameters\\FirewallPolicy also indicate adversarial actions."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1686",
   "technique_ja": "システムファイアウォールの無効化/変更",
   "technique_en": "Disable or Modify System Firewall",
   "analytic_id": "AN0407",
   "detection_strategy_id": "DET0145",
   "analytic_name": "Analytic 0407",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | Process Creation (linux:osquery)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | プロセス生成 (linux:osquery)",
   "tuning": "AllowedScripts",
   "detection_logic_en": "Detection of iptables, nftables, or firewalld rule modifications. Correlation of sudden drops in active firewall rules with suspicious processes suggests adversarial evasion."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1686",
   "technique_ja": "システムファイアウォールの無効化/変更",
   "technique_en": "Disable or Modify System Firewall",
   "analytic_id": "AN0408",
   "detection_strategy_id": "DET0145",
   "analytic_name": "Analytic 0408",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog)",
   "tuning": "PFConfigFiles",
   "detection_logic_en": "Detection of PF firewall rule modifications via pfctl, socketfilterfw, or defaults write to com.apple.alf. Adversaries often disable firewall profiles entirely or whitelist malicious processes."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1686",
   "technique_ja": "システムファイアウォールの無効化/変更",
   "technique_en": "Disable or Modify System Firewall",
   "analytic_id": "AN0409",
   "detection_strategy_id": "DET0145",
   "analytic_name": "Analytic 0409",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:hostd) | Firewall Rule Modification (esxi:hostd)",
   "log_sources_ja": "コマンド実行 (esxi:hostd) | ファイアウォールルール変更 (esxi:hostd)",
   "tuning": "APIMethods",
   "detection_logic_en": "Detection of firewall changes using esxcli network firewall set or vSphere API modifications. Sudden disabling of firewall rules across management interfaces is a strong adversarial signal."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1686",
   "technique_ja": "システムファイアウォールの無効化/変更",
   "technique_en": "Disable or Modify System Firewall",
   "analytic_id": "AN0410",
   "detection_strategy_id": "DET0145",
   "analytic_name": "Analytic 0410",
   "platforms": "Network Devices",
   "log_sources": "Firewall Rule Modification (networkdevice:cli)",
   "log_sources_ja": "ファイアウォールルール変更 (networkdevice:cli)",
   "tuning": "AuthorizedAdmins",
   "detection_logic_en": "Detection of firewall ACL or rule base changes through CLI (e.g., no access-list, permit any any). Monitor configuration commits from unusual users or sessions."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1686.001",
   "technique_ja": "クラウドファイアウォール",
   "technique_en": "Cloud Firewall",
   "analytic_id": "AN1188",
   "detection_strategy_id": "DET0424",
   "analytic_name": "Analytic 1188",
   "platforms": "IaaS",
   "log_sources": "Firewall Rule Modification (AWS:CloudTrail) | Firewall Disable (AWS:CloudTrail)",
   "log_sources_ja": "ファイアウォールルール変更 (AWS:CloudTrail) | ファイアウォール無効化 (AWS:CloudTrail)",
   "tuning": "AllowedIPRanges | PortScope | RoleContext | TimeWindow",
   "detection_logic_en": "Creation, deletion, or modification of security groups and firewall rules in cloud control plane logs that expand access to cloud resources beyond expected baselines. Defender view: unexpected ingress/egress rules permitting 0.0.0.0/0 or opening atypical ports, often correlated with privileged role or API key activity."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1686.002",
   "technique_ja": "ネットワークデバイスファイアウォール",
   "technique_en": "Network Device Firewall",
   "analytic_id": "AN0855",
   "detection_strategy_id": "DET0306",
   "analytic_name": "Analytic 0855",
   "platforms": "Network Devices",
   "log_sources": "Firewall Rule Modification (networkdevice:Firewall) | Logon Session Creation (networkdevice:Firewall) | Command Execution (networkdevice:Firewall) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "ファイアウォールルール変更 (networkdevice:Firewall) | ログオンセッション作成 (networkdevice:Firewall) | コマンド実行 (networkdevice:Firewall) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "TrustedAdminIPs | ConfigChangeWindow | RuleScopeThreshold | NewUserPrivilegeThreshold",
   "detection_logic_en": "Defender observes configuration changes on firewall/network appliance involving rule creation, modification, or deletion from abnormal management IPs or non-console channels (e.g., remote CLI, API). These are often correlated with a spike in previously blocked outbound traffic, unexpected allow-all rules, or bulk rule deletions. Behavior often follows unauthorized login, privilege escalation, or API abuse."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1686.003",
   "technique_ja": "Windowsホストファイアウォール",
   "technique_en": "Windows Host Firewall",
   "analytic_id": "AN2043",
   "detection_strategy_id": "DET0901",
   "analytic_name": "Analytic 2043",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon) | Windows Registry Key Creation (WinEventLog:Sysmon) | Service Creation (WinEventLog:System) | Network Connection Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | Windowsレジストリキー作成 (WinEventLog:Sysmon) | サービス作成 (WinEventLog:System) | ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Security)",
   "tuning": "AuthorizedAdminAccounts | MaintenanceWindow | ExposureCorrelationWindow | SensitivePorts | AllowedManagementParents | RuleScopeThreshold",
   "detection_logic_en": "Detects processes or users modifying Windows Defender Firewall profiles, policies, or rules followed by measurable network exposure changes. Correlates firewall management execution, registry/policy mutation, service state changes, and subsequent inbound or outbound connectivity inconsistent with baseline administration."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1687",
   "technique_ja": "防御妨害のための脆弱性悪用",
   "technique_en": "Exploitation for Defense Impairment",
   "analytic_id": "AN2038",
   "detection_strategy_id": "DET0900",
   "analytic_name": "Analytic 2038",
   "platforms": "Windows",
   "log_sources": "Service Metadata (WinEventLog:System) | Process Creation (WinEventLog:Sysmon) | Driver Load (WinEventLog:Sysmon) | Process Creation (WinEventLog:Security)",
   "log_sources_ja": "サービスメタデータ (WinEventLog:System) | プロセス生成 (WinEventLog:Sysmon) | ドライバ読み込み (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Security)",
   "tuning": "CrashCorrelationWindow | ProtectedServiceList | TelemetryGapThreshold",
   "detection_logic_en": "Detects suspicious interactions with security products followed by service crashes, unexpected restarts, driver unloads, telemetry gaps, or tamper-state changes. Correlates exploit precursor behavior with immediate degradation of defensive services and follow-on process execution."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1687",
   "technique_ja": "防御妨害のための脆弱性悪用",
   "technique_en": "Exploitation for Defense Impairment",
   "analytic_id": "AN2039",
   "detection_strategy_id": "DET0900",
   "analytic_name": "Analytic 2039",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:EXECVE) | Service Metadata (auditd:DAEMON)",
   "log_sources_ja": "コマンド実行 (auditd:EXECVE) | サービスメタデータ (auditd:DAEMON)",
   "tuning": "ProtectedProcessNames | ModuleUnloadAllowlist | HealthGapThreshold",
   "detection_logic_en": "Detects exploitation attempts against security daemons or kernel security modules followed by daemon termination, disabled logging, module unload, audit stoppage, or reduced endpoint telemetry. Correlates local execution or network input with control degradation."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1687",
   "technique_ja": "防御妨害のための脆弱性悪用",
   "technique_en": "Exploitation for Defense Impairment",
   "analytic_id": "AN2042",
   "detection_strategy_id": "DET0900",
   "analytic_name": "Analytic 2042",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (saas:okta) | Application Log Content (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (saas:okta) | アプリケーションログ内容 (m365:unified)",
   "tuning": "PrivilegedActorAllowlist | RetentionChangeThreshold",
   "detection_logic_en": "Detects exploitation or abuse of SaaS security workflows resulting in disabled alerts, reduced retention, bypassed enforcement, role escalation, or tokenized persistence that weakens monitoring. Correlates unusual admin/API activity with visibility reduction."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1687",
   "technique_ja": "防御妨害のための脆弱性悪用",
   "technique_en": "Exploitation for Defense Impairment",
   "analytic_id": "AN2040",
   "detection_strategy_id": "DET0900",
   "analytic_name": "Analytic 2040",
   "platforms": "macOS",
   "log_sources": "Process Metadata (macos:unifiedlog) | Driver Metadata (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセスメタデータ (macos:unifiedlog) | ドライバメタデータ (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ExtensionList | CrashBurstThreshold",
   "detection_logic_en": "Detects crafted activity resulting in crashes or impairment of endpoint security extensions, network filters, launch daemons, or telemetry agents. Correlates process activity, system extension state changes, and telemetry interruption."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1687",
   "technique_ja": "防御妨害のための脆弱性悪用",
   "technique_en": "Exploitation for Defense Impairment",
   "analytic_id": "AN2041",
   "detection_strategy_id": "DET0900",
   "analytic_name": "Analytic 2041",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Disable (AWS:CloudTrail) | Instance Modification (AWS:CloudTrail) | Firewall Rule Modification (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス無効化 (AWS:CloudTrail) | インスタンス変更 (AWS:CloudTrail) | ファイアウォールルール変更 (AWS:CloudTrail)",
   "tuning": "CriticalTrailList | ControlChangeWindow",
   "detection_logic_en": "Detects exploitation of cloud-native security boundaries or management components followed by disabled logging, detached agents, changed security groups, policy bypass, or telemetry suppression. Correlates suspicious API activity with reduced control coverage."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1688",
   "technique_ja": "セーフモードブート",
   "technique_en": "Safe Mode Boot",
   "analytic_id": "AN0323",
   "detection_strategy_id": "DET0116",
   "analytic_name": "Analytic 0323",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon) | Windows Registry Key Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | Windowsレジストリキー作成 (WinEventLog:Sysmon)",
   "tuning": "SafeBootRegistryPaths | AllowedAdminTools | TimeWindow",
   "detection_logic_en": "Abuse of safe mode via BCD modification, boot configuration utilities (bcdedit.exe, bootcfg.exe), and registry persistence under SafeBoot keys. Defender view: suspicious boot configuration changes correlated with registry edits that enable adversary persistence or disable defenses."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1689",
   "technique_ja": "ダウングレード攻撃",
   "technique_en": "Downgrade Attack",
   "analytic_id": "AN0995",
   "detection_strategy_id": "DET0350",
   "analytic_name": "Analytic 0995",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Security)",
   "tuning": "AllowedInterpreterVersions | RegistryDefenderKeys",
   "detection_logic_en": "Detection of processes launching downgraded PowerShell versions (e.g., v2) or other legacy binaries that lack logging or security features. Correlates command-line arguments, process metadata, and version fields. Monitors registry changes to Defender or HVCI keys that could indicate intentional downgrades."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1689",
   "technique_ja": "ダウングレード攻撃",
   "technique_en": "Downgrade Attack",
   "analytic_id": "AN0996",
   "detection_strategy_id": "DET0350",
   "analytic_name": "Analytic 0996",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | Process Metadata (linux:syslog)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | プロセスメタデータ (linux:syslog)",
   "tuning": "AllowedCryptoProtocols",
   "detection_logic_en": "Monitors execution of older or legacy interpreters (e.g., python2, bash with restricted history logging), downgrade of TLS/SSL configurations, or forced fallback to unencrypted protocols. Detects suspicious reconfiguration of kernel modules or boot loaders to reduce integrity controls."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1689",
   "technique_ja": "ダウングレード攻撃",
   "technique_en": "Downgrade Attack",
   "analytic_id": "AN0997",
   "detection_strategy_id": "DET0350",
   "analytic_name": "Analytic 0997",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Process Metadata (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | プロセスメタデータ (macos:unifiedlog)",
   "tuning": "ApprovedInterpreterVersions",
   "detection_logic_en": "Detection of execution of legacy scripting runtimes (e.g., older versions of Python, Bash, or PowerShell Core) lacking auditing. Monitoring for changes to EFI or system boot files indicative of downgrade-based persistence or bypass of integrity features."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1690",
   "technique_ja": "コマンド履歴ログの抑止",
   "technique_en": "Prevent Command History Logging",
   "analytic_id": "AN1555",
   "detection_strategy_id": "DET0563",
   "analytic_name": "Analytic 1555",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | Process Creation (linux:osquery)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | プロセス生成 (linux:osquery)",
   "tuning": "MonitoredUsers | TimeWindow",
   "detection_logic_en": "Detection of environment variable tampering (HISTFILE, HISTCONTROL, HISTFILESIZE) and absence of expected bash history writes. Correlation of unset or zeroed history variables with active shell sessions is indicative of adversarial evasion."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1690",
   "technique_ja": "コマンド履歴ログの抑止",
   "technique_en": "Prevent Command History Logging",
   "analytic_id": "AN1556",
   "detection_strategy_id": "DET0563",
   "analytic_name": "Analytic 1556",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog)",
   "tuning": "ShellProfiles",
   "detection_logic_en": "Detection of bash/zsh history suppression via HISTFILE/HISTCONTROL manipulation and absence of ~/.bash_history updates. Observing environment variable changes tied to terminal processes is a strong indicator."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1690",
   "technique_ja": "コマンド履歴ログの抑止",
   "technique_en": "Prevent Command History Logging",
   "analytic_id": "AN1557",
   "detection_strategy_id": "DET0563",
   "analytic_name": "Analytic 1557",
   "platforms": "Windows",
   "log_sources": "Command Execution (WinEventLog:PowerShell) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "コマンド実行 (WinEventLog:PowerShell) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "AllowedPaths",
   "detection_logic_en": "Detection of PowerShell history suppression using Set-PSReadLineOption with SaveNothing or altered HistorySavePath. Correlating these options with PowerShell usage highlights adversarial evasion attempts."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1690",
   "technique_ja": "コマンド履歴ログの抑止",
   "technique_en": "Prevent Command History Logging",
   "analytic_id": "AN1558",
   "detection_strategy_id": "DET0563",
   "analytic_name": "Analytic 1558",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:shell)",
   "log_sources_ja": "コマンド実行 (esxi:shell)",
   "tuning": "AdminSessions",
   "detection_logic_en": "Detection of unset HISTFILE or modified history variables in ESXi shell sessions. Correlation of suspicious shell sessions with no recorded commands despite active usage."
  },
  {
   "tactic_id": "TA0112",
   "tactic_ja": "防御妨害",
   "technique_id": "T1690",
   "technique_ja": "コマンド履歴ログの抑止",
   "technique_en": "Prevent Command History Logging",
   "analytic_id": "AN1559",
   "detection_strategy_id": "DET0563",
   "analytic_name": "Analytic 1559",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:cli)",
   "log_sources_ja": "コマンド実行 (networkdevice:cli)",
   "tuning": "DeviceVendors",
   "detection_logic_en": "Detection of CLI commands that disable history logging such as 'no logging'. Anomalous lack of new commands in session logs while activity persists is a strong signal."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1003",
   "technique_ja": "OS認証情報のダンプ",
   "technique_en": "OS Credential Dumping",
   "analytic_id": "AN0648",
   "detection_strategy_id": "DET0234",
   "analytic_name": "Analytic 0648",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | File Access (WinEventLog:Security) | Active Directory Object Access (WinEventLog:Security)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Security) | Active Directoryオブジェクトアクセス (WinEventLog:Security)",
   "tuning": "AccessMask | TimeWindow | ParentProcessFilter",
   "detection_logic_en": "Processes accessing LSASS memory or SAM registry hives outside of trusted security tools, often followed by file creation or lateral movement. Detects unauthorized access to sensitive OS subsystems for credential extraction."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1003",
   "technique_ja": "OS認証情報のダンプ",
   "technique_en": "OS Credential Dumping",
   "analytic_id": "AN0649",
   "detection_strategy_id": "DET0234",
   "analytic_name": "Analytic 0649",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Process Access (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | プロセスアクセス (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "TargetProcessName | ToolProcessName",
   "detection_logic_en": "Processes opening /proc/*/mem or /proc/*/maps targeting credential-storing services like sshd or login. Behavior often includes high privilege escalation and memory inspection tools such as gcore or gdb."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1003",
   "technique_ja": "OS認証情報のダンプ",
   "technique_en": "OS Credential Dumping",
   "analytic_id": "AN0650",
   "detection_strategy_id": "DET0234",
   "analytic_name": "Analytic 0650",
   "platforms": "macOS",
   "log_sources": "Process Metadata (macos:unifiedlog) | File Access (macos:keychain) | Process Creation (macos:osquery)",
   "log_sources_ja": "プロセスメタデータ (macos:unifiedlog) | ファイルアクセス (macos:keychain) | プロセス生成 (macos:osquery)",
   "tuning": "KeychainAccessPath | SignedBinaryStatus",
   "detection_logic_en": "Unsigned processes accessing system memory or launching known credential scraping tools (e.g., osascript, dylib injections) to access the Keychain or sensitive memory regions."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1003.001",
   "technique_ja": "LSASSメモリ",
   "technique_en": "LSASS Memory",
   "analytic_id": "AN1030",
   "detection_strategy_id": "DET0363",
   "analytic_name": "Analytic 1030",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | User Account Metadata (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ユーザーアカウントメタデータ (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "AccessMask | TimeWindow | ParentProcessName | DumpFilePath | CommandLinePattern",
   "detection_logic_en": "A non-privileged or abnormal process attempts to open a handle with full access (0x1F0FFF) to lsass.exe and subsequently invokes memory dump, file creation, or registry modification indicative of credential scraping. This behavior chain reflects staged credential theft activity."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1003.002",
   "technique_ja": "セキュリティアカウントマネージャ（SAM）",
   "technique_en": "Security Account Manager",
   "analytic_id": "AN0235",
   "detection_strategy_id": "DET0085",
   "analytic_name": "Analytic 0235",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | File Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Sysmon)",
   "tuning": "CommandLinePattern | TargetFilePath | RegistryPath | TimeWindow | ParentProcessName",
   "detection_logic_en": "An adversary running with SYSTEM-level privileges executes commands or accesses registry keys to dump the SAM hive or directly reads sensitive local files from the config directory. This behavior often involves sequential access to HKLM\\SAM, HKLM\\SYSTEM, and creation of .save or .dmp files, enabling offline hash extraction."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1003.003",
   "technique_ja": "NTDS",
   "technique_en": "NTDS",
   "analytic_id": "AN1611",
   "detection_strategy_id": "DET0586",
   "analytic_name": "Analytic 1611",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Modification (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Volume Creation (WinEventLog:Microsoft-Windows-VSS)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル変更 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ボリューム作成 (WinEventLog:Microsoft-Windows-VSS)",
   "tuning": "TargetFilePath | ParentProcessName | TimeWindow | UserContext",
   "detection_logic_en": "Detects credential dumping attempts targeting the NTDS.dit database by monitoring shadow copy creation, suspicious file access to %SystemRoot%\\NTDS\\ntds.dit, and the use of tooling like ntdsutil.exe or volume management APIs."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1003.004",
   "technique_ja": "LSAシークレット",
   "technique_en": "LSA Secrets",
   "analytic_id": "AN1212",
   "detection_strategy_id": "DET0437",
   "analytic_name": "Analytic 1212",
   "platforms": "Windows",
   "log_sources": "File Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "TargetObject | ImageLoaded | AccessMask | TimeWindow",
   "detection_logic_en": "Detects adversary activity aimed at accessing LSA Secrets, including registry key export of HKEY_LOCAL_MACHINE\\SECURITY\\Policy\\Secrets or memory scraping via tools such as Mimikatz or PowerSploit's Invoke-Mimikatz."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1003.005",
   "technique_ja": "キャッシュされたドメイン認証情報",
   "technique_en": "Cached Domain Credentials",
   "analytic_id": "AN1417",
   "detection_strategy_id": "DET0513",
   "analytic_name": "Analytic 1417",
   "platforms": "Windows",
   "log_sources": "File Access (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイルアクセス (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "TargetFilename | CommandLine | TimeWindow",
   "detection_logic_en": "Detects adversary behavior accessing Windows cached domain credential files using tools like Mimikatz, reg.exe, or PowerShell, often combined with registry exports or LSASS memory scraping."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1003.005",
   "technique_ja": "キャッシュされたドメイン認証情報",
   "technique_en": "Cached Domain Credentials",
   "analytic_id": "AN1418",
   "detection_strategy_id": "DET0513",
   "analytic_name": "Analytic 1418",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Process Creation (auditd:EXECVE) | Process Access (linux:osquery)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | プロセス生成 (auditd:EXECVE) | プロセスアクセス (linux:osquery)",
   "tuning": "filepath | CommandLine | TimeWindow",
   "detection_logic_en": "Detects access to SSSD or Quest VAS cached credential databases using tdbdump or other file access patterns, requiring sudo/root access."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1003.006",
   "technique_ja": "DCSync",
   "technique_en": "DCSync",
   "analytic_id": "AN1632",
   "detection_strategy_id": "DET0594",
   "analytic_name": "Analytic 1632",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Access (WinEventLog:Security) | Active Directory Object Deletion (WinEventLog:Security) | Network Traffic Content (NSM:Content)",
   "log_sources_ja": "Active Directoryオブジェクトアクセス (WinEventLog:Security) | Active Directoryオブジェクト削除 (WinEventLog:Security) | ネットワークトラフィック内容 (NSM:Content)",
   "tuning": "TimeWindow | UserContext | SourceIP",
   "detection_logic_en": "Detects unauthorized invocation of replication operations (DCSync) via Directory Replication Service (DRS), often executed by threat actors using Mimikatz or similar tools from non-DC endpoints."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1003.007",
   "technique_ja": "Procファイルシステム",
   "technique_en": "Proc Filesystem",
   "analytic_id": "AN1631",
   "detection_strategy_id": "DET0593",
   "analytic_name": "Analytic 1631",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | File Modification (auditd:SYSCALL) | Process Access (auditd:SYSCALL) | Process Creation (linux:Sysmon)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL) | プロセスアクセス (auditd:SYSCALL) | プロセス生成 (linux:Sysmon)",
   "tuning": "AccessedFilePath | ProcessName | UserContext | TimeWindow",
   "detection_logic_en": "Monitoring adversary access to sensitive process memory via the /proc filesystem to extract credential material, often involving multi-step access to /proc/[pid]/mem or /proc/[pid]/maps combined with privilege escalation or credential scraping binaries."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1003.008",
   "technique_ja": "/etc/passwd と /etc/shadow",
   "technique_en": "/etc/passwd and /etc/shadow",
   "analytic_id": "AN1234",
   "detection_strategy_id": "DET0446",
   "analytic_name": "Analytic 1234",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "exe | user | PATH | TimeWindow",
   "detection_logic_en": "Adversaries attempt to read sensitive files such as /etc/passwd and /etc/shadow for credential dumping. This may involve access to the files directly via command-line utilities (e.g., cat, less), creation of backup copies, or parsing through post-exploitation frameworks. Multi-event correlation includes elevated process execution, file access/read on sensitive paths, and anomalous read behaviors tied to non-root or unusual users."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1040",
   "technique_ja": "ネットワークスニッフィング",
   "technique_en": "Network Sniffing",
   "analytic_id": "AN0875",
   "detection_strategy_id": "DET0314",
   "analytic_name": "Analytic 0875",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Service Creation (WinEventLog:System)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | サービス作成 (WinEventLog:System)",
   "tuning": "ToolNames | TimeWindow",
   "detection_logic_en": "Detects suspicious execution of network monitoring tools (e.g., Wireshark, tshark, Microsoft Message Analyzer), driver loading indicative of promiscuous mode, or non-admin user privilege escalation to access NICs for capture."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1040",
   "technique_ja": "ネットワークスニッフィング",
   "technique_en": "Network Sniffing",
   "analytic_id": "AN0876",
   "detection_strategy_id": "DET0314",
   "analytic_name": "Analytic 0876",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Command Execution (auditd:SYSCALL) | Network Traffic Content (networkconfig )",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | コマンド実行 (auditd:SYSCALL) | ネットワークトラフィック内容 (networkconfig )",
   "tuning": "InterfaceList | PromiscuousSessionThreshold",
   "detection_logic_en": "Correlates interface mode changes to promiscuous with execution of sniffing tools like tcpdump, tshark, or custom pcap libraries. Detects abnormal NIC configurations and unauthorized sniffing from non-root sessions."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1040",
   "technique_ja": "ネットワークスニッフィング",
   "technique_en": "Network Sniffing",
   "analytic_id": "AN0877",
   "detection_strategy_id": "DET0314",
   "analytic_name": "Analytic 0877",
   "platforms": "macOS",
   "log_sources": "Network Traffic Content (macos:unifiedlog) | Process Creation (macos:osquery) | Command Execution (fs:fsusage)",
   "log_sources_ja": "ネットワークトラフィック内容 (macos:unifiedlog) | プロセス生成 (macos:osquery) | コマンド実行 (fs:fsusage)",
   "tuning": "AllowedTools | UserContext",
   "detection_logic_en": "Detects enabling of interface sniffing via packet capture tools or AppleScript triggering `tcpdump`. Leverages Unified Logs and process lineage to identify suspicious use of `pfctl`, `tcpdump`, or `libpcap` libraries."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1040",
   "technique_ja": "ネットワークスニッフィング",
   "technique_en": "Network Sniffing",
   "analytic_id": "AN0878",
   "detection_strategy_id": "DET0314",
   "analytic_name": "Analytic 0878",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Modification (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス変更 (AWS:CloudTrail)",
   "tuning": "MirrorSourceList | TargetIAMRole",
   "detection_logic_en": "Detects creation of traffic mirroring sessions (e.g., AWS VPC Traffic Mirroring, Azure vTAP) that redirect traffic from critical assets to other virtual instances, often followed by file creation or session establishment."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1040",
   "technique_ja": "ネットワークスニッフィング",
   "technique_en": "Network Sniffing",
   "analytic_id": "AN0879",
   "detection_strategy_id": "DET0314",
   "analytic_name": "Analytic 0879",
   "platforms": "Network Devices",
   "log_sources": "User Account Authentication (networkdevice:syslog) | Command Execution (networkdevice:syslog) | Network Traffic Content (networkdevice:syslog)",
   "log_sources_ja": "ユーザーアカウント認証 (networkdevice:syslog) | コマンド実行 (networkdevice:syslog) | ネットワークトラフィック内容 (networkdevice:syslog)",
   "tuning": "AdminSessionDuration | CaptureCommandList",
   "detection_logic_en": "Detects execution of capture commands via CLI (`monitor capture`, `debug packet`, etc.) or unauthorized CLI access followed by logging configuration changes on Cisco/Juniper/Arista gear."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1056",
   "technique_ja": "入力キャプチャ",
   "technique_en": "Input Capture",
   "analytic_id": "AN0282",
   "detection_strategy_id": "DET0102",
   "analytic_name": "Analytic 0282",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | File Access (WinEventLog:Security)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Security)",
   "tuning": "TargetImage | TimeWindow",
   "detection_logic_en": "Monitors for abnormal process behavior and API calls like SetWindowsHookEx, GetAsyncKeyState, or device input polling commonly used for keystroke logging."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1056",
   "technique_ja": "入力キャプチャ",
   "technique_en": "Input Capture",
   "analytic_id": "AN0283",
   "detection_strategy_id": "DET0102",
   "analytic_name": "Analytic 0283",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | File Modification (auditd:SYSCALL) | OS API Execution (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL) | OS API実行 (auditd:SYSCALL)",
   "tuning": "ProcessName | DevicePath",
   "detection_logic_en": "Detects use of tools/scripts accessing input devices like /dev/input/* or evdev via suspicious processes lacking GUI context."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1056",
   "technique_ja": "入力キャプチャ",
   "technique_en": "Input Capture",
   "analytic_id": "AN0284",
   "detection_strategy_id": "DET0102",
   "analytic_name": "Analytic 0284",
   "platforms": "macOS",
   "log_sources": "Process Metadata (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "プロセスメタデータ (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "Service | ParentProcess",
   "detection_logic_en": "Monitors for TCC-bypassing or unauthorized access to input services like IOHIDSystem or Quartz Event Services used in keylogging or screen monitoring."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1056",
   "technique_ja": "入力キャプチャ",
   "technique_en": "Input Capture",
   "analytic_id": "AN0285",
   "detection_strategy_id": "DET0102",
   "analytic_name": "Analytic 0285",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Content (NSM:Flow) | Network Connection Creation (NSM:Firewall)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow) | ネットワーク接続確立 (NSM:Firewall)",
   "tuning": "UserAgent | URL_Path",
   "detection_logic_en": "Detects web-based credential phishing by analyzing traffic to suspicious URLs that mimic login portals and POST credential content."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1056.001",
   "technique_ja": "キーロギング",
   "technique_en": "Keylogging",
   "analytic_id": "AN0243",
   "detection_strategy_id": "DET0089",
   "analytic_name": "Analytic 0243",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | File Access (WinEventLog:Security) | Service Creation (WinEventLog:System) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Security) | サービス作成 (WinEventLog:System) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "TargetImage | AccessMask | TimeWindow",
   "detection_logic_en": "Monitors suspicious usage of Windows API calls like SetWindowsHookEx, GetKeyState, or polling functions within non-UI service processes, combined with Registry or driver modifications."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1056.001",
   "technique_ja": "キーロギング",
   "technique_en": "Keylogging",
   "analytic_id": "AN0244",
   "detection_strategy_id": "DET0089",
   "analytic_name": "Analytic 0244",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | OS API Execution (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | OS API実行 (auditd:SYSCALL)",
   "tuning": "ProcessName | DevicePath",
   "detection_logic_en": "Detects non-system processes accessing /dev/input/* or issuing ptrace/evdev syscalls used for reading keystroke buffers directly."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1056.001",
   "technique_ja": "キーロギング",
   "technique_en": "Keylogging",
   "analytic_id": "AN0245",
   "detection_strategy_id": "DET0089",
   "analytic_name": "Analytic 0245",
   "platforms": "macOS",
   "log_sources": "Process Metadata (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "プロセスメタデータ (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "Service | ExecutablePath",
   "detection_logic_en": "Detects unauthorized TCC access or use of Quartz Event Services (CGEventTapCreate) or IOHID for event tap installation within unexpected processes."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1056.001",
   "technique_ja": "キーロギング",
   "technique_en": "Keylogging",
   "analytic_id": "AN0246",
   "detection_strategy_id": "DET0089",
   "analytic_name": "Analytic 0246",
   "platforms": "Network Devices",
   "log_sources": "Firmware Modification (networkdevice:syslog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ファームウェア変更 (networkdevice:syslog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "FirmwareVersion | Protocol",
   "detection_logic_en": "Keylogging on legacy network devices via unauthorized system image modification or remote capture of console keystrokes (telnet, SSH) through altered firmware or man-in-the-middle key sniffing."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1056.002",
   "technique_ja": "GUI入力キャプチャ",
   "technique_en": "GUI Input Capture",
   "analytic_id": "AN1440",
   "detection_strategy_id": "DET0521",
   "analytic_name": "Analytic 1440",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "CommandLine | ParentProcessName | TimeWindow",
   "detection_logic_en": "Detects suspicious use of PowerShell, .NET, or script interpreters to spawn processes that mimic UAC prompts, often with credential capture dialogue boxes invoked from non-standard parent processes."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1056.002",
   "technique_ja": "GUI入力キャプチャ",
   "technique_en": "GUI Input Capture",
   "analytic_id": "AN1441",
   "detection_strategy_id": "DET0521",
   "analytic_name": "Analytic 1441",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Command Execution (linux:cli)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | コマンド実行 (linux:cli)",
   "tuning": "ExecutableName | PromptString",
   "detection_logic_en": "Detects GUI-based credential prompts invoked via zenity/kdialog/dialog or X11 APIs from non-user-facing scripts or background shell sessions, often with authentication-related text."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1056.002",
   "technique_ja": "GUI入力キャプチャ",
   "technique_en": "GUI Input Capture",
   "analytic_id": "AN1442",
   "detection_strategy_id": "DET0521",
   "analytic_name": "Analytic 1442",
   "platforms": "macOS",
   "log_sources": "Script Execution (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "スクリプト実行 (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "ScriptContent | ProcessPath",
   "detection_logic_en": "Detects AppleScript or Objective-C usage to generate fake authentication windows (e.g., using display dialog or NSAlert) from user-launched or persistence-related processes."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1056.003",
   "technique_ja": "Webポータルキャプチャ",
   "technique_en": "Web Portal Capture",
   "analytic_id": "AN1320",
   "detection_strategy_id": "DET0480",
   "analytic_name": "Analytic 1320",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "MonitoredFilePaths | TimeWindow",
   "detection_logic_en": "Detects unauthorized modifications to login-facing web server files (e.g., index.php, login.js) typically tied to VPN, SSO, or intranet portals. Correlates suspicious file changes with remote access artifacts or web shell behavior."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1056.003",
   "technique_ja": "Webポータルキャプチャ",
   "technique_en": "Web Portal Capture",
   "analytic_id": "AN1321",
   "detection_strategy_id": "DET0480",
   "analytic_name": "Analytic 1321",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Network Traffic Content (WinEventLog:iis)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (WinEventLog:iis)",
   "tuning": "FilePath | ProcessName",
   "detection_logic_en": "Detects tampering of IIS-based login pages (e.g., default.aspx, login.aspx) tied to VPN, OWA, or SharePoint via script injection or unexpected editor processes modifying web roots."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1056.003",
   "technique_ja": "Webポータルキャプチャ",
   "technique_en": "Web Portal Capture",
   "analytic_id": "AN1322",
   "detection_strategy_id": "DET0480",
   "analytic_name": "Analytic 1322",
   "platforms": "macOS",
   "log_sources": "File Modification (fs:fsusage) | Network Traffic Content (macos:unifiedlog)",
   "log_sources_ja": "ファイル変更 (fs:fsusage) | ネットワークトラフィック内容 (macos:unifiedlog)",
   "tuning": "WebRootPath | AnomalousProcess",
   "detection_logic_en": "Detects unauthorized changes to locally hosted login pages on macOS (common in developer VPN environments) and links file edits to cron jobs, background scripts, or SUID binaries."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1056.004",
   "technique_ja": "認証情報APIフック",
   "technique_en": "Credential API Hooking",
   "analytic_id": "AN0389",
   "detection_strategy_id": "DET0139",
   "analytic_name": "Analytic 0389",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Process Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | プロセス変更 (WinEventLog:Sysmon)",
   "tuning": "TargetProcess | AccessMask | TimeWindow",
   "detection_logic_en": "Detects credential harvesting via userland API hooking (e.g., SetWindowsHookEx, IAT, or inline patching) by correlating memory modifications with hook installation functions and suspicious module loads in credential-sensitive processes like lsass.exe, explorer.exe, or winlogon.exe."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1056.004",
   "technique_ja": "認証情報APIフック",
   "technique_en": "Credential API Hooking",
   "analytic_id": "AN0390",
   "detection_strategy_id": "DET0139",
   "analytic_name": "Analytic 0390",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Module Load (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | モジュール読み込み (auditd:SYSCALL)",
   "tuning": "InjectedLibraryName | TargetProcessName",
   "detection_logic_en": "Detects credential interception via malicious LD_PRELOAD-based shared libraries loaded into ssh, sudo, or scp processes. Correlates environment variable injection, unexpected library loads, and memory patching behavior."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1056.004",
   "technique_ja": "認証情報APIフック",
   "technique_en": "Credential API Hooking",
   "analytic_id": "AN0391",
   "detection_strategy_id": "DET0139",
   "analytic_name": "Analytic 0391",
   "platforms": "macOS",
   "log_sources": "Module Load (macos:unifiedlog) | File Access (fs:fsusage) | Process Modification (macos:osquery)",
   "log_sources_ja": "モジュール読み込み (macos:unifiedlog) | ファイルアクセス (fs:fsusage) | プロセス変更 (macos:osquery)",
   "tuning": "DYLDInjectedPath | ParentProcessName",
   "detection_logic_en": "Detects DYLD_INSERT_LIBRARIES abuse to hook credential-sensitive applications by correlating process spawns with unauthorized library injection and monitoring changes to the __TEXT segment (code) of credential handling binaries."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110",
   "technique_ja": "ブルートフォース",
   "technique_en": "Brute Force",
   "analytic_id": "AN1275",
   "detection_strategy_id": "DET0463",
   "analytic_name": "Analytic 1275",
   "platforms": "Windows",
   "log_sources": "User Account Authentication (WinEventLog:Security)",
   "log_sources_ja": "ユーザーアカウント認証 (WinEventLog:Security)",
   "tuning": "TimeWindow | UserContext | FailureThreshold",
   "detection_logic_en": "High volume of failed logon attempts followed by a successful one from a suspicious user, host, or timeframe"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110",
   "technique_ja": "ブルートフォース",
   "technique_en": "Brute Force",
   "analytic_id": "AN1276",
   "detection_strategy_id": "DET0463",
   "analytic_name": "Analytic 1276",
   "platforms": "Linux",
   "log_sources": "User Account Authentication (auditd:USER_LOGIN)",
   "log_sources_ja": "ユーザーアカウント認証 (auditd:USER_LOGIN)",
   "tuning": "TimeWindow | IPWhitelist | LoginSource",
   "detection_logic_en": "Multiple authentication failures for valid or invalid users followed by success from same IP/user"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110",
   "technique_ja": "ブルートフォース",
   "technique_en": "Brute Force",
   "analytic_id": "AN1277",
   "detection_strategy_id": "DET0463",
   "analytic_name": "Analytic 1277",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (azure:signinlogs)",
   "log_sources_ja": "ユーザーアカウント認証 (azure:signinlogs)",
   "tuning": "UsernameSprayThreshold | GeoAnomaly",
   "detection_logic_en": "Password spraying or brute force attempts across user pool within short time intervals"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110",
   "technique_ja": "ブルートフォース",
   "technique_en": "Brute Force",
   "analytic_id": "AN1278",
   "detection_strategy_id": "DET0463",
   "analytic_name": "Analytic 1278",
   "platforms": "macOS",
   "log_sources": "User Account Authentication (macos:unifiedlog)",
   "log_sources_ja": "ユーザーアカウント認証 (macos:unifiedlog)",
   "tuning": "TimeWindow | TargetUser",
   "detection_logic_en": "Multiple failed authentications in unified logs (e.g., loginwindow or sshd)"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110",
   "technique_ja": "ブルートフォース",
   "technique_en": "Brute Force",
   "analytic_id": "AN1279",
   "detection_strategy_id": "DET0463",
   "analytic_name": "Analytic 1279",
   "platforms": "SaaS",
   "log_sources": "User Account Authentication (m365:unified)",
   "log_sources_ja": "ユーザーアカウント認証 (m365:unified)",
   "tuning": "AppName | UserGroup",
   "detection_logic_en": "Excessive login attempts followed by success from SaaS apps like O365, Dropbox, etc."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.001",
   "technique_ja": "パスワード推測",
   "technique_en": "Password Guessing",
   "analytic_id": "AN1521",
   "detection_strategy_id": "DET0551",
   "analytic_name": "Analytic 1521",
   "platforms": "Windows",
   "log_sources": "User Account Authentication (WinEventLog:Security)",
   "log_sources_ja": "ユーザーアカウント認証 (WinEventLog:Security)",
   "tuning": "TimeWindow | UsernamePattern | SourceIPThreshold",
   "detection_logic_en": "Series of authentication failures (Event ID 4625) targeting the same or similar user accounts over time from one or more remote IPs"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.001",
   "technique_ja": "パスワード推測",
   "technique_en": "Password Guessing",
   "analytic_id": "AN1522",
   "detection_strategy_id": "DET0551",
   "analytic_name": "Analytic 1522",
   "platforms": "Linux",
   "log_sources": "User Account Authentication (linux:syslog)",
   "log_sources_ja": "ユーザーアカウント認証 (linux:syslog)",
   "tuning": "PortScope | UserScope | AttemptThreshold",
   "detection_logic_en": "Repeated failed SSH login attempts followed by a possible success from the same remote host"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.001",
   "technique_ja": "パスワード推測",
   "technique_en": "Password Guessing",
   "analytic_id": "AN1523",
   "detection_strategy_id": "DET0551",
   "analytic_name": "Analytic 1523",
   "platforms": "macOS",
   "log_sources": "User Account Authentication (macos:unifiedlog)",
   "log_sources_ja": "ユーザーアカウント認証 (macos:unifiedlog)",
   "tuning": "AuthMechanism | FailurePattern",
   "detection_logic_en": "Series of failed logins from loginwindow or sshd with repeated usernames or password prompts"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.001",
   "technique_ja": "パスワード推測",
   "technique_en": "Password Guessing",
   "analytic_id": "AN1524",
   "detection_strategy_id": "DET0551",
   "analytic_name": "Analytic 1524",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (azure:signinlogs)",
   "log_sources_ja": "ユーザーアカウント認証 (azure:signinlogs)",
   "tuning": "GeoRiskScore | MFAStatus",
   "detection_logic_en": "Multiple failed sign-in attempts from external sources across many users followed by success from the same IP"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.001",
   "technique_ja": "パスワード推測",
   "technique_en": "Password Guessing",
   "analytic_id": "AN1525",
   "detection_strategy_id": "DET0551",
   "analytic_name": "Analytic 1525",
   "platforms": "Network Devices",
   "log_sources": "User Account Authentication (networkdevice:syslog)",
   "log_sources_ja": "ユーザーアカウント認証 (networkdevice:syslog)",
   "tuning": "InterfaceType | FailedAttemptThreshold",
   "detection_logic_en": "Login attempt failures over SNMP, Telnet, or SSH interface, often reflected in logs or syslog events"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.001",
   "technique_ja": "パスワード推測",
   "technique_en": "Password Guessing",
   "analytic_id": "AN1526",
   "detection_strategy_id": "DET0551",
   "analytic_name": "Analytic 1526",
   "platforms": "SaaS",
   "log_sources": "User Account Authentication (GCPAuditLogs:login.googleapis.com)",
   "log_sources_ja": "ユーザーアカウント認証 (GCPAuditLogs:login.googleapis.com)",
   "tuning": "AppContext | EmailPattern",
   "detection_logic_en": "Password guessing attempts against web-based apps (e.g., Dropbox, Google Workspace) reflected in API or sign-in logs"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.002",
   "technique_ja": "パスワード解読",
   "technique_en": "Password Cracking",
   "analytic_id": "AN0292",
   "detection_strategy_id": "DET0105",
   "analytic_name": "Analytic 0292",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Access (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "HashToolName | FilePathIndicators | ExecutionContext",
   "detection_logic_en": "Use of hash-cracking tools (e.g., John the Ripper, Hashcat) after credential dumping, combined with high CPU usage or GPU invocation via unsigned binaries accessing password hash files"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.002",
   "technique_ja": "パスワード解読",
   "technique_en": "Password Cracking",
   "analytic_id": "AN0293",
   "detection_strategy_id": "DET0105",
   "analytic_name": "Analytic 0293",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Access (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルアクセス (linux:syslog)",
   "tuning": "ShadowAccessPattern | CrackingBinaryPath | CPUUsageThreshold",
   "detection_logic_en": "Execution of hash cracking binaries or scripts (e.g., john, hashcat) following access to shadow file or dumped hashes"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.002",
   "technique_ja": "パスワード解読",
   "technique_en": "Password Cracking",
   "analytic_id": "AN0294",
   "detection_strategy_id": "DET0105",
   "analytic_name": "Analytic 0294",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog)",
   "tuning": "UnsignedBinaryPath | UserPrivilegeLevel",
   "detection_logic_en": "Unsigned or scripting-based processes invoking password cracking binaries or accessing hashed credential artifacts post-login"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.002",
   "technique_ja": "パスワード解読",
   "technique_en": "Password Cracking",
   "analytic_id": "AN0295",
   "detection_strategy_id": "DET0105",
   "analytic_name": "Analytic 0295",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (azure:signinlogs)",
   "log_sources_ja": "ユーザーアカウント認証 (azure:signinlogs)",
   "tuning": "PostDumpTimeWindow | LoginLocationRisk",
   "detection_logic_en": "Sudden valid logins from accounts that previously had credentials dumped but had not authenticated successfully in the past; correlated with timeline of suspected hash cracking"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.002",
   "technique_ja": "パスワード解読",
   "technique_en": "Password Cracking",
   "analytic_id": "AN0296",
   "detection_strategy_id": "DET0105",
   "analytic_name": "Analytic 0296",
   "platforms": "Network Devices",
   "log_sources": "User Account Authentication (networkdevice:syslog)",
   "log_sources_ja": "ユーザーアカウント認証 (networkdevice:syslog)",
   "tuning": "LogonTimeCorrelation | SourceDeviceTag",
   "detection_logic_en": "Offline cracking inferred by subsequent successful CLI or web-based authentications into routers or switches from previously dumped accounts"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.003",
   "technique_ja": "パスワードスプレー",
   "technique_en": "Password Spraying",
   "analytic_id": "AN1336",
   "detection_strategy_id": "DET0487",
   "analytic_name": "Analytic 1336",
   "platforms": "Windows",
   "log_sources": "User Account Authentication (WinEventLog:Security)",
   "log_sources_ja": "ユーザーアカウント認証 (WinEventLog:Security)",
   "tuning": "PasswordReuseThreshold | TimeWindow | TargetGroupFilter",
   "detection_logic_en": "A high volume of authentication failures using a single password (or small set) across many different user accounts within a defined time window"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.003",
   "technique_ja": "パスワードスプレー",
   "technique_en": "Password Spraying",
   "analytic_id": "AN1337",
   "detection_strategy_id": "DET0487",
   "analytic_name": "Analytic 1337",
   "platforms": "Linux",
   "log_sources": "User Account Authentication (linux:syslog)",
   "log_sources_ja": "ユーザーアカウント認証 (linux:syslog)",
   "tuning": "PasswordReusePattern | IPAggregationWindow",
   "detection_logic_en": "Authentication failures across different accounts using a repeated or similar password via SSH or PAM stack within a short window"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.003",
   "technique_ja": "パスワードスプレー",
   "technique_en": "Password Spraying",
   "analytic_id": "AN1338",
   "detection_strategy_id": "DET0487",
   "analytic_name": "Analytic 1338",
   "platforms": "macOS",
   "log_sources": "User Account Authentication (macos:unifiedlog)",
   "log_sources_ja": "ユーザーアカウント認証 (macos:unifiedlog)",
   "tuning": "RetryCountThreshold | CommonPasswordList",
   "detection_logic_en": "Multiple failed login attempts across different users using common password patterns (e.g., 'Welcome2023')"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.003",
   "technique_ja": "パスワードスプレー",
   "technique_en": "Password Spraying",
   "analytic_id": "AN1339",
   "detection_strategy_id": "DET0487",
   "analytic_name": "Analytic 1339",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (azure:signinlogs)",
   "log_sources_ja": "ユーザーアカウント認証 (azure:signinlogs)",
   "tuning": "GeoIPAnomalyCheck | FailedUserRatio",
   "detection_logic_en": "Sign-in failures across enterprise SSO applications or SaaS platforms from same IP address using the same password against multiple user identities"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.003",
   "technique_ja": "パスワードスプレー",
   "technique_en": "Password Spraying",
   "analytic_id": "AN1340",
   "detection_strategy_id": "DET0487",
   "analytic_name": "Analytic 1340",
   "platforms": "Network Devices",
   "log_sources": "User Account Authentication (networkdevice:syslog)",
   "log_sources_ja": "ユーザーアカウント認証 (networkdevice:syslog)",
   "tuning": "AuthFailureBurst | InterfaceFilter",
   "detection_logic_en": "Authentication failure logs on routers/switches showing repeated use of default or common passwords across multiple accounts"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.003",
   "technique_ja": "パスワードスプレー",
   "technique_en": "Password Spraying",
   "analytic_id": "AN1341",
   "detection_strategy_id": "DET0487",
   "analytic_name": "Analytic 1341",
   "platforms": "Containers",
   "log_sources": "User Account Authentication (kubernetes:audit)",
   "log_sources_ja": "ユーザーアカウント認証 (kubernetes:audit)",
   "tuning": "OrchestrationScope | ServiceAccountFilter",
   "detection_logic_en": "Repeated failed authentication attempts to container APIs, control planes, or login shells across many user names using same password"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.003",
   "technique_ja": "パスワードスプレー",
   "technique_en": "Password Spraying",
   "analytic_id": "AN1342",
   "detection_strategy_id": "DET0487",
   "analytic_name": "Analytic 1342",
   "platforms": "Office Suite",
   "log_sources": "User Account Authentication (m365:exchange)",
   "log_sources_ja": "ユーザーアカウント認証 (m365:exchange)",
   "tuning": "MailboxAccessAttempts | EmailPatternAnalysis",
   "detection_logic_en": "Failed authentication attempts across user mailboxes using identical or common passwords (e.g., OWA brute attempts)"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.003",
   "technique_ja": "パスワードスプレー",
   "technique_en": "Password Spraying",
   "analytic_id": "AN1343",
   "detection_strategy_id": "DET0487",
   "analytic_name": "Analytic 1343",
   "platforms": "SaaS",
   "log_sources": "User Account Authentication (saas:auth)",
   "log_sources_ja": "ユーザーアカウント認証 (saas:auth)",
   "tuning": "CloudAppScope | UserPopulationSensitivity",
   "detection_logic_en": "SaaS applications receiving authentication failures for dozens of accounts using same password or login signature"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.004",
   "technique_ja": "クレデンシャルスタッフィング",
   "technique_en": "Credential Stuffing",
   "analytic_id": "AN1262",
   "detection_strategy_id": "DET0460",
   "analytic_name": "Analytic 1262",
   "platforms": "Windows",
   "log_sources": "User Account Authentication (WinEventLog:Security)",
   "log_sources_ja": "ユーザーアカウント認証 (WinEventLog:Security)",
   "tuning": "UsernameUniquenessThreshold | TimeWindow | SourceIPScope",
   "detection_logic_en": "Multiple failed authentication attempts using distinct username/password pairs from a single IP address or session within a short time window, targeting common services like RDP or SMB"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.004",
   "technique_ja": "クレデンシャルスタッフィング",
   "technique_en": "Credential Stuffing",
   "analytic_id": "AN1263",
   "detection_strategy_id": "DET0460",
   "analytic_name": "Analytic 1263",
   "platforms": "Linux",
   "log_sources": "User Account Authentication (linux:syslog)",
   "log_sources_ja": "ユーザーアカウント認証 (linux:syslog)",
   "tuning": "LoginFailureRatio | AuthServiceFilter",
   "detection_logic_en": "Rapid login failures across different users from a single IP address, targeting SSH or PAM login with distinct username-password pairs"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.004",
   "technique_ja": "クレデンシャルスタッフィング",
   "technique_en": "Credential Stuffing",
   "analytic_id": "AN1264",
   "detection_strategy_id": "DET0460",
   "analytic_name": "Analytic 1264",
   "platforms": "macOS",
   "log_sources": "User Account Authentication (macos:unifiedlog)",
   "log_sources_ja": "ユーザーアカウント認証 (macos:unifiedlog)",
   "tuning": "DistinctUsernameCount | RemoteAccessFilter",
   "detection_logic_en": "Burst of failed authentications with rotating usernames against loginwindow or remote management service using reused breached credentials"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.004",
   "technique_ja": "クレデンシャルスタッフィング",
   "technique_en": "Credential Stuffing",
   "analytic_id": "AN1265",
   "detection_strategy_id": "DET0460",
   "analytic_name": "Analytic 1265",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (azure:signinlogs)",
   "log_sources_ja": "ユーザーアカウント認証 (azure:signinlogs)",
   "tuning": "BreachedCredentialSourceMatch | SSOServiceScope",
   "detection_logic_en": "Same source IP performing multiple authentication attempts using known breached username/password combinations across different identities in Azure AD, Okta, or Duo"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.004",
   "technique_ja": "クレデンシャルスタッフィング",
   "technique_en": "Credential Stuffing",
   "analytic_id": "AN1266",
   "detection_strategy_id": "DET0460",
   "analytic_name": "Analytic 1266",
   "platforms": "SaaS",
   "log_sources": "User Account Authentication (saas-app:auth)",
   "log_sources_ja": "ユーザーアカウント認証 (saas-app:auth)",
   "tuning": "UserAccountOverlap | FailedAttemptsPerIP",
   "detection_logic_en": "Multiple sign-in failures against cloud-based applications using username/password combinations leaked from unrelated domains"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.004",
   "technique_ja": "クレデンシャルスタッフィング",
   "technique_en": "Credential Stuffing",
   "analytic_id": "AN1267",
   "detection_strategy_id": "DET0460",
   "analytic_name": "Analytic 1267",
   "platforms": "Network Devices",
   "log_sources": "User Account Authentication (networkdevice:syslog)",
   "log_sources_ja": "ユーザーアカウント認証 (networkdevice:syslog)",
   "tuning": "AuthProtocolFilter | FailedAuthBurst",
   "detection_logic_en": "Router/firewall/syslog logs showing authentication failures with unique usernames and reused credentials from same source IP"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.004",
   "technique_ja": "クレデンシャルスタッフィング",
   "technique_en": "Credential Stuffing",
   "analytic_id": "AN1268",
   "detection_strategy_id": "DET0460",
   "analytic_name": "Analytic 1268",
   "platforms": "Containers",
   "log_sources": "User Account Authentication (kubernetes:apiserver)",
   "log_sources_ja": "ユーザーアカウント認証 (kubernetes:apiserver)",
   "tuning": "PodAccessScope | CredentialSetSize",
   "detection_logic_en": "Credential stuffing attempts against Kubernetes API or containerized login shells using stolen or leaked user credentials"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.004",
   "technique_ja": "クレデンシャルスタッフィング",
   "technique_en": "Credential Stuffing",
   "analytic_id": "AN1269",
   "detection_strategy_id": "DET0460",
   "analytic_name": "Analytic 1269",
   "platforms": "Office Suite",
   "log_sources": "User Account Authentication (m365:exchange)",
   "log_sources_ja": "ユーザーアカウント認証 (m365:exchange)",
   "tuning": "PasswordSourceMatch | MailboxLoginThreshold",
   "detection_logic_en": "Use of leaked credential pairs against Outlook Web Access (OWA), Microsoft 365, or Exchange from a single client IP with multiple failures"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1110.004",
   "technique_ja": "クレデンシャルスタッフィング",
   "technique_en": "Credential Stuffing",
   "analytic_id": "AN1270",
   "detection_strategy_id": "DET0460",
   "analytic_name": "Analytic 1270",
   "platforms": "IaaS",
   "log_sources": "User Account Authentication (AWS:CloudTrail)",
   "log_sources_ja": "ユーザーアカウント認証 (AWS:CloudTrail)",
   "tuning": "InstanceIDScope | IPBehaviorHistory",
   "detection_logic_en": "Burst of failed login attempts across VM instances using leaked credential pairs from single IP in public cloud environments"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1111",
   "technique_ja": "多要素認証の傍受",
   "technique_en": "Multi-Factor Authentication Interception",
   "analytic_id": "AN0687",
   "detection_strategy_id": "DET0246",
   "analytic_name": "Analytic 0687",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Logon Session Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | ログオンセッション作成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "AccessMask | ProcessNameExclusions | TimeWindow",
   "detection_logic_en": "Behavior chain involving unexpected API calls to capture keyboard input, driver loads for keyloggers, or remote use of smart card authentication via logon sessions not initiated by local user interaction"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1111",
   "technique_ja": "多要素認証の傍受",
   "technique_en": "Multi-Factor Authentication Interception",
   "analytic_id": "AN0688",
   "detection_strategy_id": "DET0246",
   "analytic_name": "Analytic 0688",
   "platforms": "Linux",
   "log_sources": "Process Access (linux:syslog) | Driver Load (linux:syslog)",
   "log_sources_ja": "プロセスアクセス (linux:syslog) | ドライバ読み込み (linux:syslog)",
   "tuning": "PathTarget | UserContext | ModuleWhitelist",
   "detection_logic_en": "Detection of unauthorized keylogger behavior through access to `/dev/input`, loading kernel modules (e.g., via insmod), or polling user input devices from non-user shells"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1111",
   "technique_ja": "多要素認証の傍受",
   "technique_en": "Multi-Factor Authentication Interception",
   "analytic_id": "AN0689",
   "detection_strategy_id": "DET0246",
   "analytic_name": "Analytic 0689",
   "platforms": "macOS",
   "log_sources": "OS API Execution (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "OS API実行 (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "AccessibilityAPIUsage | TCCBypassAttempt | SignedBinaryCheck",
   "detection_logic_en": "Processes accessing TCC-protected input APIs or polling HID services without user interaction, or dynamically loaded keylogging frameworks using accessibility privileges"
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1187",
   "technique_ja": "強制認証",
   "technique_en": "Forced Authentication",
   "analytic_id": "AN0065",
   "detection_strategy_id": "DET0022",
   "analytic_name": "Analytic 0065",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Modification (WinEventLog:Security) | Network Traffic Content (NSM:Flow) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Security) | ネットワークトラフィック内容 (NSM:Flow) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "UserLocations | LureExtensions | UntrustedCIDR/DNS | TimeWindow | WorkstationZones | OfficeTemplatePaths",
   "detection_logic_en": "Adversary stages a lure that references a remote resource (e.g., LNK/SCF/Office template). When the user opens/renders the file or a shell enumerates icons, the host automatically attempts SMB or WebDAV authentication to the attacker host. The chain is: (1) lure file is created or modified in a user-exposed location → (2) user or system accesses the lure → (3) host makes outbound NTLM (SMB 139/445 or WebDAV over 80/443) to an untrusted destination → (4) repeated attempts from multiple users/hosts or from privileged workstations."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1212",
   "technique_ja": "認証情報アクセスのための脆弱性悪用",
   "technique_en": "Exploitation for Credential Access",
   "analytic_id": "AN0493",
   "detection_strategy_id": "DET0174",
   "analytic_name": "Analytic 0493",
   "platforms": "Windows",
   "log_sources": "User Account Authentication (WinEventLog:Security) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "ユーザーアカウント認証 (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "MonitoredAccounts | ReplayDetectionWindow",
   "detection_logic_en": "Detects adversary exploitation of authentication mechanisms or credential validation processes. Defender perspective includes forged Kerberos tickets (e.g., MS14-068), abnormal LSASS memory access, replayed authentication attempts, and unexpected crashes of authentication services. Multi-event correlation ties exploitation attempts to abnormal process creation, service instability, and suspicious authentication events."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1212",
   "technique_ja": "認証情報アクセスのための脆弱性悪用",
   "technique_en": "Exploitation for Credential Access",
   "analytic_id": "AN0494",
   "detection_strategy_id": "DET0174",
   "analytic_name": "Analytic 0494",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | User Account Authentication (NSM:Connections)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ユーザーアカウント認証 (NSM:Connections)",
   "tuning": "AuthServiceList | FailureThreshold",
   "detection_logic_en": "Detects exploitation of authentication daemons or PAM modules. Defender perspective includes failed or anomalous PAM authentications, abnormal segfaults in authentication services, and exploitation attempts followed by successful unauthorized logins. Correlation identifies memory corruption, replay attempts, and privilege escalation tied to credential services."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1212",
   "technique_ja": "認証情報アクセスのための脆弱性悪用",
   "technique_en": "Exploitation for Credential Access",
   "analytic_id": "AN0495",
   "detection_strategy_id": "DET0174",
   "analytic_name": "Analytic 0495",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "WatchedAPIs | CrashCorrelationWindow",
   "detection_logic_en": "Detects exploitation attempts against macOS authentication frameworks such as OpenDirectory or Keychain. Defender perspective includes abnormal crashes in opendirectoryd, unauthorized Keychain API usage, and unusual sudo or login events. Correlation links unexpected process behavior with credential access anomalies."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1212",
   "technique_ja": "認証情報アクセスのための脆弱性悪用",
   "technique_en": "Exploitation for Credential Access",
   "analytic_id": "AN0496",
   "detection_strategy_id": "DET0174",
   "analytic_name": "Analytic 0496",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (azure:signinlogs) | Application Log Content (m365:unified)",
   "log_sources_ja": "ユーザーアカウント認証 (azure:signinlogs) | アプリケーションログ内容 (m365:unified)",
   "tuning": "TokenAnomalyThreshold | MonitoredAppIntegrations",
   "detection_logic_en": "Detects exploitation of vulnerabilities in cloud identity providers (IdPs) such as Azure AD or Okta for credential access. Defender perspective includes anomalous token creation or renewal, authentication bypass events, and API abuse to mint unauthorized tokens. Correlation highlights exploitation attempts tied to absent or inconsistent audit logs."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1528",
   "technique_ja": "アプリケーションアクセストークンの窃取",
   "technique_en": "Steal Application Access Token",
   "analytic_id": "AN1423",
   "detection_strategy_id": "DET0515",
   "analytic_name": "Analytic 1423",
   "platforms": "Containers",
   "log_sources": "File Access (kubernetes:audit)",
   "log_sources_ja": "ファイルアクセス (kubernetes:audit)",
   "tuning": "TimeWindow | UserContext",
   "detection_logic_en": "Access and retrieval of container service account tokens followed by unauthorized API requests using those tokens to interact with the Kubernetes API server or internal services."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1528",
   "technique_ja": "アプリケーションアクセストークンの窃取",
   "technique_en": "Steal Application Access Token",
   "analytic_id": "AN1424",
   "detection_strategy_id": "DET0515",
   "analytic_name": "Analytic 1424",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Enumeration (AWS:CloudTrail) | Cloud Service Modification (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス列挙 (AWS:CloudTrail) | クラウドサービス変更 (AWS:CloudTrail)",
   "tuning": "UserAgent | TimeWindow",
   "detection_logic_en": "Token retrieval from instance metadata endpoints such as AWS IMDS or Azure IMDS, followed by API usage using the obtained token from non-standard applications."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1528",
   "technique_ja": "アプリケーションアクセストークンの窃取",
   "technique_en": "Steal Application Access Token",
   "analytic_id": "AN1425",
   "detection_strategy_id": "DET0515",
   "analytic_name": "Analytic 1425",
   "platforms": "Identity Provider",
   "log_sources": "Application Log Content (azure:audit)",
   "log_sources_ja": "アプリケーションログ内容 (azure:audit)",
   "tuning": "ConsentScope | AppUserRatio",
   "detection_logic_en": "Unusual OAuth app registration followed by user-granted OAuth tokens and subsequent high-privilege resource access via those tokens."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1528",
   "technique_ja": "アプリケーションアクセストークンの窃取",
   "technique_en": "Steal Application Access Token",
   "analytic_id": "AN1426",
   "detection_strategy_id": "DET0515",
   "analytic_name": "Analytic 1426",
   "platforms": "Office Suite",
   "log_sources": "Cloud Storage Access (m365:unified)",
   "log_sources_ja": "クラウドストレージアクセス (m365:unified)",
   "tuning": "ClientAppIDAllowList | AccessVolumeThreshold",
   "detection_logic_en": "Use of OAuth tokens by third-party apps to access user mail, calendar, or SharePoint resources where the token was granted recently or via spearphishing."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1528",
   "technique_ja": "アプリケーションアクセストークンの窃取",
   "technique_en": "Steal Application Access Token",
   "analytic_id": "AN1427",
   "detection_strategy_id": "DET0515",
   "analytic_name": "Analytic 1427",
   "platforms": "SaaS",
   "log_sources": "User Account Authentication (saas:googleworkspace) | Application Log Content (saas:slack)",
   "log_sources_ja": "ユーザーアカウント認証 (saas:googleworkspace) | アプリケーションログ内容 (saas:slack)",
   "tuning": "GeoVelocity | OAuthScopeSensitivity",
   "detection_logic_en": "Programmatic access to user content via stolen access tokens in platforms like Slack, GitHub, Google Workspace — especially from new IPs, apps, or excessive resource access."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1539",
   "technique_ja": "Webセッションクッキーの窃取",
   "technique_en": "Steal Web Session Cookie",
   "analytic_id": "AN1402",
   "detection_strategy_id": "DET0509",
   "analytic_name": "Analytic 1402",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | File Modification (WinEventLog:Sysmon) | Process Creation (WinEventLog:Security)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Security)",
   "tuning": "TargetProcessList | AccessToolList | TargetCookiePaths",
   "detection_logic_en": "Detects suspicious access to browser session cookie storage (e.g., Chrome’s `Cookies` SQLite DB) or memory reads of browser processes. Anomalous injection or memory dump utilities targeting browser processes such as `chrome.exe`, `firefox.exe`, or `msedge.exe`."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1539",
   "technique_ja": "Webセッションクッキーの窃取",
   "technique_en": "Steal Web Session Cookie",
   "analytic_id": "AN1403",
   "detection_strategy_id": "DET0509",
   "analytic_name": "Analytic 1403",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Process Access (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | プロセスアクセス (auditd:SYSCALL)",
   "tuning": "CookieFilePatterns | TimeWindow | BrowserProcPatterns",
   "detection_logic_en": "Detects access to known browser cookie files (e.g., `~/.mozilla/firefox/*.default/cookies.sqlite`, `~/.config/google-chrome/`) and suspicious reads of browser memory via `/proc/[pid]/mem` or ptrace."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1539",
   "technique_ja": "Webセッションクッキーの窃取",
   "technique_en": "Steal Web Session Cookie",
   "analytic_id": "AN1404",
   "detection_strategy_id": "DET0509",
   "analytic_name": "Analytic 1404",
   "platforms": "macOS",
   "log_sources": "Process Access (macos:unifiedlog) | File Access (fs:fsusage)",
   "log_sources_ja": "プロセスアクセス (macos:unifiedlog) | ファイルアクセス (fs:fsusage)",
   "tuning": "TargetBrowserList | BrowserCookiePathList",
   "detection_logic_en": "Detects unauthorized access to browser cookie paths (e.g., `~/Library/Application Support/Google/Chrome/Default/Cookies`) or `task_for_pid`/`vm_read` calls to Safari/Chrome memory space."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1539",
   "technique_ja": "Webセッションクッキーの窃取",
   "technique_en": "Steal Web Session Cookie",
   "analytic_id": "AN1405",
   "detection_strategy_id": "DET0509",
   "analytic_name": "Analytic 1405",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified) | File Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | ファイル変更 (WinEventLog:Sysmon)",
   "tuning": "MacroTargetPath | HTTPDestinationIPList",
   "detection_logic_en": "Detects automation macros or VBA scripts in documents that access browser file paths, read cookie data, or attempt to exfiltrate browser session tokens over HTTP."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1539",
   "technique_ja": "Webセッションクッキーの窃取",
   "technique_en": "Steal Web Session Cookie",
   "analytic_id": "AN1406",
   "detection_strategy_id": "DET0509",
   "analytic_name": "Analytic 1406",
   "platforms": "SaaS",
   "log_sources": "User Account Authentication (saas:googleworkspace) | Logon Session Creation (saas:okta)",
   "log_sources_ja": "ユーザーアカウント認証 (saas:googleworkspace) | ログオンセッション作成 (saas:okta)",
   "tuning": "TokenReuseTimeWindow | UserAgentAnomalyScore | GeoLocationAnomalyScore",
   "detection_logic_en": "Detects use of session cookies or authentication tokens from unusual user agents or locations. Identifies token reuse without reauthentication or attempts to bypass MFA using previously stolen cookies."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552",
   "technique_ja": "保護されていない認証情報",
   "technique_en": "Unsecured Credentials",
   "analytic_id": "AN1153",
   "detection_strategy_id": "DET0412",
   "analytic_name": "Analytic 1153",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | SuspiciousProcessList",
   "detection_logic_en": "Unusual access to bash history, registry credentials paths, or private key files by unauthorized or scripting tools, with correlated file and process activity."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552",
   "technique_ja": "保護されていない認証情報",
   "technique_en": "Unsecured Credentials",
   "analytic_id": "AN1154",
   "detection_strategy_id": "DET0412",
   "analytic_name": "Analytic 1154",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Command Execution (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | コマンド実行 (auditd:SYSCALL)",
   "tuning": "SensitivePaths | UserContext",
   "detection_logic_en": "Reading of sensitive files like .bash_history, /etc/shadow, or private key directories by unauthorized users or unusual processes."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552",
   "technique_ja": "保護されていない認証情報",
   "technique_en": "Unsecured Credentials",
   "analytic_id": "AN1155",
   "detection_strategy_id": "DET0412",
   "analytic_name": "Analytic 1155",
   "platforms": "macOS",
   "log_sources": "File Access (macos:unifiedlog) | Command Execution (macos:unifiedlog)",
   "log_sources_ja": "ファイルアクセス (macos:unifiedlog) | コマンド実行 (macos:unifiedlog)",
   "tuning": "ProcessName | TargetPath",
   "detection_logic_en": "Unusual access to ~/Library/Keychains, ~/.bash_history, or Terminal command history by unauthorized processes or users."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552",
   "technique_ja": "保護されていない認証情報",
   "technique_en": "Unsecured Credentials",
   "analytic_id": "AN1156",
   "detection_strategy_id": "DET0412",
   "analytic_name": "Analytic 1156",
   "platforms": "SaaS",
   "log_sources": "User Account Authentication (saas:googleworkspace) | Application Log Content (saas:zoom)",
   "log_sources_ja": "ユーザーアカウント認証 (saas:googleworkspace) | アプリケーションログ内容 (saas:zoom)",
   "tuning": "TokenAnomalyThreshold | AccessGeoLocation",
   "detection_logic_en": "Unusual web-based access or API scraping of password managers, single sign-on sessions, or credential sync services via browser automation or anomalous API tokens."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552",
   "technique_ja": "保護されていない認証情報",
   "technique_en": "Unsecured Credentials",
   "analytic_id": "AN1157",
   "detection_strategy_id": "DET0412",
   "analytic_name": "Analytic 1157",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (azure:signinlogs) | Cloud Service Metadata (AWS:CloudTrail)",
   "log_sources_ja": "ユーザーアカウント認証 (azure:signinlogs) | クラウドサービスメタデータ (AWS:CloudTrail)",
   "tuning": "SSOSettingScope | SecretType",
   "detection_logic_en": "Unauthorized API or console calls to retrieve or reset password credentials, download key material, or modify SSO settings."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552",
   "technique_ja": "保護されていない認証情報",
   "technique_en": "Unsecured Credentials",
   "analytic_id": "AN1158",
   "detection_strategy_id": "DET0412",
   "analytic_name": "Analytic 1158",
   "platforms": "Containers",
   "log_sources": "File Access (auditd:SYSCALL) | Process Creation (containerd:Events)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | プロセス生成 (containerd:Events)",
   "tuning": "EntrypointAllowlist | VolumeMountPath",
   "detection_logic_en": "Access to container image layers or mounted secrets (e.g., Docker secrets) by processes not tied to entrypoint or orchestration context."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552",
   "technique_ja": "保護されていない認証情報",
   "technique_en": "Unsecured Credentials",
   "analytic_id": "AN1159",
   "detection_strategy_id": "DET0412",
   "analytic_name": "Analytic 1159",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (linux:syslog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (linux:syslog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ManagementInterfaceIPs | CommandPattern",
   "detection_logic_en": "Use of configuration backup utilities or CLI access to dump plaintext passwords, local user hashes, or SNMP strings."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552.001",
   "technique_ja": "ファイル内の認証情報",
   "technique_en": "Credentials In Files",
   "analytic_id": "AN0856",
   "detection_strategy_id": "DET0307",
   "analytic_name": "Analytic 0856",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Logon Session Creation (WinEventLog:Security)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ログオンセッション作成 (WinEventLog:Security)",
   "tuning": "FileNamePattern | ProcessAccessScope | TimeWindow",
   "detection_logic_en": "Correlated file access to insecure credential files (e.g., *.env, *.xml, *.ps1) followed by suspicious process execution or authentication using retrieved credentials. Detected through Sysmon logs and Windows Security Event logs."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552.001",
   "technique_ja": "ファイル内の認証情報",
   "technique_en": "Credentials In Files",
   "analytic_id": "AN0857",
   "detection_strategy_id": "DET0307",
   "analytic_name": "Analytic 0857",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Command Execution (auditd:EXECVE) | Logon Session Creation (linux:syslog)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | コマンド実行 (auditd:EXECVE) | ログオンセッション作成 (linux:syslog)",
   "tuning": "RegexPatterns | UserContextScope | TimeWindow",
   "detection_logic_en": "File reads or process executions involving insecurely stored credential files (e.g., config files with password fields) by non-root or anomalous users followed by ssh authentication attempts."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552.001",
   "technique_ja": "ファイル内の認証情報",
   "technique_en": "Credentials In Files",
   "analytic_id": "AN0858",
   "detection_strategy_id": "DET0307",
   "analytic_name": "Analytic 0858",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Access (macos:unifiedlog) | Logon Session Creation (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイルアクセス (macos:unifiedlog) | ログオンセッション作成 (macos:unifiedlog)",
   "tuning": "KeychainToolAccess | FileTypeList",
   "detection_logic_en": "Terminal-based grep or open of plist/config files containing credentials, correlated with Keychain or system login attempts."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552.001",
   "technique_ja": "ファイル内の認証情報",
   "technique_en": "Credentials In Files",
   "analytic_id": "AN0859",
   "detection_strategy_id": "DET0307",
   "analytic_name": "Analytic 0859",
   "platforms": "Containers",
   "log_sources": "File Access (ebpf:syscalls) | Command Execution (kubernetes:audit) | Network Connection Creation (cni:netflow)",
   "log_sources_ja": "ファイルアクセス (ebpf:syscalls) | コマンド実行 (kubernetes:audit) | ネットワーク接続確立 (cni:netflow)",
   "tuning": "SecretMountPaths | ProcessBaselineDeviation",
   "detection_logic_en": "Container processes accessing mounted secrets or configuration paths (e.g., /run/secrets, /mnt/config) followed by network access or credential use."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552.001",
   "technique_ja": "ファイル内の認証情報",
   "technique_en": "Credentials In Files",
   "analytic_id": "AN0860",
   "detection_strategy_id": "DET0307",
   "analytic_name": "Analytic 0860",
   "platforms": "IaaS",
   "log_sources": "File Access (CloudTrail:GetObject) | Command Execution (AWS:CloudTrail) | Logon Session Creation (AWS:CloudTrail)",
   "log_sources_ja": "ファイルアクセス (CloudTrail:GetObject) | コマンド実行 (AWS:CloudTrail) | ログオンセッション作成 (AWS:CloudTrail)",
   "tuning": "CredentialFilePattern | RoleAssumptionScope | TimeWindow",
   "detection_logic_en": "Access to local credential/config files (e.g., ~/.aws/credentials) followed by metadata API calls or cloud role assumptions."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552.002",
   "technique_ja": "レジストリ内の認証情報",
   "technique_en": "Credentials in Registry",
   "analytic_id": "AN0694",
   "detection_strategy_id": "DET0250",
   "analytic_name": "Analytic 0694",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | Windows Registry Key Access (EDR:hunting)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | Windowsレジストリキーアクセス (EDR:hunting)",
   "tuning": "KeywordMatch | ParentProcessFilter | TimeWindow | RegistryHiveScope",
   "detection_logic_en": "Defenders observe command-line executions or API-based registry reads targeting sensitive paths like HKLM or HKCU with keyword filters such as 'password', 'cred', or 'logon'. Typically performed by Reg.exe, PowerShell, custom binaries, or offensive tools such as Cobalt Strike. Correlation with process ancestry and command-line arguments indicates suspicious credential discovery activity."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552.003",
   "technique_ja": "シェル履歴",
   "technique_en": "Shell History",
   "analytic_id": "AN1085",
   "detection_strategy_id": "DET0385",
   "analytic_name": "Analytic 1085",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Process Creation (auditd:EXECVE) | File Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | プロセス生成 (auditd:EXECVE) | ファイル作成 (auditd:SYSCALL)",
   "tuning": "UserContext | TimeWindow | ProcessNamePatterns",
   "detection_logic_en": "A process outside of interactive shell context reads ~/.bash_history directly (e.g., using cat, less, grep), often shortly after privilege escalation or user switch (su/sudo). This may be followed by credential scanning in memory or file writes to new locations."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552.003",
   "technique_ja": "シェル履歴",
   "technique_en": "Shell History",
   "analytic_id": "AN1086",
   "detection_strategy_id": "DET0385",
   "analytic_name": "Analytic 1086",
   "platforms": "macOS",
   "log_sources": "File Access (macos:endpointsecurity) | Process Metadata (macos:unifiedlog)",
   "log_sources_ja": "ファイルアクセス (macos:endpointsecurity) | プロセスメタデータ (macos:unifiedlog)",
   "tuning": "ParentProcessCheck | AccessFrequency",
   "detection_logic_en": "A process or terminal command outside of standard shell utilities reads the user's .bash_history file. On macOS, unified logs or telemetry tools like EndpointSecurity (ESF) may observe file read APIs or terminal process lineage that shows non-user-initiated access."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552.004",
   "technique_ja": "秘密鍵",
   "technique_en": "Private Keys",
   "analytic_id": "AN1516",
   "detection_strategy_id": "DET0549",
   "analytic_name": "Analytic 1516",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Network Share Access (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ネットワーク共有アクセス (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "FilePathRegex | ParentProcessName",
   "detection_logic_en": "A process (non-system or user-initiated) accesses private key files in user profile paths or system certificate stores followed by potential network connections or compression activity."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552.004",
   "technique_ja": "秘密鍵",
   "technique_en": "Private Keys",
   "analytic_id": "AN1517",
   "detection_strategy_id": "DET0549",
   "analytic_name": "Analytic 1517",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Process Creation (auditd:EXECVE)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | プロセス生成 (auditd:EXECVE)",
   "tuning": "FilePathRegex | CommandLineMatch",
   "detection_logic_en": "User or script-based access to ~/.ssh or other directories containing private keys followed by unusual shell activity or network connections."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552.004",
   "technique_ja": "秘密鍵",
   "technique_en": "Private Keys",
   "analytic_id": "AN1518",
   "detection_strategy_id": "DET0549",
   "analytic_name": "Analytic 1518",
   "platforms": "macOS",
   "log_sources": "File Access (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ファイルアクセス (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "ProcessName | FileAccessPath",
   "detection_logic_en": "Access to user private key directories (e.g., /Users/*/.ssh) via Terminal, scripting engines, or non-default processes."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552.004",
   "technique_ja": "秘密鍵",
   "technique_en": "Private Keys",
   "analytic_id": "AN1519",
   "detection_strategy_id": "DET0549",
   "analytic_name": "Analytic 1519",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:syslog)",
   "log_sources_ja": "コマンド実行 (networkdevice:syslog)",
   "tuning": "CLICommandMatch | AAAUserContext",
   "detection_logic_en": "CLI-based export of private key material (e.g., 'crypto pki export') with anomalous user session or AAA role escalation."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552.005",
   "technique_ja": "クラウドインスタンスメタデータAPI",
   "technique_en": "Cloud Instance Metadata API",
   "analytic_id": "AN0001",
   "detection_strategy_id": "DET0001",
   "analytic_name": "Analytic 0001",
   "platforms": "IaaS",
   "log_sources": "Network Connection Creation (AWS:VPCFlowLogs) | Cloud Service Metadata (AWS:CloudTrail) | Network Traffic Content (ebpf:syscalls)",
   "log_sources_ja": "ネットワーク接続確立 (AWS:VPCFlowLogs) | クラウドサービスメタデータ (AWS:CloudTrail) | ネットワークトラフィック内容 (ebpf:syscalls)",
   "tuning": "TimeWindow | UserContext | RequestHeaderMatch",
   "detection_logic_en": "Detects access attempts to cloud instance metadata endpoints (e.g., 169.254.169.254) from virtual machines or containerized workloads. This includes both direct access and SSRF exploitation patterns."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552.006",
   "technique_ja": "グループポリシー設定",
   "technique_en": "Group Policy Preferences",
   "analytic_id": "AN1075",
   "detection_strategy_id": "DET0381",
   "analytic_name": "Analytic 1075",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Network Share Access (WinEventLog:Security) | Script Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ネットワーク共有アクセス (WinEventLog:Security) | スクリプト実行 (WinEventLog:PowerShell)",
   "tuning": "UserContext | TimeWindow | KnownToolsSignature | HostType",
   "detection_logic_en": "Correlates file enumeration of XML files in the SYSVOL share with suspicious process execution that decodes or reads encrypted credentials embedded in Group Policy Preference files (e.g., Get-GPPPassword.ps1, gpprefdecrypt.py, Metasploit). Detects abnormal access to \\DOMAIN\\SYSVOL combined with XML file parsing or decryption logic."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552.007",
   "technique_ja": "コンテナAPI",
   "technique_en": "Container API",
   "analytic_id": "AN0571",
   "detection_strategy_id": "DET0198",
   "analytic_name": "Analytic 0571",
   "platforms": "Containers",
   "log_sources": "Command Execution (docker:api) | User Account Authentication (kubernetes:apiserver) | Process Creation (kubernetes:apiserver) | Application Log Content (kubernetes:orchestrator)",
   "log_sources_ja": "コマンド実行 (docker:api) | ユーザーアカウント認証 (kubernetes:apiserver) | プロセス生成 (kubernetes:apiserver) | アプリケーションログ内容 (kubernetes:orchestrator)",
   "tuning": "UserContext | NamespaceScope | TimeWindow | SourceIP",
   "detection_logic_en": "Detection correlates anomalous Docker or Kubernetes API requests with access to logs, secrets, or service accounts. Observes unauthorized use of `docker logs`, `kubectl get secrets`, or direct API calls to Kubernetes API server endpoints. Identifies behavioral patterns where adversaries escalate from basic pod/container interaction to privileged API calls exposing sensitive credential material."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552.008",
   "technique_ja": "チャットメッセージ",
   "technique_en": "Chat Messages",
   "analytic_id": "AN0309",
   "detection_strategy_id": "DET0111",
   "analytic_name": "Analytic 0309",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified)",
   "tuning": "RegexPatterns | AllowedDomains | TimeWindow",
   "detection_logic_en": "Detection correlates message events in email and collaboration tools (e.g., Outlook, Teams) that contain regex-like patterns resembling credentials, API keys, or tokens. Anomalous forwarding or bulk copy activity of chat/email content containing secrets is flagged. Suspicious behavior includes users pasting secrets into direct messages or attaching config files with passwords."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1552.008",
   "technique_ja": "チャットメッセージ",
   "technique_en": "Chat Messages",
   "analytic_id": "AN0310",
   "detection_strategy_id": "DET0111",
   "analytic_name": "Analytic 0310",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (saas:slack) | User Account Authentication (saas:okta)",
   "log_sources_ja": "アプリケーションログ内容 (saas:slack) | ユーザーアカウント認証 (saas:okta)",
   "tuning": "IntegrationScope | RegexPatterns | UserContext",
   "detection_logic_en": "Detection monitors SaaS collaboration tools (e.g., Slack, Zoom, Jira) for messages or files containing credential-like patterns, or for suspicious API calls retrieving bulk chat histories by non-admin users. Identifies adversary behavior chains where chat logs are queried via APIs or integration bots to systematically extract sensitive material."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1555",
   "technique_ja": "パスワードストアからの認証情報窃取",
   "technique_en": "Credentials from Password Stores",
   "analytic_id": "AN1198",
   "detection_strategy_id": "DET0430",
   "analytic_name": "Analytic 1198",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | File Access (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TargetProcesses | KeywordPatterns",
   "detection_logic_en": "Monitors suspicious access to password stores such as LSASS, DPAPI, Windows Credential Manager, or browser credential databases. Detects anomalous process-to-process access (e.g., Mimikatz accessing LSASS) and correlation of credential store file reads with execution of non-standard processes."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1555",
   "technique_ja": "パスワードストアからの認証情報窃取",
   "technique_en": "Credentials from Password Stores",
   "analytic_id": "AN1199",
   "detection_strategy_id": "DET0430",
   "analytic_name": "Analytic 1199",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Process Creation (auditd:EXECVE)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | プロセス生成 (auditd:EXECVE)",
   "tuning": "MonitoredFiles | SuspiciousCommands",
   "detection_logic_en": "Detects access to known password store files (e.g., /etc/shadow, GNOME Keyring, KWallet, browser credential databases). Monitors anomalous process read attempts and suspicious API calls that attempt to extract stored credentials."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1555",
   "technique_ja": "パスワードストアからの認証情報窃取",
   "technique_en": "Credentials from Password Stores",
   "analytic_id": "AN1200",
   "detection_strategy_id": "DET0430",
   "analytic_name": "Analytic 1200",
   "platforms": "macOS",
   "log_sources": "File Access (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ファイルアクセス (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "AllowedApplications | AlertThreshold",
   "detection_logic_en": "Monitors Keychain database access and suspicious invocations of security and osascript utilities. Correlates process execution with attempts to dump or unlock Keychain data."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1555",
   "technique_ja": "パスワードストアからの認証情報窃取",
   "technique_en": "Credentials from Password Stores",
   "analytic_id": "AN1201",
   "detection_strategy_id": "DET0430",
   "analytic_name": "Analytic 1201",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Enumeration (AWS:CloudTrail) | OS API Execution (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス列挙 (AWS:CloudTrail) | OS API実行 (AWS:CloudTrail)",
   "tuning": "UserContext | AccessThreshold",
   "detection_logic_en": "Detects attempts to access or enumerate cloud password/secrets storage services such as AWS Secrets Manager, Azure Key Vault, or GCP Secret Manager. Monitors API calls for abnormal enumeration or bulk retrieval of secrets."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1555.001",
   "technique_ja": "キーチェーン",
   "technique_en": "Keychain",
   "analytic_id": "AN1112",
   "detection_strategy_id": "DET0396",
   "analytic_name": "Analytic 1112",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | OS API Execution (macos:unifiedlog) | File Access (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | OS API実行 (macos:unifiedlog) | ファイルアクセス (macos:unifiedlog)",
   "tuning": "AllowedApplications | AlertThreshold | ParentProcessContext",
   "detection_logic_en": "Detects suspicious access to macOS Keychain files and APIs. Observes processes invoking the 'security' utility or accessing Keychain databases directly, correlates these with abnormal parent process lineage or unexpected user context. Monitors attempts to dump, unlock, or read credential storage beyond normal application workflows."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1555.002",
   "technique_ja": "securitydメモリ",
   "technique_en": "Securityd Memory",
   "analytic_id": "AN0156",
   "detection_strategy_id": "DET0057",
   "analytic_name": "Analytic 0156",
   "platforms": "macOS",
   "log_sources": "Process Access (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセスアクセス (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "AllowedDebuggers | TimeWindow | PrivilegedUsers",
   "detection_logic_en": "Detects suspicious memory access attempts targeting the `securityd` process. Observes tools invoking process memory read operations (e.g., ptrace, task_for_pid) against `securityd`. Correlates with anomalous parent process lineage, root privilege escalation, or repeated unauthorized attempts."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1555.002",
   "technique_ja": "securitydメモリ",
   "technique_en": "Securityd Memory",
   "analytic_id": "AN0157",
   "detection_strategy_id": "DET0057",
   "analytic_name": "Analytic 0157",
   "platforms": "Linux",
   "log_sources": "Process Access (auditd:SYSCALL) | File Access (auditd:FILE) | Command Execution (auditd:EXECVE)",
   "log_sources_ja": "プロセスアクセス (auditd:SYSCALL) | ファイルアクセス (auditd:FILE) | コマンド実行 (auditd:EXECVE)",
   "tuning": "MonitoredProcesses | CorrelationDepth | PrivilegeContext",
   "detection_logic_en": "Detects adversaries attempting to attach debuggers or memory dump utilities to credential storage daemons analogous to macOS `securityd`. Observes ptrace syscalls, /proc/<pid>/mem access, or gcore dumps against sensitive processes. Correlates anomalies with privilege escalation or credential dumping attempts."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1555.003",
   "technique_ja": "Webブラウザからの認証情報",
   "technique_en": "Credentials from Web Browsers",
   "analytic_id": "AN0105",
   "detection_strategy_id": "DET0037",
   "analytic_name": "Analytic 0105",
   "platforms": "Windows",
   "log_sources": "File Access (WinEventLog:Security) | Process Access (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイルアクセス (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "MonitoredPaths | TimeWindow",
   "detection_logic_en": "Detects unauthorized access to web browser credential stores (e.g., Chrome Login Data, Edge Credential Locker) by processes other than the browser itself. Correlates file reads of credential databases with subsequent API calls to `CryptUnprotectData` or memory inspection attempts."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1555.003",
   "technique_ja": "Webブラウザからの認証情報",
   "technique_en": "Credentials from Web Browsers",
   "analytic_id": "AN0106",
   "detection_strategy_id": "DET0037",
   "analytic_name": "Analytic 0106",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:FILE) | Process Access (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:FILE) | プロセスアクセス (auditd:SYSCALL)",
   "tuning": "BrowserCredentialFiles | AllowedDebuggers",
   "detection_logic_en": "Detects attempts to access browser credential stores (e.g., Firefox `logins.json`, Chrome SQLite DB) or processes (e.g., gnome-keyring-daemon). Observes unauthorized file reads and memory inspection of browser processes using ptrace or gdb."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1555.003",
   "technique_ja": "Webブラウザからの認証情報",
   "technique_en": "Credentials from Web Browsers",
   "analytic_id": "AN0107",
   "detection_strategy_id": "DET0037",
   "analytic_name": "Analytic 0107",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Access (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイルアクセス (macos:unifiedlog)",
   "tuning": "PrivilegedUsers | TimeWindow",
   "detection_logic_en": "Detects abnormal access to Safari credential stores (Keychain-backed) or Chrome/Firefox login databases. Observes processes executing `security dump-keychain` or directly reading credential files in `~/Library/Application Support`. Correlates file access with suspicious process ancestry or unsigned binaries."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1555.004",
   "technique_ja": "Windows資格情報マネージャ",
   "technique_en": "Windows Credential Manager",
   "analytic_id": "AN0378",
   "detection_strategy_id": "DET0134",
   "analytic_name": "Analytic 0378",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Process Access (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon)",
   "tuning": "MonitoredPaths | TimeWindow | PrivilegedUsers",
   "detection_logic_en": "Detects unauthorized access to Windows Credential Manager through anomalous process execution (vaultcmd.exe, rundll32.exe keymgr.dll), suspicious API calls (CredEnumerateA), or direct file access to Credential Locker files. Correlates process creation with subsequent file reads of .vcrd/.vpol files under user Credential Locker directories."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1555.005",
   "technique_ja": "パスワードマネージャ",
   "technique_en": "Password Managers",
   "analytic_id": "AN1641",
   "detection_strategy_id": "DET0597",
   "analytic_name": "Analytic 1641",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Process Access (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon)",
   "tuning": "PasswordManagerBinaries | TimeWindow | UserContext",
   "detection_logic_en": "Detection of suspicious access to password manager processes (KeePass, 1Password, LastPass, Bitwarden) through abnormal process injection, memory reads, or command-line usage of vault-related DLLs. Correlates process creation with OS API calls and file access to vault databases (.kdbx, .opvault, .ldb)."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1555.005",
   "technique_ja": "パスワードマネージャ",
   "technique_en": "Password Managers",
   "analytic_id": "AN1642",
   "detection_strategy_id": "DET0597",
   "analytic_name": "Analytic 1642",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Process Access (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | プロセスアクセス (auditd:SYSCALL)",
   "tuning": "VaultFilePaths | TimeWindow",
   "detection_logic_en": "Suspicious access to password manager vaults (KeePassXC, gnome-keyring, pass) via memory scraping or unauthorized file reads. Detects unusual command execution involving gdb/strace attached to password manager processes."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1555.005",
   "technique_ja": "パスワードマネージャ",
   "technique_en": "Password Managers",
   "analytic_id": "AN1643",
   "detection_strategy_id": "DET0597",
   "analytic_name": "Analytic 1643",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Access (macos:unifiedlog) | Process Access (macos:osquery)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイルアクセス (macos:unifiedlog) | プロセスアクセス (macos:osquery)",
   "tuning": "VaultFileExtensions | ParentProcessWhitelist",
   "detection_logic_en": "Detection of password manager database access (1Password .opvault, LastPass caches, KeePass .kdbx) outside expected parent processes. Identifies memory scraping attempts via suspicious API calls or tools attaching to password manager processes."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1555.006",
   "technique_ja": "クラウドシークレット管理ストア",
   "technique_en": "Cloud Secrets Management Stores",
   "analytic_id": "AN0366",
   "detection_strategy_id": "DET0130",
   "analytic_name": "Analytic 0366",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Enumeration (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス列挙 (AWS:CloudTrail)",
   "tuning": "PrivilegedRoles | TimeWindow | AccessPatterns | RegionConstraints",
   "detection_logic_en": "Detection of suspicious access to cloud-native secret management systems (AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, HashiCorp Vault). Focuses on abnormal secret retrieval activity, such as secrets being accessed by unusual identities, from unexpected regions, outside business hours, or at high volume. Correlates API calls to secret retrieval with surrounding authentication events, role assumptions, and anomalous execution patterns."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556",
   "technique_ja": "認証プロセスの変更",
   "technique_en": "Modify Authentication Process",
   "analytic_id": "AN0287",
   "detection_strategy_id": "DET0104",
   "analytic_name": "Analytic 0287",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Process Access (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "MonitoredRegistryKeys | TimeWindow",
   "detection_logic_en": "Detects modification of LSASS and authentication DLLs, suspicious registry changes to password filter packages, and abnormal process access to lsass.exe. Correlates registry modifications, DLL loads, and process handle access events."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556",
   "technique_ja": "認証プロセスの変更",
   "technique_en": "Modify Authentication Process",
   "analytic_id": "AN0288",
   "detection_strategy_id": "DET0104",
   "analytic_name": "Analytic 0288",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "WatchedPaths",
   "detection_logic_en": "Detects modification of PAM configuration files, unauthorized new PAM modules, and suspicious process execution accessing PAM-related binaries. Correlates file modification events in /etc/pam.d/ with process execution of unauthorized binaries."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556",
   "technique_ja": "認証プロセスの変更",
   "technique_en": "Modify Authentication Process",
   "analytic_id": "AN0289",
   "detection_strategy_id": "DET0104",
   "analytic_name": "Analytic 0289",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | Process Access (macos:osquery)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | プロセスアクセス (macos:osquery)",
   "tuning": "PluginPaths",
   "detection_logic_en": "Detects unauthorized additions or changes to /Library/Security/SecurityAgentPlugins and suspicious process activity attempting to hook authentication APIs. Correlates file modifications with abnormal plugin loads in authentication flows."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556",
   "technique_ja": "認証プロセスの変更",
   "technique_en": "Modify Authentication Process",
   "analytic_id": "AN0290",
   "detection_strategy_id": "DET0104",
   "analytic_name": "Analytic 0290",
   "platforms": "Identity Provider",
   "log_sources": "Cloud Service Modification (azure:policy) | User Account Modification (m365:unified)",
   "log_sources_ja": "クラウドサービス変更 (azure:policy) | ユーザーアカウント変更 (m365:unified)",
   "tuning": "PolicyBaseline",
   "detection_logic_en": "Detects suspicious configuration changes in IdP authentication flows such as enabling reversible password encryption, MFA bypass, or policy weakening. Correlates policy modification events with unusual administrative activity."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556",
   "technique_ja": "認証プロセスの変更",
   "technique_en": "Modify Authentication Process",
   "analytic_id": "AN0291",
   "detection_strategy_id": "DET0104",
   "analytic_name": "Analytic 0291",
   "platforms": "IaaS",
   "log_sources": "User Account Modification (AWS:CloudTrail) | Cloud Service Modification (AWS:CloudTrail)",
   "log_sources_ja": "ユーザーアカウント変更 (AWS:CloudTrail) | クラウドサービス変更 (AWS:CloudTrail)",
   "tuning": "ApprovedAccounts",
   "detection_logic_en": "Detects unauthorized changes to IAM authentication configurations such as disabling MFA, creating backdoor access keys, or altering trust policies. Correlates identity policy updates with unusual login behavior."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.001",
   "technique_ja": "ドメインコントローラ認証",
   "technique_en": "Domain Controller Authentication",
   "analytic_id": "AN0757",
   "detection_strategy_id": "DET0271",
   "analytic_name": "Analytic 0757",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Logon Session Creation (WinEventLog:Security) | File Modification (WinEventLog:System)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ログオンセッション作成 (WinEventLog:Security) | ファイル変更 (WinEventLog:System)",
   "tuning": "MonitoredDLLs | TimeWindow | UserContext",
   "detection_logic_en": "Detects anomalous process access to LSASS on domain controllers, suspicious module loads of authentication DLLs, and registry or file modifications indicative of Skeleton Key–style patching. Correlates LSASS access attempts with subsequent abnormal logon activity patterns."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.002",
   "technique_ja": "パスワードフィルタDLL",
   "technique_en": "Password Filter DLL",
   "analytic_id": "AN1303",
   "detection_strategy_id": "DET0472",
   "analytic_name": "Analytic 1303",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "RegistryPath | AllowedDLLs | TimeWindow | FilePathPatterns",
   "detection_logic_en": "Detects suspicious registration of new password filter DLLs into the authentication process. Correlates registry modifications to LSASS Notification Packages with subsequent DLL creation and loading events. Observes anomalous file placement of DLLs in system directories followed by LSASS loading the new filter during logon/password change activity."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.003",
   "technique_ja": "プラガブル認証モジュール（PAM）",
   "technique_en": "Pluggable Authentication Modules",
   "analytic_id": "AN1250",
   "detection_strategy_id": "DET0454",
   "analytic_name": "Analytic 1250",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Logon Session Creation (NSM:Connections)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | ログオンセッション作成 (NSM:Connections)",
   "tuning": "MonitoredPaths | TimeWindow | BaselineAccounts",
   "detection_logic_en": "Detects unauthorized modifications to PAM configuration files or shared object modules. Correlates file modification events under /etc/pam.d/ or /lib/security/ with unusual authentication activity such as multiple simultaneous logins, off-hours logins, or logons without corresponding physical/VPN access."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.003",
   "technique_ja": "プラガブル認証モジュール（PAM）",
   "technique_en": "Pluggable Authentication Modules",
   "analytic_id": "AN1251",
   "detection_strategy_id": "DET0454",
   "analytic_name": "Analytic 1251",
   "platforms": "macOS",
   "log_sources": "Logon Session Creation (macos:unifiedlog) | File Modification (macos:osquery)",
   "log_sources_ja": "ログオンセッション作成 (macos:unifiedlog) | ファイル変更 (macos:osquery)",
   "tuning": "WatchedPlugins | CorrelatedSources",
   "detection_logic_en": "Detects suspicious changes to macOS authorization and PAM plugin files. Correlates file modifications under /etc/pam.d/ or /Library/Security/SecurityAgentPlugins with unexpected authentication attempts or anomalous account usage."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.004",
   "technique_ja": "ネットワークデバイス認証",
   "technique_en": "Network Device Authentication",
   "analytic_id": "AN0758",
   "detection_strategy_id": "DET0272",
   "analytic_name": "Analytic 0758",
   "platforms": "Network Devices",
   "log_sources": "File Modification (networkconfig) | User Account Authentication (network:auth)",
   "log_sources_ja": "ファイル変更 (networkconfig) | ユーザーアカウント認証 (network:auth)",
   "tuning": "BaselineChecksums | AuthFailureThreshold | VerificationInterval",
   "detection_logic_en": "Detects unauthorized modification of network device authentication by correlating OS image file changes, checksum mismatches, or memory verification failures with anomalous authentication events. Focus is on behaviors where patched images introduce hardcoded passwords or bypass native authentication."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.005",
   "technique_ja": "可逆暗号化",
   "technique_en": "Reversible Encryption",
   "analytic_id": "AN1621",
   "detection_strategy_id": "DET0589",
   "analytic_name": "Analytic 1621",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "MonitoredOUs | TimeWindow | SuspiciousCmdletList",
   "detection_logic_en": "Detects enabling of reversible password encryption in Active Directory or Group Policy, suspicious PowerShell commands modifying AD user properties, and unusual account configuration changes correlated with policy modifications. Multi-event correlation links Group Policy edits, PowerShell command execution, and user account property changes to identify tampering with authentication encryption settings."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0543",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0543",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Modification (WinEventLog:Security) | Script Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (WinEventLog:Security) | スクリプト実行 (WinEventLog:PowerShell)",
   "tuning": "WatchedAttributes | TimeWindow",
   "detection_logic_en": "Detects registry and Group Policy modifications that disable or weaken MFA, suspicious PowerShell usage modifying MFA-related attributes, and anomalous login sessions succeeding without expected MFA challenge."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0544",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0544",
   "platforms": "Identity Provider",
   "log_sources": "Application Log Content (azure:signinlogs) | User Account Modification (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (azure:signinlogs) | ユーザーアカウント変更 (m365:unified)",
   "tuning": "PrivilegedRoles",
   "detection_logic_en": "Detects conditional access policy changes, exclusion of accounts from MFA enforcement, or registration of new MFA factors by non-admin or anomalous users."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0545",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0545",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Modification (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス変更 (AWS:CloudTrail)",
   "tuning": "MonitoredServices",
   "detection_logic_en": "Detects API calls to cloud secrets/MFA configurations where MFA enforcement policies are disabled or bypassed."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0546",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0546",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | User Account Authentication (NSM:Connections)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | ユーザーアカウント認証 (NSM:Connections)",
   "tuning": "MFAHooks",
   "detection_logic_en": "Detects PAM module modifications or removal of MFA hooks in /etc/pam.d/ configurations, correlated with successful authentications lacking MFA prompts."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0547",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0547",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | User Account Authentication (macos:unifiedlog)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | ユーザーアカウント認証 (macos:unifiedlog)",
   "tuning": "WatchedPluginPaths",
   "detection_logic_en": "Detects modifications to authorization plugins responsible for MFA enforcement and correlates with suspicious login sessions missing MFA prompts."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0548",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0548",
   "platforms": "SaaS",
   "log_sources": "User Account Modification (saas:zoom)",
   "log_sources_ja": "ユーザーアカウント変更 (saas:zoom)",
   "tuning": "AcceptedFactors",
   "detection_logic_en": "Detects suspicious MFA method changes, such as registration of weaker factors (e.g., SMS), or removal of MFA requirements for specific accounts or groups."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.006",
   "technique_ja": "多要素認証",
   "technique_en": "Multi-Factor Authentication",
   "analytic_id": "AN0549",
   "detection_strategy_id": "DET0190",
   "analytic_name": "Analytic 0549",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified)",
   "tuning": "MonitoredPolicies",
   "detection_logic_en": "Detects MFA bypass attempts by modifying tenant-wide authentication policies or excluding high-value accounts from MFA enforcement."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.007",
   "technique_ja": "ハイブリッドID",
   "technique_en": "Hybrid Identity",
   "analytic_id": "AN0814",
   "detection_strategy_id": "DET0293",
   "analytic_name": "Analytic 0814",
   "platforms": "Windows",
   "log_sources": "Module Load (WinEventLog:Sysmon) | Active Directory Object Modification (WinEventLog:Security) | Logon Session Creation (WinEventLog:Security)",
   "log_sources_ja": "モジュール読み込み (WinEventLog:Sysmon) | Active Directoryオブジェクト変更 (WinEventLog:Security) | ログオンセッション作成 (WinEventLog:Security)",
   "tuning": "WatchedServices | TimeWindow",
   "detection_logic_en": "Detects injection or tampering of DLLs in hybrid identity agents (e.g., AzureADConnectAuthenticationAgentService), registry or configuration changes tied to PTA/AD FS, and anomalous LSASS or AD FS module loads correlated with authentication anomalies."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.007",
   "technique_ja": "ハイブリッドID",
   "technique_en": "Hybrid Identity",
   "analytic_id": "AN0815",
   "detection_strategy_id": "DET0293",
   "analytic_name": "Analytic 0815",
   "platforms": "Identity Provider",
   "log_sources": "Application Log Content (azure:signinlogs) | User Account Modification (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (azure:signinlogs) | ユーザーアカウント変更 (m365:unified)",
   "tuning": "PrivilegedRoles",
   "detection_logic_en": "Detects registration of new PTA agents, conditional access changes disabling hybrid MFA enforcement, or suspicious updates to AD FS token-signing configurations."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.007",
   "technique_ja": "ハイブリッドID",
   "technique_en": "Hybrid Identity",
   "analytic_id": "AN0816",
   "detection_strategy_id": "DET0293",
   "analytic_name": "Analytic 0816",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Modification (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス変更 (AWS:CloudTrail)",
   "tuning": "MonitoredFederations",
   "detection_logic_en": "Detects API calls registering or updating hybrid identity connectors, modification of cloud-to-on-premises federation trust, and unusual token issuance logs."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.007",
   "technique_ja": "ハイブリッドID",
   "technique_en": "Hybrid Identity",
   "analytic_id": "AN0817",
   "detection_strategy_id": "DET0293",
   "analytic_name": "Analytic 0817",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified)",
   "tuning": "PolicyScope",
   "detection_logic_en": "Detects tenant-wide authentication or conditional access changes that weaken hybrid identity enforcement, including disabling AD FS or bypassing hybrid MFA policies."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.007",
   "technique_ja": "ハイブリッドID",
   "technique_en": "Hybrid Identity",
   "analytic_id": "AN0818",
   "detection_strategy_id": "DET0293",
   "analytic_name": "Analytic 0818",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (saas:okta)",
   "log_sources_ja": "アプリケーションログ内容 (saas:okta)",
   "tuning": "FederationEndpoints",
   "detection_logic_en": "Detects suspicious changes to SAML/OAuth federation configurations, such as new signing certificates, altered endpoints, or claims issuance rules granting elevated privileges."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.008",
   "technique_ja": "ネットワークプロバイダDLL",
   "technique_en": "Network Provider DLL",
   "analytic_id": "AN1598",
   "detection_strategy_id": "DET0580",
   "analytic_name": "Analytic 1598",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "MonitoredRegistryKeys | SuspiciousDLLPaths | TimeWindow",
   "detection_logic_en": "Detects registration of new or modified network provider DLLs via registry changes, anomalous file creation of DLLs in system directories, and suspicious process activity (mpnotify.exe interacting with non-standard DLLs). Multi-event correlation ties registry modification events to subsequent DLL loads during user logon activity."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.009",
   "technique_ja": "条件付きアクセスポリシー",
   "technique_en": "Conditional Access Policies",
   "analytic_id": "AN0087",
   "detection_strategy_id": "DET0030",
   "analytic_name": "Analytic 0087",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Modification (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス変更 (AWS:CloudTrail)",
   "tuning": "MonitoredIAMConditions | TimeWindow | PrivilegedAccounts",
   "detection_logic_en": "Detects modifications to IAM conditions or policies that alter authentication behavior, such as adding permissive trusted IPs, removing MFA requirements, or changing regional access restrictions. Behavioral detection focuses on anomalous policy updates tied to privileged accounts and subsequent suspicious logon activity from previously blocked regions or devices."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1556.009",
   "technique_ja": "条件付きアクセスポリシー",
   "technique_en": "Conditional Access Policies",
   "analytic_id": "AN0088",
   "detection_strategy_id": "DET0030",
   "analytic_name": "Analytic 0088",
   "platforms": "Identity Provider",
   "log_sources": "Active Directory Object Modification (azure:activity) | Application Log Content (saas:okta)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (azure:activity) | アプリケーションログ内容 (saas:okta)",
   "tuning": "TargetedApplications | RiskThresholds | UserContext",
   "detection_logic_en": "Detects suspicious updates to conditional access or MFA enforcement policies in identity providers such as Entra ID, Okta, or JumpCloud. Focus is on removal of policy blocks, addition of broad exclusions, or registration of adversary-controlled MFA methods, followed by anomalous login activity that takes advantage of the modified policies."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1557",
   "technique_ja": "中間者（AiTM）",
   "technique_en": "Adversary-in-the-Middle",
   "analytic_id": "AN0823",
   "detection_strategy_id": "DET0296",
   "analytic_name": "Analytic 0823",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "MonitoredRegistryPaths | DowngradeCipherList | TimeWindow",
   "detection_logic_en": "Detects suspicious DNS/ARP poisoning attempts, unauthorized modifications to registry/network configuration, or abnormal TLS downgrade activity. Correlates changes in system configuration with subsequent unusual network flows or authentication events."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1557",
   "technique_ja": "中間者（AiTM）",
   "technique_en": "Adversary-in-the-Middle",
   "analytic_id": "AN0824",
   "detection_strategy_id": "DET0296",
   "analytic_name": "Analytic 0824",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "MonitoredFiles | ARPThreshold",
   "detection_logic_en": "Detects unauthorized edits to /etc/hosts, /etc/resolv.conf, or suspicious ARP broadcasts. Correlates file modifications with subsequent unexpected network sessions or service creation."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1557",
   "technique_ja": "中間者（AiTM）",
   "technique_en": "Adversary-in-the-Middle",
   "analytic_id": "AN0825",
   "detection_strategy_id": "DET0296",
   "analytic_name": "Analytic 0825",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ProfileIdentifiers | TLSVersionThreshold",
   "detection_logic_en": "Detects unauthorized edits to system configuration profiles, unexpected certificate trust changes, or abnormal ARP/DNS patterns indicative of interception."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1557",
   "technique_ja": "中間者（AiTM）",
   "technique_en": "Adversary-in-the-Middle",
   "analytic_id": "AN0826",
   "detection_strategy_id": "DET0296",
   "analytic_name": "Analytic 0826",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Flow (NSM:Flow) | File Modification (networkdevice:config)",
   "log_sources_ja": "ネットワークトラフィックフロー (NSM:Flow) | ファイル変更 (networkdevice:config)",
   "tuning": "RoutingPolicyBaseline | FirmwareChecksum",
   "detection_logic_en": "Detects unauthorized firmware or configuration changes enabling adversary-in-the-middle positioning (e.g., route injection, DNS spoofing, SSL downgrade). Behavioral analytics focus on sudden changes to routing tables or image file integrity failures."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1557.001",
   "technique_ja": "名前解決ポイズニングとSMBリレー",
   "technique_en": "Name Resolution Poisoning and SMB Relay",
   "analytic_id": "AN1274",
   "detection_strategy_id": "DET0462",
   "analytic_name": "Analytic 1274",
   "platforms": "Windows",
   "log_sources": "Service Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Security) | Network Traffic Content (NSM:Flow) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "サービス作成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Security) | ネットワークトラフィック内容 (NSM:Flow) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "TrustedResponderList | TimeWindow | SMBServiceBaseline",
   "detection_logic_en": "Detects anomalous network traffic on UDP 5355 (LLMNR) and UDP 137 (NBT-NS) combined with unauthorized SMB relay attempts, registry modifications re-enabling multicast name resolution, or suspicious service creation indicative of adversary-in-the-middle credential interception."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1557.002",
   "technique_ja": "ARPキャッシュポイズニング",
   "technique_en": "ARP Cache Poisoning",
   "analytic_id": "AN1091",
   "detection_strategy_id": "DET0387",
   "analytic_name": "Analytic 1091",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Flow (WinEventLog:Security)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィックフロー (WinEventLog:Security)",
   "tuning": "TrustedGatewayMAC | TimeWindow",
   "detection_logic_en": "Detects anomalous ARP traffic or cache modifications on Windows endpoints that indicate ARP poisoning. Behavioral focus is on multiple IP addresses resolving to a single MAC, or unsolicited ARP replies from unauthorized devices."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1557.002",
   "technique_ja": "ARPキャッシュポイズニング",
   "technique_en": "ARP Cache Poisoning",
   "analytic_id": "AN1092",
   "detection_strategy_id": "DET0387",
   "analytic_name": "Analytic 1092",
   "platforms": "Linux",
   "log_sources": "Network Traffic Content (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィック内容 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "AllowedARPUpdates | AlertThreshold",
   "detection_logic_en": "Detects suspicious gratuitous ARP responses or inconsistent IP-to-MAC mappings using auditd and packet capture. Behavioral focus is on unsolicited replies overriding legitimate ARP ownership."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1557.002",
   "technique_ja": "ARPキャッシュポイズニング",
   "technique_en": "ARP Cache Poisoning",
   "analytic_id": "AN1093",
   "detection_strategy_id": "DET0387",
   "analytic_name": "Analytic 1093",
   "platforms": "macOS",
   "log_sources": "Network Traffic Flow (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィックフロー (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "GatewayMACBaseline | CorrelationDepth",
   "detection_logic_en": "Detects anomalous ARP cache changes and unsolicited ARP broadcasts using unified logs and packet capture. Behavioral detection includes multiple IP addresses mapped to the same MAC address and repeated gratuitous ARP traffic."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1557.003",
   "technique_ja": "DHCPスプーフィング",
   "technique_en": "DHCP Spoofing",
   "analytic_id": "AN1290",
   "detection_strategy_id": "DET0468",
   "analytic_name": "Analytic 1290",
   "platforms": "Windows",
   "log_sources": "Application Log Content (WinEventLog:System) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (WinEventLog:System) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "AuthorizedDHCPServers | TimeWindow",
   "detection_logic_en": "Detects rogue DHCP server activity and anomalous DHCP OFFER/ACK messages assigning unexpected DNS or gateway values. Detection correlates DHCP server role changes, DHCP exhaustion warnings, and sudden network configuration changes across endpoints."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1557.003",
   "technique_ja": "DHCPスプーフィング",
   "technique_en": "DHCP Spoofing",
   "analytic_id": "AN1291",
   "detection_strategy_id": "DET0468",
   "analytic_name": "Analytic 1291",
   "platforms": "Linux",
   "log_sources": "Application Log Content (linux:syslog) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (linux:syslog) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "AllowedDHCPMACs | DHCPLeaseChangeThreshold",
   "detection_logic_en": "Detects rogue DHCP activity by monitoring syslog for dhclient messages assigning unauthorized DNS/gateway values. Packet capture or IDS can detect multiple competing DHCP OFFERs from non-authorized servers."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1557.003",
   "technique_ja": "DHCPスプーフィング",
   "technique_en": "DHCP Spoofing",
   "analytic_id": "AN1292",
   "detection_strategy_id": "DET0468",
   "analytic_name": "Analytic 1292",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "BaselineDNS | AlertSensitivity",
   "detection_logic_en": "Detects DHCP spoofing by monitoring unified logs for unexpected DHCP ACK/OFFER parameters and correlating with packet captures for multiple DHCP servers. Behavioral emphasis is on inconsistent DNS and gateway assignments that redirect traffic."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1557.004",
   "technique_ja": "イーブルツイン",
   "technique_en": "Evil Twin",
   "analytic_id": "AN1069",
   "detection_strategy_id": "DET0379",
   "analytic_name": "Analytic 1069",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Flow (WLANLogs:Association) | Network Traffic Content (NSM:Flow) | Application Log Content (networkdevice:syslog)",
   "log_sources_ja": "ネットワークトラフィックフロー (WLANLogs:Association) | ネットワークトラフィック内容 (NSM:Flow) | アプリケーションログ内容 (networkdevice:syslog)",
   "tuning": "KnownSSIDs | AllowedBSSIDs | SignalStrengthThreshold | CaptivePortalDomains",
   "detection_logic_en": "Detects rogue Wi-Fi access points broadcasting the same SSID as legitimate APs with stronger signal strength, unexpected MAC/BSSID values, or inconsistent encryption settings. Correlates authentication attempts, captive portal redirections, and anomalous traffic flows through unauthorized APs."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1558",
   "technique_ja": "Kerberosチケットの窃取/偽造",
   "technique_en": "Steal or Forge Kerberos Tickets",
   "analytic_id": "AN1443",
   "detection_strategy_id": "DET0522",
   "analytic_name": "Analytic 1443",
   "platforms": "Windows",
   "log_sources": "Logon Session Metadata (WinEventLog:Security) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッションメタデータ (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "TicketLifetimeThreshold | EncryptionTypes | ProcessAllowlist",
   "detection_logic_en": "Detects anomalous Kerberos activity such as forged or stolen tickets by correlating malformed fields in logon events, RC4-encrypted TGTs, or TGS requests without corresponding TGT requests. Also detects suspicious processes accessing LSASS memory for ticket extraction."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1558",
   "technique_ja": "Kerberosチケットの窃取/偽造",
   "technique_en": "Steal or Forge Kerberos Tickets",
   "analytic_id": "AN1444",
   "detection_strategy_id": "DET0522",
   "analytic_name": "Analytic 1444",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Active Directory Credential Request (linux:syslog)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | Active Directory資格情報要求 (linux:syslog)",
   "tuning": "SecretsAccessThreshold | UnusualServiceAccounts",
   "detection_logic_en": "Detects suspicious access to SSSD secrets database and Kerberos key material indicating ticket theft or replay attempts. Correlates anomalous file access with unusual Kerberos service ticket requests."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1558",
   "technique_ja": "Kerberosチケットの窃取/偽造",
   "technique_en": "Steal or Forge Kerberos Tickets",
   "analytic_id": "AN1445",
   "detection_strategy_id": "DET0522",
   "analytic_name": "Analytic 1445",
   "platforms": "macOS",
   "log_sources": "Logon Session Metadata (macos:unifiedlog)",
   "log_sources_ja": "ログオンセッションメタデータ (macos:unifiedlog)",
   "tuning": "TicketRequestPatterns | TicketLifetime",
   "detection_logic_en": "Detects attempts to forge or replay Kerberos tickets by monitoring Unified Logs for anomalous kinit/klist activity and correlating unusual authentication sequences."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1558.001",
   "technique_ja": "ゴールデンチケット",
   "technique_en": "Golden Ticket",
   "analytic_id": "AN0405",
   "detection_strategy_id": "DET0144",
   "analytic_name": "Analytic 0405",
   "platforms": "Windows",
   "log_sources": "Logon Session Metadata (WinEventLog:Security) | Active Directory Credential Request (WinEventLog:Security) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッションメタデータ (WinEventLog:Security) | Active Directory資格情報要求 (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "TicketLifetimeThreshold | AllowedEncryptionTypes | PrivilegedAccountPatterns | ProcessAllowlist",
   "detection_logic_en": "Detects forged Kerberos Golden Tickets by correlating anomalous Kerberos ticket lifetimes, unexpected encryption types (e.g., RC4 in modern domains), malformed fields in logon/logoff events, and TGS requests without preceding TGT requests. Also monitors for abnormal patterns of access associated with elevated privileges across multiple systems."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1558.002",
   "technique_ja": "シルバーチケット",
   "technique_en": "Silver Ticket",
   "analytic_id": "AN0675",
   "detection_strategy_id": "DET0241",
   "analytic_name": "Analytic 0675",
   "platforms": "Windows",
   "log_sources": "Logon Session Metadata (WinEventLog:Security) | Active Directory Credential Request (WinEventLog:Kerberos) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッションメタデータ (WinEventLog:Security) | Active Directory資格情報要求 (WinEventLog:Kerberos) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "ServiceAccountScope | TicketValidationBaseline | ProcessAllowlist | TimeWindow",
   "detection_logic_en": "Detects forged Kerberos Silver Tickets by identifying anomalous Kerberos service ticket activity such as malformed fields in logon events, TGS requests without interaction with the KDC, and access attempts using service accounts outside expected hosts/resources. Also monitors suspicious processes accessing LSASS memory for credential dumping."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1558.003",
   "technique_ja": "Kerberoasting",
   "technique_en": "Kerberoasting",
   "analytic_id": "AN0444",
   "detection_strategy_id": "DET0157",
   "analytic_name": "Analytic 0444",
   "platforms": "Windows",
   "log_sources": "Active Directory Credential Request (WinEventLog:Security) | Process Access (WinEventLog:Sysmon) | Logon Session Creation (WinEventLog:Security) | Logon Session Metadata (WinEventLog:Security)",
   "log_sources_ja": "Active Directory資格情報要求 (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon) | ログオンセッション作成 (WinEventLog:Security) | ログオンセッションメタデータ (WinEventLog:Security)",
   "tuning": "TGSRequestThreshold | AllowedEncryptionTypes | ServiceAccountBaselines | TimeWindow",
   "detection_logic_en": "Detects Kerberoasting attempts by monitoring for anomalous Kerberos TGS requests (Event ID 4769) with RC4 encryption (etype 0x17), accounts requesting an unusual number of service tickets in a short period, or service accounts targeted outside normal usage baselines. Also correlates suspicious process activity (e.g., Mimikatz invoking LSASS access) with Kerberos ticket anomalies."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1558.004",
   "technique_ja": "AS-REP Roasting",
   "technique_en": "AS-REP Roasting",
   "analytic_id": "AN0316",
   "detection_strategy_id": "DET0113",
   "analytic_name": "Analytic 0316",
   "platforms": "Windows",
   "log_sources": "Active Directory Credential Request (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Active Directory資格情報要求 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "PreAuthDisabledAccountsBaseline | TGTRequestThreshold | AllowedEncryptionTypes | TimeWindow",
   "detection_logic_en": "Detects AS-REP roasting attempts by monitoring for Kerberos AS-REQ/AS-REP authentication patterns where preauthentication is disabled (Event ID 4768 with Pre-Auth Type 0). Correlates these requests with subsequent service ticket activity (Event ID 4769) and anomalies such as requests using weak RC4 encryption (etype 0x17). Excessive enumeration of accounts with 'Do not require Kerberos preauthentication' set in Active Directory is another key detection point."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1558.005",
   "technique_ja": "Ccacheファイル",
   "technique_en": "Ccache Files",
   "analytic_id": "AN0069",
   "detection_strategy_id": "DET0024",
   "analytic_name": "Analytic 0069",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "CcachePathBaseline | AllowedProcesses | TimeWindow",
   "detection_logic_en": "Detects unauthorized access, copying, or modification of Kerberos ccache files (krb5cc_%UID% or krb5.ccache) in /tmp or custom paths defined by KRB5CCNAME. Correlates file access with suspicious processes (e.g., credential dumping tools) and subsequent anomalous Kerberos authentication requests from non-standard processes."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1558.005",
   "technique_ja": "Ccacheファイル",
   "technique_en": "Ccache Files",
   "analytic_id": "AN0070",
   "detection_strategy_id": "DET0024",
   "analytic_name": "Analytic 0070",
   "platforms": "macOS",
   "log_sources": "File Access (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "ファイルアクセス (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "KerberosAPIProcessBaseline | SuspiciousBinaryList | TimeWindow",
   "detection_logic_en": "Detects abnormal interaction with memory-based Kerberos ccache (API:{uuid}) or file-based overrides. Focus on processes attempting to enumerate or extract Kerberos tickets outside of built-in utilities. Detects use of open-source tools (e.g., Bifrost, modified Mimikatz ports) that interact with the Kerberos framework APIs."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1606",
   "technique_ja": "Web認証情報の偽造",
   "technique_en": "Forge Web Credentials",
   "analytic_id": "AN0717",
   "detection_strategy_id": "DET0260",
   "analytic_name": "Analytic 0717",
   "platforms": "IaaS",
   "log_sources": "Web Credential Creation (AWS:CloudTrail) | Logon Session Creation (AWS:CloudTrail)",
   "log_sources_ja": "Web資格情報作成 (AWS:CloudTrail) | ログオンセッション作成 (AWS:CloudTrail)",
   "tuning": "AuthorizedRoleMappings | GeoVelocityThreshold",
   "detection_logic_en": "Defenders may detect adversaries forging web credentials in IaaS environments by monitoring for anomalous API activity such as AssumeRole or GetFederationToken being executed by unusual principals. These events often correlate with sudden logon sessions from unfamiliar IP addresses or regions. The chain is usually secret material misuse (stolen private key or password) → API request generating a new token → access to high-value resources."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1606",
   "technique_ja": "Web認証情報の偽造",
   "technique_en": "Forge Web Credentials",
   "analytic_id": "AN0718",
   "detection_strategy_id": "DET0260",
   "analytic_name": "Analytic 0718",
   "platforms": "Identity Provider",
   "log_sources": "Web Credential Creation (azure:signinlogs) | Web Credential Usage (NSM:Connections)",
   "log_sources_ja": "Web資格情報作成 (azure:signinlogs) | Web資格情報の使用 (NSM:Connections)",
   "tuning": "TokenLifetimeThreshold | ExpectedAuthFlows",
   "detection_logic_en": "Forged web credentials may manifest as anomalous SAML token issuance, OpenID Connect token minting, or Zimbra pre-auth key usage. Defenders may see tokens issued without normal authentication events, multiple valid tokens generated simultaneously, or signing anomalies in IdP logs."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1606",
   "technique_ja": "Web認証情報の偽造",
   "technique_en": "Forge Web Credentials",
   "analytic_id": "AN0719",
   "detection_strategy_id": "DET0260",
   "analytic_name": "Analytic 0719",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Logon Session Creation (WinEventLog:Security)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | ログオンセッション作成 (WinEventLog:Security)",
   "tuning": "ProcessWhitelist",
   "detection_logic_en": "Forged web credentials on Windows endpoints may be detected by anomalous browser cookie files, local token cache manipulations, or tools injecting tokens into sessions. Defenders may observe processes accessing LSASS or browser credential stores unexpectedly, followed by unusual logon sessions."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1606",
   "technique_ja": "Web認証情報の偽造",
   "technique_en": "Forge Web Credentials",
   "analytic_id": "AN0720",
   "detection_strategy_id": "DET0260",
   "analytic_name": "Analytic 0720",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Network Traffic Content (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | ネットワークトラフィック内容 (WinEventLog:Sysmon)",
   "tuning": "CredentialFilePaths",
   "detection_logic_en": "On Linux systems, forged credentials may be injected into browser session files, curl/wget headers, or token caches in memory. Detection can leverage auditd to track processes accessing sensitive files (~/.mozilla, ~/.config/chromium, ~/.aws/credentials) and correlate with suspicious outbound connections."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1606",
   "technique_ja": "Web認証情報の偽造",
   "technique_en": "Forge Web Credentials",
   "analytic_id": "AN0721",
   "detection_strategy_id": "DET0260",
   "analytic_name": "Analytic 0721",
   "platforms": "macOS",
   "log_sources": "Logon Session Creation (macos:unifiedlog) | Web Credential Usage (macos:unifiedlog)",
   "log_sources_ja": "ログオンセッション作成 (macos:unifiedlog) | Web資格情報の使用 (macos:unifiedlog)",
   "tuning": "AuthorizedKeychainApps",
   "detection_logic_en": "Forged credentials on macOS may be visible through Unified Logs showing abnormal access to Keychain or browser session files. Correlated with anomalous web session usage from Safari or Chrome processes outside typical user context."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1606",
   "technique_ja": "Web認証情報の偽造",
   "technique_en": "Forge Web Credentials",
   "analytic_id": "AN0722",
   "detection_strategy_id": "DET0260",
   "analytic_name": "Analytic 0722",
   "platforms": "SaaS",
   "log_sources": "Web Credential Creation (m365:unified) | Web Credential Usage (saas:auth)",
   "log_sources_ja": "Web資格情報作成 (m365:unified) | Web資格情報の使用 (saas:auth)",
   "tuning": "GeoLocationAlerts | TokenReplayThreshold",
   "detection_logic_en": "SaaS platforms may show forged credentials as unusual API keys, tokens, or session cookies being used without corresponding authentication. Correlated patterns include simultaneous valid sessions from multiple geographies, unusual API calls with new tokens, or bypass of expected MFA enforcement."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1606",
   "technique_ja": "Web認証情報の偽造",
   "technique_en": "Forge Web Credentials",
   "analytic_id": "AN0723",
   "detection_strategy_id": "DET0260",
   "analytic_name": "Analytic 0723",
   "platforms": "Office Suite",
   "log_sources": "Web Credential Creation (m365:oauth) | Logon Session Creation (m365:signinlogs)",
   "log_sources_ja": "Web資格情報作成 (m365:oauth) | ログオンセッション作成 (m365:signinlogs)",
   "tuning": "OAuthAppAllowlist",
   "detection_logic_en": "Forged web credentials in Office Suite contexts may appear as abnormal authentication headers in Outlook or Teams traffic, or unexplained OAuth grants in M365/Azure logs. Defenders should correlate token usage events with missing authentication flows and mismatched device/user context."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1606.001",
   "technique_ja": "Webクッキー",
   "technique_en": "Web Cookies",
   "analytic_id": "AN0483",
   "detection_strategy_id": "DET0171",
   "analytic_name": "Analytic 0483",
   "platforms": "IaaS",
   "log_sources": "Logon Session Creation (AWS:CloudTrail) | Web Credential Usage (AWS:CloudTrail)",
   "log_sources_ja": "ログオンセッション作成 (AWS:CloudTrail) | Web資格情報の使用 (AWS:CloudTrail)",
   "tuning": "GeoVelocityThreshold | AuthorizedCookieIssuers",
   "detection_logic_en": "Forged cookies in IaaS environments may appear as authentication attempts that bypass MFA, leveraging AssumeRole or session APIs with cookies that were never legitimately issued. Defenders should correlate cloud logs for cookie-based sessions without prior valid authentication, often followed by resource access from unfamiliar IP addresses."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1606.001",
   "technique_ja": "Webクッキー",
   "technique_en": "Web Cookies",
   "analytic_id": "AN0484",
   "detection_strategy_id": "DET0171",
   "analytic_name": "Analytic 0484",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Logon Session Creation (WinEventLog:Security)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ログオンセッション作成 (WinEventLog:Security)",
   "tuning": "BrowserCookiePaths | ProcessWhitelist",
   "detection_logic_en": "Forged web cookies on Windows endpoints can be detected by monitoring unusual modifications of browser cookie stores (e.g., Chrome SQLite DB, Edge cache) by processes outside of browsers, followed by authentication events to SaaS or IaaS services. Defenders may observe processes writing directly to cookie storage paths or injecting tokens into browser sessions."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1606.001",
   "technique_ja": "Webクッキー",
   "technique_en": "Web Cookies",
   "analytic_id": "AN0485",
   "detection_strategy_id": "DET0171",
   "analytic_name": "Analytic 0485",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "CredentialFilePaths",
   "detection_logic_en": "On Linux, defenders may observe forged cookie activity as unauthorized modifications to browser cookie databases (e.g., ~/.mozilla/firefox/*/cookies.sqlite, ~/.config/chromium/Default/Cookies) or scripted injection of session tokens. Suspicious usage includes curl/wget commands embedding forged cookies in headers, correlated with abnormal session activity in SaaS or IaaS logs."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1606.001",
   "technique_ja": "Webクッキー",
   "technique_en": "Web Cookies",
   "analytic_id": "AN0486",
   "detection_strategy_id": "DET0171",
   "analytic_name": "Analytic 0486",
   "platforms": "macOS",
   "log_sources": "File Access (macos:unifiedlog) | Web Credential Usage (macos:unifiedlog)",
   "log_sources_ja": "ファイルアクセス (macos:unifiedlog) | Web資格情報の使用 (macos:unifiedlog)",
   "tuning": "AuthorizedKeychainApps",
   "detection_logic_en": "Forged cookies on macOS may show up as abnormal access to Safari/Chrome cookie databases in ~/Library/Cookies, combined with unexpected logon sessions authenticated by those cookies. Unified Logs may show cookie injection events or abnormal access patterns to Keychain when linked to browser authentication flows."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1606.001",
   "technique_ja": "Webクッキー",
   "technique_en": "Web Cookies",
   "analytic_id": "AN0487",
   "detection_strategy_id": "DET0171",
   "analytic_name": "Analytic 0487",
   "platforms": "SaaS",
   "log_sources": "Web Credential Usage (m365:unified) | Logon Session Creation (saas:access)",
   "log_sources_ja": "Web資格情報の使用 (m365:unified) | ログオンセッション作成 (saas:access)",
   "tuning": "TokenReplayThreshold | GeoLocationAlerts",
   "detection_logic_en": "Forged cookies in SaaS environments manifest as valid web sessions without matching login activity, MFA enforcement bypass, or cookies reused across multiple devices/IPs. Defenders should look for cookie replay, concurrent sessions from multiple geographies, or session tokens generated by unrecognized apps."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1606.002",
   "technique_ja": "SAMLトークン",
   "technique_en": "SAML Tokens",
   "analytic_id": "AN0418",
   "detection_strategy_id": "DET0148",
   "analytic_name": "Analytic 0418",
   "platforms": "Identity Provider",
   "log_sources": "Logon Session Metadata (azure:signinlogs) | User Account Authentication (WinEventLog:Security)",
   "log_sources_ja": "ログオンセッションメタデータ (azure:signinlogs) | ユーザーアカウント認証 (WinEventLog:Security)",
   "tuning": "TokenLifetimeThreshold | TrustedIssuerList",
   "detection_logic_en": "Forged SAML tokens can be observed as authentication attempts with valid signatures but missing expected preceding Kerberos or authentication events. Defenders may correlate SAML assertions with absent Event IDs 4769, 1200, or 1202, or tokens issued with abnormal lifetimes, issuers, or claims compared to baseline."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1606.002",
   "technique_ja": "SAMLトークン",
   "technique_en": "SAML Tokens",
   "analytic_id": "AN0419",
   "detection_strategy_id": "DET0148",
   "analytic_name": "Analytic 0419",
   "platforms": "IaaS",
   "log_sources": "Web Credential Usage (AWS:CloudTrail) | Logon Session Creation (CloudTrail:Signin)",
   "log_sources_ja": "Web資格情報の使用 (AWS:CloudTrail) | ログオンセッション作成 (CloudTrail:Signin)",
   "tuning": "CrossAccountUsage",
   "detection_logic_en": "Forged SAML tokens in IaaS environments often manifest as cross-cloud or cross-account authentication without matching STS events. Defenders may see AssumeRole or GetFederationToken API usage without a corresponding SAML assertion log from the trusted IdP."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1606.002",
   "technique_ja": "SAMLトークン",
   "technique_en": "SAML Tokens",
   "analytic_id": "AN0420",
   "detection_strategy_id": "DET0148",
   "analytic_name": "Analytic 0420",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Web Credential Creation (WinEventLog:ADFS)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | Web資格情報作成 (WinEventLog:ADFS)",
   "tuning": "ClaimAnomalyThreshold",
   "detection_logic_en": "Forged SAML tokens may be used on Windows systems to authenticate to federated apps without normal Kerberos activity. Defenders may detect anomalous event correlation, where access to SaaS/O365 via SAML occurs without prior TGT requests or user logons."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1606.002",
   "technique_ja": "SAMLトークン",
   "technique_en": "SAML Tokens",
   "analytic_id": "AN0421",
   "detection_strategy_id": "DET0148",
   "analytic_name": "Analytic 0421",
   "platforms": "SaaS",
   "log_sources": "Web Credential Usage (saas:access) | Logon Session Metadata (m365:unified)",
   "log_sources_ja": "Web資格情報の使用 (saas:access) | ログオンセッションメタデータ (m365:unified)",
   "tuning": "GeoVelocityThreshold",
   "detection_logic_en": "Forged SAML tokens can appear as SaaS logins where authentication succeeded without MFA, or where tokens contain claims inconsistent with the user profile. Look for concurrent sessions across different geographies with the same SAML assertion ID."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1606.002",
   "technique_ja": "SAMLトークン",
   "technique_en": "SAML Tokens",
   "analytic_id": "AN0422",
   "detection_strategy_id": "DET0148",
   "analytic_name": "Analytic 0422",
   "platforms": "Office Suite",
   "log_sources": "Web Credential Usage (m365:exchange) | Logon Session Creation (m365:sharepoint)",
   "log_sources_ja": "Web資格情報の使用 (m365:exchange) | ログオンセッション作成 (m365:sharepoint)",
   "tuning": "ReplayDetectionThreshold",
   "detection_logic_en": "Forged SAML tokens may be leveraged to access O365 apps such as Outlook or SharePoint. Defenders should monitor for token replay across multiple clients or access attempts to privileged mailboxes without prior interactive login."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1621",
   "technique_ja": "多要素認証リクエストの生成",
   "technique_en": "Multi-Factor Authentication Request Generation",
   "analytic_id": "AN0449",
   "detection_strategy_id": "DET0160",
   "analytic_name": "Analytic 0449",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (azure:signinlogs) | Application Log Content (NSM:Connections)",
   "log_sources_ja": "ユーザーアカウント認証 (azure:signinlogs) | アプリケーションログ内容 (NSM:Connections)",
   "tuning": "TimeWindow | GeoIPAllowList",
   "detection_logic_en": "Monitor for excessive or anomalous MFA push notifications or token requests, especially when login attempts originate from unusual IPs or geolocations and do not correspond to legitimate user-initiated sessions."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1621",
   "technique_ja": "多要素認証リクエストの生成",
   "technique_en": "Multi-Factor Authentication Request Generation",
   "analytic_id": "AN0450",
   "detection_strategy_id": "DET0160",
   "analytic_name": "Analytic 0450",
   "platforms": "IaaS",
   "log_sources": "User Account Authentication (AWS:CloudTrail)",
   "log_sources_ja": "ユーザーアカウント認証 (AWS:CloudTrail)",
   "tuning": "FailedLoginThreshold",
   "detection_logic_en": "Detect abnormal MFA activity within cloud service provider logs, such as repeated generation of MFA challenges for the same user session or mismatched MFA device and login origin."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1621",
   "technique_ja": "多要素認証リクエストの生成",
   "technique_en": "Multi-Factor Authentication Request Generation",
   "analytic_id": "AN0451",
   "detection_strategy_id": "DET0160",
   "analytic_name": "Analytic 0451",
   "platforms": "Windows",
   "log_sources": "User Account Authentication (WinEventLog:Security)",
   "log_sources_ja": "ユーザーアカウント認証 (WinEventLog:Security)",
   "tuning": "ServiceAccountExclusion",
   "detection_logic_en": "Detect repeated failed login events followed by MFA challenges triggered in rapid succession, especially if originating from service accounts or anomalous IP addresses."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1621",
   "technique_ja": "多要素認証リクエストの生成",
   "technique_en": "Multi-Factor Authentication Request Generation",
   "analytic_id": "AN0452",
   "detection_strategy_id": "DET0160",
   "analytic_name": "Analytic 0452",
   "platforms": "Linux",
   "log_sources": "User Account Authentication (auditd:AUTH)",
   "log_sources_ja": "ユーザーアカウント認証 (auditd:AUTH)",
   "tuning": "AuthRetryThreshold",
   "detection_logic_en": "Monitor PAM and syslog entries for unusual frequency of login attempts that trigger MFA prompts, particularly when MFA challenges do not match expected user behavior."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1621",
   "technique_ja": "多要素認証リクエストの生成",
   "technique_en": "Multi-Factor Authentication Request Generation",
   "analytic_id": "AN0453",
   "detection_strategy_id": "DET0160",
   "analytic_name": "Analytic 0453",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (saas:okta)",
   "log_sources_ja": "アプリケーションログ内容 (saas:okta)",
   "tuning": "MFAProvider",
   "detection_logic_en": "Detect anomalous OAuth or SSO logins that repeatedly generate MFA challenges, particularly where MFA approvals are denied or timed out by the user."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1621",
   "technique_ja": "多要素認証リクエストの生成",
   "technique_en": "Multi-Factor Authentication Request Generation",
   "analytic_id": "AN0454",
   "detection_strategy_id": "DET0160",
   "analytic_name": "Analytic 0454",
   "platforms": "macOS",
   "log_sources": "Logon Session Metadata (macos:unifiedlog)",
   "log_sources_ja": "ログオンセッションメタデータ (macos:unifiedlog)",
   "tuning": "DeviceEnrollmentStatus",
   "detection_logic_en": "Detect user account logon attempts that trigger multiple MFA challenges through enterprise identity integrations, especially if MFA push requests are generated without successful interactive login."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1649",
   "technique_ja": "認証証明書の窃取/偽造",
   "technique_en": "Steal or Forge Authentication Certificates",
   "analytic_id": "AN0671",
   "detection_strategy_id": "DET0240",
   "analytic_name": "Analytic 0671",
   "platforms": "Windows",
   "log_sources": "Active Directory Credential Request (WinEventLog:Security) | Windows Registry Key Access (WinEventLog:Security)",
   "log_sources_ja": "Active Directory資格情報要求 (WinEventLog:Security) | Windowsレジストリキーアクセス (WinEventLog:Security)",
   "tuning": "EKU_Thresholds | TimeWindow | LogonContext",
   "detection_logic_en": "Monitor for abnormal certificate enrollment and usage activity in Active Directory Certificate Services (AD CS), registry access to certificate storage locations, and unusual process executions that attempt to export or access private keys."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1649",
   "technique_ja": "認証証明書の窃取/偽造",
   "technique_en": "Steal or Forge Authentication Certificates",
   "analytic_id": "AN0672",
   "detection_strategy_id": "DET0240",
   "analytic_name": "Analytic 0672",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Command Execution (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | コマンド実行 (auditd:SYSCALL)",
   "tuning": "PathExclusions | UserContext",
   "detection_logic_en": "Monitor for file access to certificate directories, commands invoking OpenSSL or PKCS#12 utilities to export or modify certificates, and processes accessing sensitive key storage paths."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1649",
   "technique_ja": "認証証明書の窃取/偽造",
   "technique_en": "Steal or Forge Authentication Certificates",
   "analytic_id": "AN0673",
   "detection_strategy_id": "DET0240",
   "analytic_name": "Analytic 0673",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Access (macos:keychain)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイルアクセス (macos:keychain)",
   "tuning": "ApplicationAllowList",
   "detection_logic_en": "Monitor for security commands and API calls interacting with the Keychain, as well as file access attempts to stored certificates and private keys in ~/Library/Keychains or /Library/Keychains."
  },
  {
   "tactic_id": "TA0006",
   "tactic_ja": "認証情報アクセス",
   "technique_id": "T1649",
   "technique_ja": "認証証明書の窃取/偽造",
   "technique_en": "Steal or Forge Authentication Certificates",
   "analytic_id": "AN0674",
   "detection_strategy_id": "DET0240",
   "analytic_name": "Analytic 0674",
   "platforms": "Identity Provider",
   "log_sources": "Active Directory Object Modification (azure:signinlogs) | Application Log Content (m365:unified)",
   "log_sources_ja": "Active Directoryオブジェクト変更 (azure:signinlogs) | アプリケーションログ内容 (m365:unified)",
   "tuning": "GeoContext | Thresholds",
   "detection_logic_en": "Monitor for abnormal certificate enrollment events in identity platforms, unexpected use of token-signing certificates, and unusual CA configuration modifications."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1007",
   "technique_ja": "システムサービスの探索",
   "technique_en": "System Service Discovery",
   "analytic_id": "AN1325",
   "detection_strategy_id": "DET0483",
   "analytic_name": "Analytic 1325",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "ProcessName | CommandLineMatch | ParentProcess",
   "detection_logic_en": "Enumeration of services via native CLI tools (e.g., `sc query`, `tasklist /svc`, `net start`) or API calls via PowerShell and WMI."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1007",
   "technique_ja": "システムサービスの探索",
   "technique_en": "System Service Discovery",
   "analytic_id": "AN1326",
   "detection_strategy_id": "DET0483",
   "analytic_name": "Analytic 1326",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:EXECVE)",
   "log_sources_ja": "プロセス生成 (auditd:EXECVE)",
   "tuning": "CommandPattern | ExecutionUser | TimeWindow",
   "detection_logic_en": "Execution of service management commands like `systemctl list-units`, `service --status-all`, or direct reading of `/etc/init.d`."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1007",
   "technique_ja": "システムサービスの探索",
   "technique_en": "System Service Discovery",
   "analytic_id": "AN1327",
   "detection_strategy_id": "DET0483",
   "analytic_name": "Analytic 1327",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "CommandLineContent | ProcessParent",
   "detection_logic_en": "Discovery via launchctl commands, or process enumeration using `ps aux | grep com.apple.` to identify daemons and services."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1010",
   "technique_ja": "アプリケーションウィンドウの探索",
   "technique_en": "Application Window Discovery",
   "analytic_id": "AN0271",
   "detection_strategy_id": "DET0097",
   "analytic_name": "Analytic 0271",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "AccessedFunction | UserContext | TimeWindow",
   "detection_logic_en": "Processes using Win32 API calls (e.g., EnumWindows, GetForegroundWindow) or scripting tools (e.g., PowerShell, VBScript) to enumerate open windows. These often appear with reconnaissance or data collection TTPs."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1010",
   "technique_ja": "アプリケーションウィンドウの探索",
   "technique_en": "Application Window Discovery",
   "analytic_id": "AN0272",
   "detection_strategy_id": "DET0097",
   "analytic_name": "Analytic 0272",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:EXECVE) | Command Execution (linus:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:EXECVE) | コマンド実行 (linus:syslog)",
   "tuning": "ExecutableName | DisplayContext",
   "detection_logic_en": "Scripted or binary usage of X11 utilities (e.g., xdotool, wmctrl) or direct /proc/*/window mappings to discover open GUI windows and active desktops."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1010",
   "technique_ja": "アプリケーションウィンドウの探索",
   "technique_en": "Application Window Discovery",
   "analytic_id": "AN0273",
   "detection_strategy_id": "DET0097",
   "analytic_name": "Analytic 0273",
   "platforms": "macOS",
   "log_sources": "OS API Execution (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "OS API実行 (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "AppleScriptTarget | ParentProcess",
   "detection_logic_en": "Processes that utilize AppleScript, `CGWindowListCopyWindowInfo`, or `NSRunningApplication` APIs to list active application windows and foreground processes."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1012",
   "technique_ja": "レジストリの照会",
   "technique_en": "Query Registry",
   "analytic_id": "AN0589",
   "detection_strategy_id": "DET0209",
   "analytic_name": "Analytic 0589",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "TargetRegistryPath | ParentProcess | TimeWindow",
   "detection_logic_en": "Registry read access associated with suspicious or non-interactive processes querying system config, installed software, or security settings."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1016",
   "technique_ja": "システムネットワーク構成の探索",
   "technique_en": "System Network Configuration Discovery",
   "analytic_id": "AN0559",
   "detection_strategy_id": "DET0195",
   "analytic_name": "Analytic 0559",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "ParentProcess | UserContext | TimeWindow",
   "detection_logic_en": "Execution of built-in tools (e.g., ipconfig, route, netsh) or PowerShell/WMI queries to enumerate IP, MAC, interface status, or routing configuration."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1016",
   "technique_ja": "システムネットワーク構成の探索",
   "technique_en": "System Network Configuration Discovery",
   "analytic_id": "AN0560",
   "detection_strategy_id": "DET0195",
   "analytic_name": "Analytic 0560",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:EXECVE)",
   "log_sources_ja": "プロセス生成 (auditd:EXECVE)",
   "tuning": "CommandLinePattern | InteractiveShellIndicator",
   "detection_logic_en": "Execution of `ifconfig`, `ip a`, or access to `/proc/net/` indicating collection of local interface and route configuration."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1016",
   "technique_ja": "システムネットワーク構成の探索",
   "technique_en": "System Network Configuration Discovery",
   "analytic_id": "AN0561",
   "detection_strategy_id": "DET0195",
   "analytic_name": "Analytic 0561",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog)",
   "tuning": "ScriptedContext | ExecutionFrequency",
   "detection_logic_en": "Execution of `ifconfig`, `networksetup`, or `system_profiler` to query IP/MAC/interface configuration and status."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1016",
   "technique_ja": "システムネットワーク構成の探索",
   "technique_en": "System Network Configuration Discovery",
   "analytic_id": "AN0562",
   "detection_strategy_id": "DET0195",
   "analytic_name": "Analytic 0562",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:hostd)",
   "log_sources_ja": "コマンド実行 (esxi:hostd)",
   "tuning": "SSHSessionOrigin | esxcliCommandDepth",
   "detection_logic_en": "Use of `esxcli network` commands (e.g., `esxcli network nic list`, `esxcli network ip interface ipv4 get`) via SSH or hostd to enumerate adapter and IP information."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1016",
   "technique_ja": "システムネットワーク構成の探索",
   "technique_en": "System Network Configuration Discovery",
   "analytic_id": "AN0563",
   "detection_strategy_id": "DET0195",
   "analytic_name": "Analytic 0563",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:cli)",
   "log_sources_ja": "コマンド実行 (networkdevice:cli)",
   "tuning": "Username | CommandString | TransportType",
   "detection_logic_en": "CLI-based execution of interface and routing discovery commands (e.g., `show ip interface`, `show arp`, `show route`) over Telnet, SSH, or console."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1016.001",
   "technique_ja": "インターネット接続の探索",
   "technique_en": "Internet Connection Discovery",
   "analytic_id": "AN1015",
   "detection_strategy_id": "DET0357",
   "analytic_name": "Analytic 1015",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | Network Connection Creation (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | ネットワーク接続確立 (WinEventLog:Security)",
   "tuning": "DestinationIP | TimeWindow | UserContext",
   "detection_logic_en": "Execution of utilities (e.g., ping, tracert, Test-NetConnection) or scripted methods to test Internet connectivity by interacting with external IPs/domains."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1016.001",
   "technique_ja": "インターネット接続の探索",
   "technique_en": "Internet Connection Discovery",
   "analytic_id": "AN1016",
   "detection_strategy_id": "DET0357",
   "analytic_name": "Analytic 1016",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:EXECVE) | Network Connection Creation (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:EXECVE) | ネットワーク接続確立 (linux:syslog)",
   "tuning": "DomainPatterns | ProtocolType",
   "detection_logic_en": "Execution of ping, traceroute, or curl/wget against public IPs/domains to verify Internet reachability."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1016.001",
   "technique_ja": "インターネット接続の探索",
   "technique_en": "Internet Connection Discovery",
   "analytic_id": "AN1017",
   "detection_strategy_id": "DET0357",
   "analytic_name": "Analytic 1017",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog)",
   "tuning": "ExecutionFrequency | EnrichmentLevel",
   "detection_logic_en": "Execution of ping, traceroute, or network utility tools to external destinations; may include `scutil` or system_profiler."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1016.001",
   "technique_ja": "インターネット接続の探索",
   "technique_en": "Internet Connection Discovery",
   "analytic_id": "AN1018",
   "detection_strategy_id": "DET0357",
   "analytic_name": "Analytic 1018",
   "platforms": "ESXi",
   "log_sources": "Script Execution (esxi:shell) | Process Creation (esxi:hostd)",
   "log_sources_ja": "スクリプト実行 (esxi:shell) | プロセス生成 (esxi:hostd)",
   "tuning": "SSHSessionOrigin | TargetIP",
   "detection_logic_en": "Execution of `ping`, `vmkping`, or `curl` from shell or through automation jobs/scripts to verify Internet egress."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1016.002",
   "technique_ja": "Wi-Fiの探索",
   "technique_en": "Wi-Fi Discovery",
   "analytic_id": "AN1280",
   "detection_strategy_id": "DET0464",
   "analytic_name": "Analytic 1280",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "WiFiProfileName | ParentProcess | TimeWindow",
   "detection_logic_en": "Enumeration of saved Wi-Fi profiles and cleartext password retrieval using `netsh wlan` or API-level access to `wlanAPI.dll`."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1016.002",
   "technique_ja": "Wi-Fiの探索",
   "technique_en": "Wi-Fi Discovery",
   "analytic_id": "AN1281",
   "detection_strategy_id": "DET0464",
   "analytic_name": "Analytic 1281",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:PATH) | Process Creation (auditd:EXECVE)",
   "log_sources_ja": "ファイルアクセス (auditd:PATH) | プロセス生成 (auditd:EXECVE)",
   "tuning": "FilenamePattern | UserContext",
   "detection_logic_en": "File access to NetworkManager connection configs and attempts to read PSK credentials from `/etc/NetworkManager/system-connections/*`."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1016.002",
   "technique_ja": "Wi-Fiの探索",
   "technique_en": "Wi-Fi Discovery",
   "analytic_id": "AN1282",
   "detection_strategy_id": "DET0464",
   "analytic_name": "Analytic 1282",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog)",
   "tuning": "WiFiNetworkFilter | ExecutionUser",
   "detection_logic_en": "Use of the `security` command or Keychain API to extract known Wi-Fi passwords for target SSIDs."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1018",
   "technique_ja": "リモートシステムの探索",
   "technique_en": "Remote System Discovery",
   "analytic_id": "AN1583",
   "detection_strategy_id": "DET0574",
   "analytic_name": "Analytic 1583",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | CommandLinePattern | ParentProcess",
   "detection_logic_en": "Execution of network enumeration utilities (e.g., net.exe, ping.exe, tracert.exe) in short succession, often chained with lateral movement tools or system enumeration commands."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1018",
   "technique_ja": "リモートシステムの探索",
   "technique_en": "Remote System Discovery",
   "analytic_id": "AN1584",
   "detection_strategy_id": "DET0574",
   "analytic_name": "Analytic 1584",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:EXECVE) | Network Connection Creation (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:EXECVE) | ネットワーク接続確立 (linux:syslog)",
   "tuning": "TargetIPRange | ShellContext",
   "detection_logic_en": "Use of bash scripts or interactive shells to issue sequential ping, arp, or traceroute commands to map remote hosts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1018",
   "technique_ja": "リモートシステムの探索",
   "technique_en": "Remote System Discovery",
   "analytic_id": "AN1585",
   "detection_strategy_id": "DET0574",
   "analytic_name": "Analytic 1585",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Access (macos:osquery)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイルアクセス (macos:osquery)",
   "tuning": "ExecutionUser | CommandSignature",
   "detection_logic_en": "Execution of built-in or AppleScript-based system enumeration via `arp`, `netstat`, `ping`, and discovery of `/etc/hosts` contents."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1018",
   "technique_ja": "リモートシステムの探索",
   "technique_en": "Remote System Discovery",
   "analytic_id": "AN1586",
   "detection_strategy_id": "DET0574",
   "analytic_name": "Analytic 1586",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:hostd)",
   "log_sources_ja": "コマンド実行 (esxi:hostd)",
   "tuning": "ESXCommandPattern | RemoteUserShell",
   "detection_logic_en": "ESXi shell or SSH access issuing `esxcli network diag ping` or viewing routing tables to identify connected hosts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1018",
   "technique_ja": "リモートシステムの探索",
   "technique_en": "Remote System Discovery",
   "analytic_id": "AN1587",
   "detection_strategy_id": "DET0574",
   "analytic_name": "Analytic 1587",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:syslog)",
   "log_sources_ja": "コマンド実行 (networkdevice:syslog)",
   "tuning": "CommandList | PrivLevel",
   "detection_logic_en": "Execution of discovery commands like `show cdp neighbors`, `show arp`, and other interface-level introspection on Cisco or Juniper devices."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1033",
   "technique_ja": "システム所有者/ユーザーの探索",
   "technique_en": "System Owner/User Discovery",
   "analytic_id": "AN0254",
   "detection_strategy_id": "DET0093",
   "analytic_name": "Analytic 0254",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "ParentProcessContext | TimeWindow | UserContext",
   "detection_logic_en": "Adversary launches built-in system tools (e.g., whoami, query user, net user) or scripts that enumerate user account information via local execution or remote API queries (e.g., WMI, PowerShell)."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1033",
   "technique_ja": "システム所有者/ユーザーの探索",
   "technique_en": "System Owner/User Discovery",
   "analytic_id": "AN0255",
   "detection_strategy_id": "DET0093",
   "analytic_name": "Analytic 0255",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL)",
   "tuning": "CommandLineRegex | ShellContext | AccessFrequency",
   "detection_logic_en": "Adversary runs commands like `whoami`, `id`, `w`, or `cat /etc/passwd` from non-interactive or scripting contexts to enumerate system user details."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1033",
   "technique_ja": "システム所有者/ユーザーの探索",
   "technique_en": "System Owner/User Discovery",
   "analytic_id": "AN0256",
   "detection_strategy_id": "DET0093",
   "analytic_name": "Analytic 0256",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Process Creation (macos:endpointsecurity)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | プロセス生成 (macos:endpointsecurity)",
   "tuning": "LaunchAgentPersistence | CommandExecutionPath | UsernameEnumerationPattern",
   "detection_logic_en": "Adversary uses `dscl`, `who`, or environment variables like `$USER` to identify accounts or sessions via Terminal or malicious LaunchAgents."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1033",
   "technique_ja": "システム所有者/ユーザーの探索",
   "technique_en": "System Owner/User Discovery",
   "analytic_id": "AN0257",
   "detection_strategy_id": "DET0093",
   "analytic_name": "Analytic 0257",
   "platforms": "Network Devices",
   "log_sources": "OS API Execution (networkdevice:syslog) | Command Execution (networkdevice:syslog)",
   "log_sources_ja": "OS API実行 (networkdevice:syslog) | コマンド実行 (networkdevice:syslog)",
   "tuning": "CLICommandBaseline | DeviceRoleSensitivity | CommandFrequencyThreshold",
   "detection_logic_en": "Adversary executes CLI commands like `show users`, `show ssh`, or attempts to dump AAA user lists from routers or switches."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1040",
   "technique_ja": "ネットワークスニッフィング",
   "technique_en": "Network Sniffing",
   "analytic_id": "AN0875",
   "detection_strategy_id": "DET0314",
   "analytic_name": "Analytic 0875",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Service Creation (WinEventLog:System)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | サービス作成 (WinEventLog:System)",
   "tuning": "ToolNames | TimeWindow",
   "detection_logic_en": "Detects suspicious execution of network monitoring tools (e.g., Wireshark, tshark, Microsoft Message Analyzer), driver loading indicative of promiscuous mode, or non-admin user privilege escalation to access NICs for capture."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1040",
   "technique_ja": "ネットワークスニッフィング",
   "technique_en": "Network Sniffing",
   "analytic_id": "AN0876",
   "detection_strategy_id": "DET0314",
   "analytic_name": "Analytic 0876",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Command Execution (auditd:SYSCALL) | Network Traffic Content (networkconfig )",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | コマンド実行 (auditd:SYSCALL) | ネットワークトラフィック内容 (networkconfig )",
   "tuning": "InterfaceList | PromiscuousSessionThreshold",
   "detection_logic_en": "Correlates interface mode changes to promiscuous with execution of sniffing tools like tcpdump, tshark, or custom pcap libraries. Detects abnormal NIC configurations and unauthorized sniffing from non-root sessions."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1040",
   "technique_ja": "ネットワークスニッフィング",
   "technique_en": "Network Sniffing",
   "analytic_id": "AN0877",
   "detection_strategy_id": "DET0314",
   "analytic_name": "Analytic 0877",
   "platforms": "macOS",
   "log_sources": "Network Traffic Content (macos:unifiedlog) | Process Creation (macos:osquery) | Command Execution (fs:fsusage)",
   "log_sources_ja": "ネットワークトラフィック内容 (macos:unifiedlog) | プロセス生成 (macos:osquery) | コマンド実行 (fs:fsusage)",
   "tuning": "AllowedTools | UserContext",
   "detection_logic_en": "Detects enabling of interface sniffing via packet capture tools or AppleScript triggering `tcpdump`. Leverages Unified Logs and process lineage to identify suspicious use of `pfctl`, `tcpdump`, or `libpcap` libraries."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1040",
   "technique_ja": "ネットワークスニッフィング",
   "technique_en": "Network Sniffing",
   "analytic_id": "AN0878",
   "detection_strategy_id": "DET0314",
   "analytic_name": "Analytic 0878",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Modification (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス変更 (AWS:CloudTrail)",
   "tuning": "MirrorSourceList | TargetIAMRole",
   "detection_logic_en": "Detects creation of traffic mirroring sessions (e.g., AWS VPC Traffic Mirroring, Azure vTAP) that redirect traffic from critical assets to other virtual instances, often followed by file creation or session establishment."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1040",
   "technique_ja": "ネットワークスニッフィング",
   "technique_en": "Network Sniffing",
   "analytic_id": "AN0879",
   "detection_strategy_id": "DET0314",
   "analytic_name": "Analytic 0879",
   "platforms": "Network Devices",
   "log_sources": "User Account Authentication (networkdevice:syslog) | Command Execution (networkdevice:syslog) | Network Traffic Content (networkdevice:syslog)",
   "log_sources_ja": "ユーザーアカウント認証 (networkdevice:syslog) | コマンド実行 (networkdevice:syslog) | ネットワークトラフィック内容 (networkdevice:syslog)",
   "tuning": "AdminSessionDuration | CaptureCommandList",
   "detection_logic_en": "Detects execution of capture commands via CLI (`monitor capture`, `debug packet`, etc.) or unauthorized CLI access followed by logging configuration changes on Cisco/Juniper/Arista gear."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1046",
   "technique_ja": "ネットワークサービスの探索",
   "technique_en": "Network Service Discovery",
   "analytic_id": "AN1057",
   "detection_strategy_id": "DET0376",
   "analytic_name": "Analytic 1057",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "ScanRateThreshold | KnownScannerExeList | TimeWindow",
   "detection_logic_en": "Detects processes performing network enumeration (e.g., port scans, service probing) by correlating process creation, socket connections, and sequential destination IP probing within a time window."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1046",
   "technique_ja": "ネットワークサービスの探索",
   "technique_en": "Network Service Discovery",
   "analytic_id": "AN1058",
   "detection_strategy_id": "DET0376",
   "analytic_name": "Analytic 1058",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "PortScanThreshold | ToolPatternRegex | ExpectedScanSources",
   "detection_logic_en": "Detects use of network scanning utilities or scripts performing rapid connections to multiple services or hosts using auditd and netflow/pcap telemetry."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1046",
   "technique_ja": "ネットワークサービスの探索",
   "technique_en": "Network Service Discovery",
   "analytic_id": "AN1059",
   "detection_strategy_id": "DET0376",
   "analytic_name": "Analytic 1059",
   "platforms": "macOS",
   "log_sources": "Network Traffic Content (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "ネットワークトラフィック内容 (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "MDNSServiceQueryPatterns | UserContext | ScanToolList",
   "detection_logic_en": "Detects Bonjour-based mDNS enumeration or use of system tools (e.g., dns-sd, nmap) to find active services via multicast probing or targeted scans."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1046",
   "technique_ja": "ネットワークサービスの探索",
   "technique_en": "Network Service Discovery",
   "analytic_id": "AN1060",
   "detection_strategy_id": "DET0376",
   "analytic_name": "Analytic 1060",
   "platforms": "Containers",
   "log_sources": "Network Connection Creation (ebpf:syscalls) | Process Creation (ebpf:syscalls) | Network Traffic Flow (containerd:runtime)",
   "log_sources_ja": "ネットワーク接続確立 (ebpf:syscalls) | プロセス生成 (ebpf:syscalls) | ネットワークトラフィックフロー (containerd:runtime)",
   "tuning": "ExecutablePath | TimeWindow | NetworkDestinationCount",
   "detection_logic_en": "Detects lateral discovery or container breakout attempts using netcat, curl, or custom binaries probing other services within the same namespace or VPC subnet."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1049",
   "technique_ja": "システムネットワーク接続の探索",
   "technique_en": "System Network Connections Discovery",
   "analytic_id": "AN0903",
   "detection_strategy_id": "DET0320",
   "analytic_name": "Analytic 0903",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "SuspiciousParentProcesses | TimeWindow | CommandPatternList",
   "detection_logic_en": "Detects usage of commands or binaries (e.g., netstat, PowerShell Get-NetTCPConnection) and WMI or API calls to enumerate local or remote network connections."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1049",
   "technique_ja": "システムネットワーク接続の探索",
   "technique_en": "System Network Connections Discovery",
   "analytic_id": "AN0904",
   "detection_strategy_id": "DET0320",
   "analytic_name": "Analytic 0904",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Command Execution (linux:cli)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | コマンド実行 (linux:cli)",
   "tuning": "UtilityNameList | UserContextScope | ExecutionFrequencyThreshold",
   "detection_logic_en": "Detects use of netstat, ss, lsof, or custom shell scripts to list current network connections. Often paired with privilege escalation or staging."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1049",
   "technique_ja": "システムネットワーク接続の探索",
   "technique_en": "System Network Connections Discovery",
   "analytic_id": "AN0905",
   "detection_strategy_id": "DET0320",
   "analytic_name": "Analytic 0905",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:osquery)",
   "log_sources_ja": "プロセス生成 (macos:osquery)",
   "tuning": "ShellCommandWatchlist | TerminalBinaryDenylist",
   "detection_logic_en": "Detects shell-based enumeration of active connections using `netstat`, `lsof -i`, or AppleScript-based system discovery."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1049",
   "technique_ja": "システムネットワーク接続の探索",
   "technique_en": "System Network Connections Discovery",
   "analytic_id": "AN0906",
   "detection_strategy_id": "DET0320",
   "analytic_name": "Analytic 0906",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:hostd)",
   "log_sources_ja": "コマンド実行 (esxi:hostd)",
   "tuning": "ExecutionOriginCheck | ExpectedAdminAccessWindow",
   "detection_logic_en": "Detects shell or API usage of `esxcli network ip connection list` or `netstat` to enumerate ESXi host connections."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1049",
   "technique_ja": "システムネットワーク接続の探索",
   "technique_en": "System Network Connections Discovery",
   "analytic_id": "AN0907",
   "detection_strategy_id": "DET0320",
   "analytic_name": "Analytic 0907",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:cli) | OS API Execution (snmp:trap)",
   "log_sources_ja": "コマンド実行 (networkdevice:cli) | OS API実行 (snmp:trap)",
   "tuning": "CommandPatternList | PrivilegedUserCheck",
   "detection_logic_en": "Detects interactive or automated use of CLI commands like `show ip sockets`, `show tcp brief`, or SNMP queries for active sessions on routers/switches."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1049",
   "technique_ja": "システムネットワーク接続の探索",
   "technique_en": "System Network Connections Discovery",
   "analytic_id": "AN0908",
   "detection_strategy_id": "DET0320",
   "analytic_name": "Analytic 0908",
   "platforms": "IaaS",
   "log_sources": "OS API Execution (AWS:CloudTrail) | Network Traffic Content (azure:activity)",
   "log_sources_ja": "OS API実行 (AWS:CloudTrail) | ネットワークトラフィック内容 (azure:activity)",
   "tuning": "ServicePrincipalAllowlist | BurstQueryThreshold",
   "detection_logic_en": "Detects enumeration of cloud network interfaces, VPCs, subnets, or peer connections using CLI or SDKs (e.g., AWS CLI, Azure CLI, GCloud CLI)."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1057",
   "technique_ja": "プロセスの探索",
   "technique_en": "Process Discovery",
   "analytic_id": "AN0095",
   "detection_strategy_id": "DET0034",
   "analytic_name": "Analytic 0095",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "ParentProcessName | CommandLinePattern | TimeWindow",
   "detection_logic_en": "Identifies adversary behavior that launches commands or invokes APIs to enumerate active processes (e.g., tasklist.exe, Get-Process, or CreateToolhelp32Snapshot). Detects execution combined with parent process lineage, network session context, or remote origin."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1057",
   "technique_ja": "プロセスの探索",
   "technique_en": "Process Discovery",
   "analytic_id": "AN0096",
   "detection_strategy_id": "DET0034",
   "analytic_name": "Analytic 0096",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Access (auditd:SYSCALL) | Process Access (linux:osquery)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルアクセス (auditd:SYSCALL) | プロセスアクセス (linux:osquery)",
   "tuning": "AccessedPath | UserContext",
   "detection_logic_en": "Detects execution of common process enumeration utilities (e.g., ps, top, htop) or access to /proc with suspicious ancestry. Correlates command usage with interactive shell context and user role."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1057",
   "technique_ja": "プロセスの探索",
   "technique_en": "Process Discovery",
   "analytic_id": "AN0097",
   "detection_strategy_id": "DET0034",
   "analytic_name": "Analytic 0097",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Process Metadata (macos:osquery)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | プロセスメタデータ (macos:osquery)",
   "tuning": "ParentApp",
   "detection_logic_en": "Monitors execution of ps, top, or launchctl with unusual parent processes or from terminal scripts. Also detects AppleScript-based process listing or `system_profiler SPApplicationsDataType` misuse."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1057",
   "technique_ja": "プロセスの探索",
   "technique_en": "Process Discovery",
   "analytic_id": "AN0098",
   "detection_strategy_id": "DET0034",
   "analytic_name": "Analytic 0098",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:shell) | Process Metadata (esxi:auth)",
   "log_sources_ja": "コマンド実行 (esxi:shell) | プロセスメタデータ (esxi:auth)",
   "tuning": "User",
   "detection_logic_en": "Detects process enumeration using `esxcli system process list` or `ps` on ESXi shell or via unauthorized SSH sessions. Correlates with interactive sessions and abnormal user roles."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1057",
   "technique_ja": "プロセスの探索",
   "technique_en": "Process Discovery",
   "analytic_id": "AN0099",
   "detection_strategy_id": "DET0034",
   "analytic_name": "Analytic 0099",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:cli) | Process Metadata (networkdevice:syslog)",
   "log_sources_ja": "コマンド実行 (networkdevice:cli) | プロセスメタデータ (networkdevice:syslog)",
   "tuning": "Username | CommandString",
   "detection_logic_en": "Monitors CLI-based execution of `show process` or equivalent on routers/switches. Correlates unusual device access, unauthorized roles, or config mode changes."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1069",
   "technique_ja": "権限グループの探索",
   "technique_en": "Permission Groups Discovery",
   "analytic_id": "AN0507",
   "detection_strategy_id": "DET0179",
   "analytic_name": "Analytic 0507",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "CommandLineRegex | TimeWindow | UserContext",
   "detection_logic_en": "Detection of adversary enumeration of domain or local group memberships via native tools such as net.exe, PowerShell, or WMI. This activity may precede lateral movement or privilege escalation."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1069",
   "technique_ja": "権限グループの探索",
   "technique_en": "Permission Groups Discovery",
   "analytic_id": "AN0508",
   "detection_strategy_id": "DET0179",
   "analytic_name": "Analytic 0508",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL)",
   "tuning": "CommandLine | TTYSession",
   "detection_logic_en": "Detection of group enumeration using commands like 'id', 'groups', or 'getent group', often followed by privilege escalation or SSH lateral movement."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1069",
   "technique_ja": "権限グループの探索",
   "technique_en": "Permission Groups Discovery",
   "analytic_id": "AN0509",
   "detection_strategy_id": "DET0179",
   "analytic_name": "Analytic 0509",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog)",
   "tuning": "CommandLine | ParentProcess",
   "detection_logic_en": "Group membership checks via 'dscl', 'dscacheutil', or 'id', typically executed via terminal or automation scripts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1069.001",
   "technique_ja": "ローカルグループ",
   "technique_en": "Local Groups",
   "analytic_id": "AN0317",
   "detection_strategy_id": "DET0114",
   "analytic_name": "Analytic 0317",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security)",
   "tuning": "TimeWindow | UserContext",
   "detection_logic_en": "Detects attempts to enumerate local groups via Net.exe, PowerShell, or native API calls that precede lateral movement or privilege abuse."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1069.001",
   "technique_ja": "ローカルグループ",
   "technique_en": "Local Groups",
   "analytic_id": "AN0318",
   "detection_strategy_id": "DET0114",
   "analytic_name": "Analytic 0318",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL)",
   "tuning": "ProcessName | ParentProcess",
   "detection_logic_en": "Detects enumeration of local groups using common binaries (groups, getent, cat /etc/group) or scripting with suspicious lineage."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1069.001",
   "technique_ja": "ローカルグループ",
   "technique_en": "Local Groups",
   "analytic_id": "AN0319",
   "detection_strategy_id": "DET0114",
   "analytic_name": "Analytic 0319",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog)",
   "tuning": "CommandLineContains | InteractiveSession",
   "detection_logic_en": "Detects use of dscl or id/group commands to enumerate local system groups, often by post-exploitation tools or persistence checks."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1069.002",
   "technique_ja": "ドメイングループ",
   "technique_en": "Domain Groups",
   "analytic_id": "AN1025",
   "detection_strategy_id": "DET0360",
   "analytic_name": "Analytic 1025",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "TimeWindow | UserContext | ProcessLineageDepth",
   "detection_logic_en": "Detection of domain group enumeration through command-line utilities such as 'net group /domain' or PowerShell cmdlets, followed by suspicious access to API calls or LSASS memory."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1069.002",
   "technique_ja": "ドメイングループ",
   "technique_en": "Domain Groups",
   "analytic_id": "AN1026",
   "detection_strategy_id": "DET0360",
   "analytic_name": "Analytic 1026",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Command Execution (linux:syslog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | コマンド実行 (linux:syslog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "LDAPQueryDepth | CommandPattern",
   "detection_logic_en": "Behavioral detection of domain group enumeration via ldapsearch or custom scripts leveraging LDAP over the network."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1069.002",
   "technique_ja": "ドメイングループ",
   "technique_en": "Domain Groups",
   "analytic_id": "AN1027",
   "detection_strategy_id": "DET0360",
   "analytic_name": "Analytic 1027",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog)",
   "tuning": "CommandSignatureThreshold | TimeWindow",
   "detection_logic_en": "Enumeration of domain groups using dscacheutil or dscl commands, often following initial login or domain trust queries."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1069.003",
   "technique_ja": "クラウドグループ",
   "technique_en": "Cloud Groups",
   "analytic_id": "AN0695",
   "detection_strategy_id": "DET0251",
   "analytic_name": "Analytic 0695",
   "platforms": "IaaS",
   "log_sources": "Group Enumeration (AWS:CloudTrail)",
   "log_sources_ja": "グループ列挙 (AWS:CloudTrail)",
   "tuning": "UserContext | TimeWindow",
   "detection_logic_en": "Detects adversarial use of cloud-native APIs (e.g., AWS IAM, Azure RBAC, GCP Identity) to enumerate cloud group memberships or policy mappings via unauthorized sessions or scripts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1069.003",
   "technique_ja": "クラウドグループ",
   "technique_en": "Cloud Groups",
   "analytic_id": "AN0696",
   "detection_strategy_id": "DET0251",
   "analytic_name": "Analytic 0696",
   "platforms": "Office Suite",
   "log_sources": "Command Execution (m365:exchange) | Group Metadata (m365:sharepoint)",
   "log_sources_ja": "コマンド実行 (m365:exchange) | グループメタデータ (m365:sharepoint)",
   "tuning": "AccessScope | ScriptExecutionContext",
   "detection_logic_en": "Identifies unauthorized access or enumeration of administrative roles, security groups, or distribution groups via Exchange/SharePoint/Teams APIs or role discovery scripts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1069.003",
   "technique_ja": "クラウドグループ",
   "technique_en": "Cloud Groups",
   "analytic_id": "AN0697",
   "detection_strategy_id": "DET0251",
   "analytic_name": "Analytic 0697",
   "platforms": "SaaS",
   "log_sources": "Group Enumeration (saas:salesforce)",
   "log_sources_ja": "グループ列挙 (saas:salesforce)",
   "tuning": "OrgScope | RequestRate",
   "detection_logic_en": "Monitors API calls and service-specific logs for enumeration of organizational roles, permissions, and group structure, particularly outside of normal admin behavior baselines."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1082",
   "technique_ja": "システム情報の探索",
   "technique_en": "System Information Discovery",
   "analytic_id": "AN1452",
   "detection_strategy_id": "DET0525",
   "analytic_name": "Analytic 1452",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Command Execution (WinEventLog:PowerShell) | Process Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | コマンド実行 (WinEventLog:PowerShell) | プロセス生成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext",
   "detection_logic_en": "Detection of processes executing system environment inspection operations followed by access to OS configuration APIs or registry locations that expose OS version, architecture, patch level, or hardware characteristics. Defenders observe process execution retrieving system configuration metadata immediately after process startup."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1082",
   "technique_ja": "システム情報の探索",
   "technique_en": "System Information Discovery",
   "analytic_id": "AN1453",
   "detection_strategy_id": "DET0525",
   "analytic_name": "Analytic 1453",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL)",
   "tuning": "CommandList | TerminalSessionID",
   "detection_logic_en": "Execution of system enumeration commands such as `uname`, `df`, `uptime`, `hostname`, `lscpu`, and `cat /etc/os-release` through local terminal or scripts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1082",
   "technique_ja": "システム情報の探索",
   "technique_en": "System Information Discovery",
   "analytic_id": "AN1454",
   "detection_strategy_id": "DET0525",
   "analytic_name": "Analytic 1454",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog)",
   "tuning": "ParentProcess | FrequencyThreshold",
   "detection_logic_en": "Execution of system info utilities like `systemsetup`, `sw_vers`, `uname`, or `sysctl` by terminal or scripted processes."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1082",
   "technique_ja": "システム情報の探索",
   "technique_en": "System Information Discovery",
   "analytic_id": "AN1455",
   "detection_strategy_id": "DET0525",
   "analytic_name": "Analytic 1455",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:vmkernel)",
   "log_sources_ja": "コマンド実行 (esxi:vmkernel)",
   "tuning": "SessionOrigin | CommandString",
   "detection_logic_en": "Execution of `esxcli system hostname get`, `esxcli system version get`, or `esxcli hardware` commands through SSH or local shell."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1082",
   "technique_ja": "システム情報の探索",
   "technique_en": "System Information Discovery",
   "analytic_id": "AN1456",
   "detection_strategy_id": "DET0525",
   "analytic_name": "Analytic 1456",
   "platforms": "IaaS",
   "log_sources": "Instance Enumeration (AWS:CloudTrail)",
   "log_sources_ja": "インスタンス列挙 (AWS:CloudTrail)",
   "tuning": "IAMRoleContext | APIFrequency",
   "detection_logic_en": "Use of cloud API calls (e.g., AWS EC2 DescribeInstances, Azure VM Inventory) to enumerate system configurations across assets."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1082",
   "technique_ja": "システム情報の探索",
   "technique_en": "System Information Discovery",
   "analytic_id": "AN1457",
   "detection_strategy_id": "DET0525",
   "analytic_name": "Analytic 1457",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:syslog)",
   "log_sources_ja": "コマンド実行 (networkdevice:syslog)",
   "tuning": "Username | CommandList",
   "detection_logic_en": "Execution of `show version`, `show hardware`, or `show system` commands through CLI via SSH or console."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1083",
   "technique_ja": "ファイル/ディレクトリの探索",
   "technique_en": "File and Directory Discovery",
   "analytic_id": "AN1040",
   "detection_strategy_id": "DET0370",
   "analytic_name": "Analytic 1040",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "CommandLineRegex | UserContext | TimeWindow",
   "detection_logic_en": "Execution of file enumeration commands (e.g., 'dir', 'tree') from non-standard processes or unusual user contexts, followed by recursive directory traversal or access to sensitive locations."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1083",
   "technique_ja": "ファイル/ディレクトリの探索",
   "technique_en": "File and Directory Discovery",
   "analytic_id": "AN1041",
   "detection_strategy_id": "DET0370",
   "analytic_name": "Analytic 1041",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Access (auditd:PATH)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルアクセス (auditd:PATH)",
   "tuning": "FilePathDepth | UserContext",
   "detection_logic_en": "Use of file enumeration commands (e.g., 'ls', 'find', 'locate') executed by suspicious users or scripts accessing broad file hierarchies or restricted directories."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1083",
   "technique_ja": "ファイル/ディレクトリの探索",
   "technique_en": "File and Directory Discovery",
   "analytic_id": "AN1042",
   "detection_strategy_id": "DET0370",
   "analytic_name": "Analytic 1042",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Access (fs:fsusage)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイルアクセス (fs:fsusage)",
   "tuning": "PredicateScope | TimeWindow",
   "detection_logic_en": "Execution of file or directory discovery commands (e.g., 'ls', 'find') from terminal or script-based tooling, especially outside normal user workflows."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1083",
   "technique_ja": "ファイル/ディレクトリの探索",
   "technique_en": "File and Directory Discovery",
   "analytic_id": "AN1043",
   "detection_strategy_id": "DET0370",
   "analytic_name": "Analytic 1043",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:shell) | File Access (esxi:hostd)",
   "log_sources_ja": "コマンド実行 (esxi:shell) | ファイルアクセス (esxi:hostd)",
   "tuning": "CLICommandPattern | AccessSource",
   "detection_logic_en": "Execution of esxcli commands to enumerate datastore, configuration files, or directory structures by unauthorized or remote users."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1083",
   "technique_ja": "ファイル/ディレクトリの探索",
   "technique_en": "File and Directory Discovery",
   "analytic_id": "AN1044",
   "detection_strategy_id": "DET0370",
   "analytic_name": "Analytic 1044",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:syslog)",
   "log_sources_ja": "コマンド実行 (networkdevice:syslog)",
   "tuning": "CommandWhitelist | SessionOrigin",
   "detection_logic_en": "Execution of file discovery commands (e.g., 'dir', 'show flash', 'nvram:') from CLI interfaces, especially by unauthorized users or from abnormal source IPs."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087",
   "technique_ja": "アカウントの探索",
   "technique_en": "Account Discovery",
   "analytic_id": "AN1612",
   "detection_strategy_id": "DET0587",
   "analytic_name": "Analytic 1612",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Security) | Group Enumeration (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Security) | グループ列挙 (WinEventLog:Security)",
   "tuning": "CommandLinePattern | TimeWindow | UserContext",
   "detection_logic_en": "Detection of processes performing local or domain account enumeration by invoking account directory queries or security APIs followed by structured output of account lists. The defender observes command execution or API invocation patterns that retrieve account information and produce enumeration artifacts shortly afterward."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087",
   "technique_ja": "アカウントの探索",
   "technique_en": "Account Discovery",
   "analytic_id": "AN1613",
   "detection_strategy_id": "DET0587",
   "analytic_name": "Analytic 1613",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Process Creation (linux:Sysmon)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | プロセス生成 (linux:Sysmon)",
   "tuning": "AccessedFile | ParentProcessName",
   "detection_logic_en": "Enumeration of users and groups through suspicious shell commands or unauthorized access to /etc/passwd or /etc/shadow."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087",
   "technique_ja": "アカウントの探索",
   "technique_en": "Account Discovery",
   "analytic_id": "AN1614",
   "detection_strategy_id": "DET0587",
   "analytic_name": "Analytic 1614",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | User Account Metadata (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ユーザーアカウントメタデータ (macos:unifiedlog)",
   "tuning": "CommandLine | ExecutionContext",
   "detection_logic_en": "Detection of account enumeration through directory service queries or system utilities accessing account metadata stores, followed by structured enumeration output."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087",
   "technique_ja": "アカウントの探索",
   "technique_en": "Account Discovery",
   "analytic_id": "AN1615",
   "detection_strategy_id": "DET0587",
   "analytic_name": "Analytic 1615",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Enumeration (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス列挙 (AWS:CloudTrail)",
   "tuning": "API_Method | CallerType",
   "detection_logic_en": "Detection of enumeration of identity entities through cloud provider APIs where principals retrieve account metadata such as IAM users or roles in rapid succession."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087",
   "technique_ja": "アカウントの探索",
   "technique_en": "Account Discovery",
   "analytic_id": "AN1616",
   "detection_strategy_id": "DET0587",
   "analytic_name": "Analytic 1616",
   "platforms": "Identity Provider",
   "log_sources": "Cloud Service Enumeration (azure:signinlogs) | User Account Metadata (saas:okta)",
   "log_sources_ja": "クラウドサービス列挙 (azure:signinlogs) | ユーザーアカウントメタデータ (saas:okta)",
   "tuning": "QueryType | AppContext",
   "detection_logic_en": "Detection of identity directory enumeration through API calls or administrative queries retrieving multiple account objects within a short interval."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087",
   "technique_ja": "アカウントの探索",
   "technique_en": "Account Discovery",
   "analytic_id": "AN1617",
   "detection_strategy_id": "DET0587",
   "analytic_name": "Analytic 1617",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:vpxd)",
   "log_sources_ja": "コマンド実行 (esxi:vpxd)",
   "tuning": "CommandPattern | PrivilegedSession",
   "detection_logic_en": "Detection of enumeration activity when system processes query ESXi host account configuration or management APIs to retrieve user account listings."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087",
   "technique_ja": "アカウントの探索",
   "technique_en": "Account Discovery",
   "analytic_id": "AN1618",
   "detection_strategy_id": "DET0587",
   "analytic_name": "Analytic 1618",
   "platforms": "SaaS",
   "log_sources": "User Account Metadata (gcp:audit)",
   "log_sources_ja": "ユーザーアカウントメタデータ (gcp:audit)",
   "tuning": "EndpointURL | UserAgent",
   "detection_logic_en": "Account enumeration via bulk access to user directory features or hidden APIs."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087",
   "technique_ja": "アカウントの探索",
   "technique_en": "Account Discovery",
   "analytic_id": "AN1619",
   "detection_strategy_id": "DET0587",
   "analytic_name": "Analytic 1619",
   "platforms": "Office Suite",
   "log_sources": "Script Execution (m365:unified)",
   "log_sources_ja": "スクリプト実行 (m365:unified)",
   "tuning": "MacroName | ExecutionScope",
   "detection_logic_en": "Account discovery via VBA macros, COM objects, or embedded scripting."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087.001",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Account",
   "analytic_id": "AN0846",
   "detection_strategy_id": "DET0303",
   "analytic_name": "Analytic 0846",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "CommandLinePattern | UserContext | TimeWindow",
   "detection_logic_en": "Adversary enumeration of local user accounts using Net.exe, WMI, or PowerShell."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087.001",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Account",
   "analytic_id": "AN0847",
   "detection_strategy_id": "DET0303",
   "analytic_name": "Analytic 0847",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:PATH) | Process Creation (linux:Sysmon)",
   "log_sources_ja": "ファイルアクセス (auditd:PATH) | プロセス生成 (linux:Sysmon)",
   "tuning": "AccessedFile | ExecutionScope",
   "detection_logic_en": "Enumeration of local users or groups via file access (/etc/passwd) or commands like id, groups."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087.001",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Account",
   "analytic_id": "AN0848",
   "detection_strategy_id": "DET0303",
   "analytic_name": "Analytic 0848",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog)",
   "tuning": "CommandLine | InteractiveSession",
   "detection_logic_en": "Enumeration of macOS local users using dscl, id, dscacheutil, or /etc/passwd access."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087.001",
   "technique_ja": "ローカルアカウント",
   "technique_en": "Local Account",
   "analytic_id": "AN0849",
   "detection_strategy_id": "DET0303",
   "analytic_name": "Analytic 0849",
   "platforms": "ESXi",
   "log_sources": "User Account Metadata (vpxd.log) | Process Creation (esxi:shell)",
   "log_sources_ja": "ユーザーアカウントメタデータ (vpxd.log) | プロセス生成 (esxi:shell)",
   "tuning": "CommandPattern | SessionType",
   "detection_logic_en": "Enumeration of local ESXi accounts using esxcli or vSphere API from unauthorized sessions."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Account",
   "analytic_id": "AN0363",
   "detection_strategy_id": "DET0129",
   "analytic_name": "Analytic 0363",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "CommandLinePattern | TimeWindow | SourceHost",
   "detection_logic_en": "Adversary enumeration of domain accounts using net.exe, PowerShell, WMI, or LDAP queries from non-domain controllers or non-admin endpoints."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Account",
   "analytic_id": "AN0364",
   "detection_strategy_id": "DET0129",
   "analytic_name": "Analytic 0364",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Command Execution (linuxsyslog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | コマンド実行 (linuxsyslog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ProcessName | LDAPSearchFilter | UserContext",
   "detection_logic_en": "Domain account enumeration using ldapsearch, samba tools (e.g., 'wbinfo -u'), or winbindd lookups."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087.002",
   "technique_ja": "ドメインアカウント",
   "technique_en": "Domain Account",
   "analytic_id": "AN0365",
   "detection_strategy_id": "DET0129",
   "analytic_name": "Analytic 0365",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Command Execution (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | コマンド実行 (macos:unifiedlog)",
   "tuning": "CommandPattern | EndpointRole",
   "detection_logic_en": "Domain group and user enumeration via dscl or dscacheutil, or queries to directory services from non-admin endpoints."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087.003",
   "technique_ja": "メールアカウント",
   "technique_en": "Email Account",
   "analytic_id": "AN0641",
   "detection_strategy_id": "DET0229",
   "analytic_name": "Analytic 0641",
   "platforms": "Windows",
   "log_sources": "Command Execution (WinEventLog:PowerShell) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "コマンド実行 (WinEventLog:PowerShell) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "CommandLinePattern | HostRole | TimeWindow",
   "detection_logic_en": "Enumeration of global address lists or email account metadata via PowerShell cmdlets (e.g., Get-GlobalAddressList) or MAPI/RPC from non-admin, non-mailserver systems."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087.003",
   "technique_ja": "メールアカウント",
   "technique_en": "Email Account",
   "analytic_id": "AN0642",
   "detection_strategy_id": "DET0229",
   "analytic_name": "Analytic 0642",
   "platforms": "Office Suite",
   "log_sources": "User Account Metadata (gcp:audit) | Application Log Content (m365:unified) | User Account Authentication (azure:signinlogs)",
   "log_sources_ja": "ユーザーアカウントメタデータ (gcp:audit) | アプリケーションログ内容 (m365:unified) | ユーザーアカウント認証 (azure:signinlogs)",
   "tuning": "APIQueryVolume | UserContext | AppSource",
   "detection_logic_en": "Suspicious querying of organization-wide directory data via Google Workspace Directory API or Outlook GAL sync in high volume from abnormal users, service accounts, or unknown device contexts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Account",
   "analytic_id": "AN1087",
   "detection_strategy_id": "DET0386",
   "analytic_name": "Analytic 1087",
   "platforms": "Identity Provider",
   "log_sources": "User Account Metadata (Microsoft Entra ID Audit Logs) | User Account Authentication (azure:signinlogs) | Command Execution (m365:defender)",
   "log_sources_ja": "ユーザーアカウントメタデータ (Microsoft Entra ID Audit Logs) | ユーザーアカウント認証 (azure:signinlogs) | コマンド実行 (m365:defender)",
   "tuning": "TokenScope | AppContext | TimeWindow",
   "detection_logic_en": "Enumeration of identity roles and users via API calls such as `Get-MsolRoleMember`, `az ad user list`, or Graph API tokens from unauthorized users or automation accounts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Account",
   "analytic_id": "AN1088",
   "detection_strategy_id": "DET0386",
   "analytic_name": "Analytic 1088",
   "platforms": "IaaS",
   "log_sources": "User Account Authentication (AWS:CloudTrail) | User Account Metadata (azure:activity)",
   "log_sources_ja": "ユーザーアカウント認証 (AWS:CloudTrail) | ユーザーアカウントメタデータ (azure:activity)",
   "tuning": "CallerType | CLIUserAgent | CloudRegion",
   "detection_logic_en": "Use of AWS CLI (`aws iam list-users`, `list-roles`), Azure CLI (`az ad user list`), or GCP CLI (`gcloud iam service-accounts list`) from endpoints or cloud shells where such activity is unexpected."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Account",
   "analytic_id": "AN1089",
   "detection_strategy_id": "DET0386",
   "analytic_name": "Analytic 1089",
   "platforms": "Office Suite",
   "log_sources": "Command Execution (WinEventLog:PowerShell) | User Account Metadata (Microsoft Graph API Logs)",
   "log_sources_ja": "コマンド実行 (WinEventLog:PowerShell) | ユーザーアカウントメタデータ (Microsoft Graph API Logs)",
   "tuning": "CmdletVolume | UserAgent | SessionContext",
   "detection_logic_en": "Bulk enumeration of cloud user email identities through `Get-Recipient`, `Get-Mailbox`, `Get-User`, or Graph API directory listings by abnormal accounts or suspicious sessions."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1087.004",
   "technique_ja": "クラウドアカウント",
   "technique_en": "Cloud Account",
   "analytic_id": "AN1090",
   "detection_strategy_id": "DET0386",
   "analytic_name": "Analytic 1090",
   "platforms": "SaaS",
   "log_sources": "User Account Metadata (Google Admin Audit) | Application Log Content (saas:okta)",
   "log_sources_ja": "ユーザーアカウントメタデータ (Google Admin Audit) | アプリケーションログ内容 (saas:okta)",
   "tuning": "APIRequestRate | AppIntegrationID | GeoContext",
   "detection_logic_en": "Access to organizational directories via Google Workspace Directory API, Slack SCIM, or Okta SCIM by apps or identities outside normal roles."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1120",
   "technique_ja": "周辺デバイスの探索",
   "technique_en": "Peripheral Device Discovery",
   "analytic_id": "AN1353",
   "detection_strategy_id": "DET0491",
   "analytic_name": "Analytic 1353",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "CommandLineRegex | TimeWindow | UserContext",
   "detection_logic_en": "Suspicious enumeration of attached peripherals via WMI, PowerShell, or low-level API calls potentially chained with removable device interactions."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1120",
   "technique_ja": "周辺デバイスの探索",
   "technique_en": "Peripheral Device Discovery",
   "analytic_id": "AN1354",
   "detection_strategy_id": "DET0491",
   "analytic_name": "Analytic 1354",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Access (auditd:SYSCALL) | Drive Access (linux:osquery)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルアクセス (auditd:SYSCALL) | ドライブアクセス (linux:osquery)",
   "tuning": "ExecutableList | UserContext",
   "detection_logic_en": "Enumeration of USB and other peripheral hardware via udevadm, lshw, or /sys or /proc interfaces in proximity to collection or mounting behavior."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1120",
   "technique_ja": "周辺デバイスの探索",
   "technique_en": "Peripheral Device Discovery",
   "analytic_id": "AN1355",
   "detection_strategy_id": "DET0491",
   "analytic_name": "Analytic 1355",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Drive Access (macos:osquery)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ドライブアクセス (macos:osquery)",
   "tuning": "BinaryList | TimeWindow",
   "detection_logic_en": "Execution of system utilities like 'system_profiler' and 'ioreg' to enumerate hardware components or USB devices, particularly if followed by clipboard, file, or network activity."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1124",
   "technique_ja": "システム時刻の探索",
   "technique_en": "System Time Discovery",
   "analytic_id": "AN0430",
   "detection_strategy_id": "DET0151",
   "analytic_name": "Analytic 0430",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Module Load (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | OS API Execution (etw:Microsoft-Windows-Kernel-Process) | Scheduled Job Creation (WinEventLog:TaskScheduler) | Scheduled Job Metadata (WinEventLog:TaskScheduler) | Process Metadata (EDR:Telemetry)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | OS API実行 (etw:Microsoft-Windows-Kernel-Process) | スケジュールジョブ作成 (WinEventLog:TaskScheduler) | スケジュールジョブメタデータ (WinEventLog:TaskScheduler) | プロセスメタデータ (EDR:Telemetry)",
   "tuning": "TimeWindow | AllowedParents | CommandlineKeywordList | UserContextScope | ProcessPrevalenceThreshold",
   "detection_logic_en": "Untrusted or unusual process/script (cmd.exe, powershell.exe, w32tm.exe, net.exe, custom binaries) queries system time/timezone (e.g., w32tm /tz, net time \\\\host, Get-TimeZone, GetTickCount API) and (optionally) is followed within a short window by time-based scheduling or conditional execution (e.g., schtasks /create, at.exe, PowerShell Start-Sleep with large values)."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1124",
   "technique_ja": "システム時刻の探索",
   "technique_en": "System Time Discovery",
   "analytic_id": "AN0431",
   "detection_strategy_id": "DET0151",
   "analytic_name": "Analytic 0431",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | OS API Execution (auditd:SYSCALL) | User Account Authentication (linux:syslog) | Scheduled Job Metadata (linux:cron)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | OS API実行 (auditd:SYSCALL) | ユーザーアカウント認証 (linux:syslog) | スケジュールジョブメタデータ (linux:cron)",
   "tuning": "AuditRulesSyscalls | AllowedBinaries | TimeWindow | UserContextScope",
   "detection_logic_en": "A process (often spawned by a shell, interpreter, or malware implant) executes time discovery via commands (date, timedatectl, hwclock, cat /etc/timezone, /proc/uptime) or direct syscalls (time(), clock_gettime) and is (optionally) followed by scheduled task creation/modification (crontab, at) or conditional sleep logic."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1124",
   "technique_ja": "システム時刻の探索",
   "technique_en": "System Time Discovery",
   "analytic_id": "AN0432",
   "detection_strategy_id": "DET0151",
   "analytic_name": "Analytic 0432",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Scheduled Job Metadata (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | スケジュールジョブメタデータ (macos:unifiedlog)",
   "tuning": "LaunchdPaths | TimeWindow | AllowedCallers",
   "detection_logic_en": "Process/script execution of systemsetup -gettimezone, date, ioreg, or API usage (timeIntervalSinceNow, gettimeofday) followed by time-based scheduling (launchd plist modification) or sleep-based execution."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1124",
   "technique_ja": "システム時刻の探索",
   "technique_en": "System Time Discovery",
   "analytic_id": "AN0433",
   "detection_strategy_id": "DET0151",
   "analytic_name": "Analytic 0433",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:shell) | Process Metadata (esxi:hostd) | Scheduled Job Metadata (esxi:syslog)",
   "log_sources_ja": "コマンド実行 (esxi:shell) | プロセスメタデータ (esxi:hostd) | スケジュールジョブメタデータ (esxi:syslog)",
   "tuning": "MaintenanceWindow | PrivilegedAccountsAllowList | RemoteIPAllowList | TimeWindow",
   "detection_logic_en": "Interactive or remote shell/API invocation of esxcli system clock get or querying time parameters via hostd/vpxa shortly followed by time/ntp configuration checks or scheduled task creation, executed by non-standard accounts or outside maintenance windows."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1124",
   "technique_ja": "システム時刻の探索",
   "technique_en": "System Time Discovery",
   "analytic_id": "AN0434",
   "detection_strategy_id": "DET0151",
   "analytic_name": "Analytic 0434",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:syslog) | File Modification (networkdevice:config)",
   "log_sources_ja": "コマンド実行 (networkdevice:syslog) | ファイル変更 (networkdevice:config)",
   "tuning": "AllowedAdminSubnets | KnownMaintenanceUsers | TimeWindow",
   "detection_logic_en": "Non-standard or rare users/locations issue CLI commands like \"show clock detail\" or \"show timezone\"; optionally followed by configuration of time/timezone or NTP sources. AAA/TACACS+ accounting and syslog correlate execution to identity, source IP, and privilege level."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1135",
   "technique_ja": "ネットワーク共有の探索",
   "technique_en": "Network Share Discovery",
   "analytic_id": "AN0513",
   "detection_strategy_id": "DET0182",
   "analytic_name": "Analytic 0513",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | Named Pipe Metadata (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | OS API Execution (etw:Microsoft-Windows-RPC)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | 名前付きパイプメタデータ (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | OS API実行 (etw:Microsoft-Windows-RPC)",
   "tuning": "BurstHostThreshold | TimeWindow | AllowedDiscoveryAccounts | PipeNameAllowList",
   "detection_logic_en": "Process or script enumerates network shares via CLI (net view/net share, PowerShell Get-SmbShare/WMI) or OS APIs (NetShareEnum/ srvsvc.NetShareEnumAll RPC) → bursts of outbound SMB/RPC connections (445/139, \\\\host\\IPC$ / srvsvc) to many hosts inside a short window → optional follow-on file listing or copy operations."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1135",
   "technique_ja": "ネットワーク共有の探索",
   "technique_en": "Network Share Discovery",
   "analytic_id": "AN0514",
   "detection_strategy_id": "DET0182",
   "analytic_name": "Analytic 0514",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (NSM:Flow) | OS API Execution (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (NSM:Flow) | OS API実行 (NSM:Flow)",
   "tuning": "BurstHostThreshold | TimeWindow | ApprovedInventoryHosts",
   "detection_logic_en": "CLI tools (smbclient -L, smbmap, rpcclient, nmblookup) or custom scripts enumerate SMB shares on many internal hosts → corresponding SMB connections (445/139) captured by Zeek/Netflow within a short window."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1135",
   "technique_ja": "ネットワーク共有の探索",
   "technique_en": "Network Share Discovery",
   "analytic_id": "AN0515",
   "detection_strategy_id": "DET0182",
   "analytic_name": "Analytic 0515",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:endpointsecurity) | Command Execution (macos:unifiedlog) | Network Traffic Flow (NSM:Firewall) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (macos:endpointsecurity) | コマンド実行 (macos:unifiedlog) | ネットワークトラフィックフロー (NSM:Firewall) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "BurstHostThreshold | TimeWindow | AllowedMgmtTools",
   "detection_logic_en": "Use of native/mac tools (sharing -l, smbutil view, mount_smbfs) or scripts to enumerate SMB shares across many hosts, followed by outbound SMB connections observed in PF/Zeek logs."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1201",
   "technique_ja": "パスワードポリシーの探索",
   "technique_en": "Password Policy Discovery",
   "analytic_id": "AN0455",
   "detection_strategy_id": "DET0161",
   "analytic_name": "Analytic 0455",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | Active Directory Object Access (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | Active Directoryオブジェクトアクセス (WinEventLog:Security)",
   "tuning": "TimeWindow | PrivilegedUserAllowList | HostRoleScope | PS_ScriptBlockPatterns",
   "detection_logic_en": "Cause→effect chain: (1) a user or service spawns a shell/PowerShell that queries local/domain password policy via commands/cmdlets (e.g., `net accounts`, `Get-ADDefaultDomainPasswordPolicy`, `secedit /export`); (2) optional directory/LDAP reads from DCs; (3) same principal performs adjacent Discovery or credential-related actions within a short window. Correlate sysmon process creation with PowerShell ScriptBlock and Security logs."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1201",
   "technique_ja": "パスワードポリシーの探索",
   "technique_en": "Password Policy Discovery",
   "analytic_id": "AN0456",
   "detection_strategy_id": "DET0161",
   "analytic_name": "Analytic 0456",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | User Account Metadata (auditd:SYSCALL) | Command Execution (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ユーザーアカウントメタデータ (auditd:SYSCALL) | コマンド実行 (linux:syslog)",
   "tuning": "MonitoredPaths | ServiceAccountsExclude | TerminalType",
   "detection_logic_en": "Chain: (1) interactive/non-interactive `chage -l`, `grep`/`cat` of PAM config (e.g., `/etc/pam.d/common-password`, `/etc/security/pwquality.conf`); (2) optional reads of `/etc/login.defs`; (3) same user performs account enumeration or password change attempts shortly after. Use auditd `execve` and file read events plus shell history collection."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1201",
   "technique_ja": "パスワードポリシーの探索",
   "technique_en": "Password Policy Discovery",
   "analytic_id": "AN0457",
   "detection_strategy_id": "DET0161",
   "analytic_name": "Analytic 0457",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Process Creation (macos:unifiedlog) | User Account Metadata (macos:MDM)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog) | ユーザーアカウントメタデータ (macos:MDM)",
   "tuning": "MDMProfileIDs | AdminConsoleHosts",
   "detection_logic_en": "Chain: (1) execution of `pwpolicy` or MDM/DirectoryService reads of account policies; (2) optional read of `/Library/Preferences/com.apple.loginwindow` or config profiles; (3) follow-on credential probing or lateral movement by same user/session. Use unified logs and process telemetry."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1201",
   "technique_ja": "パスワードポリシーの探索",
   "technique_en": "Password Policy Discovery",
   "analytic_id": "AN0458",
   "detection_strategy_id": "DET0161",
   "analytic_name": "Analytic 0458",
   "platforms": "IaaS",
   "log_sources": "User Account Metadata (AWS:CloudTrail)",
   "log_sources_ja": "ユーザーアカウントメタデータ (AWS:CloudTrail)",
   "tuning": "CloudReadOnlyApps | ApiClientIPAllowList",
   "detection_logic_en": "Chain: (1) cloud API calls that fetch tenant/organization password policy (e.g., AWS `GetAccountPasswordPolicy`, GCP/OCI equivalents or IAM settings reads); (2) within a short window, the same principal creates users, rotates creds, or changes auth settings. Use cloud audit logs."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1201",
   "technique_ja": "パスワードポリシーの探索",
   "technique_en": "Password Policy Discovery",
   "analytic_id": "AN0459",
   "detection_strategy_id": "DET0161",
   "analytic_name": "Analytic 0459",
   "platforms": "Identity Provider",
   "log_sources": "User Account Metadata (azure:audit)",
   "log_sources_ja": "ユーザーアカウントメタデータ (azure:audit)",
   "tuning": "TrustedPartnerAppIds | GeoRiskTolerance",
   "detection_logic_en": "Chain: (1) IdP policy/read operations by a principal (e.g., Microsoft Entra/Graph requests to read password or authentication policies); (2) adjacent risky changes (role assignment, app consent) by same principal. Use IdP audit logs."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1201",
   "technique_ja": "パスワードポリシーの探索",
   "technique_en": "Password Policy Discovery",
   "analytic_id": "AN0460",
   "detection_strategy_id": "DET0161",
   "analytic_name": "Analytic 0460",
   "platforms": "SaaS",
   "log_sources": "User Account Metadata (m365:unified)",
   "log_sources_ja": "ユーザーアカウントメタデータ (m365:unified)",
   "tuning": "SaaSAdminGroup | SessionAnomalyThreshold",
   "detection_logic_en": "Chain: (1) SaaS admin API or PowerShell remote session reads tenant password/authentication settings (e.g., M365 Unified Audit Log ‘Cmdlet’ with `Get-MsolPasswordPolicy`/`Get-OrganizationConfig` parameters that expose password settings); (2) same session proceeds to mailbox or tenant changes."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1201",
   "technique_ja": "パスワードポリシーの探索",
   "technique_en": "Password Policy Discovery",
   "analytic_id": "AN0461",
   "detection_strategy_id": "DET0161",
   "analytic_name": "Analytic 0461",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:syslog)",
   "log_sources_ja": "コマンド実行 (networkdevice:syslog)",
   "tuning": "ApprovedNOCSources | DeviceTier",
   "detection_logic_en": "Chain: (1) privileged CLI sessions run read-only commands that dump AAA/password policies (e.g., `show aaa`, `show password-policy`); (2) same account changes AAA or user DB shortly after. Use network device AAA/command accounting or syslog."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1217",
   "technique_ja": "ブラウザ情報の探索",
   "technique_en": "Browser Information Discovery",
   "analytic_id": "AN0037",
   "detection_strategy_id": "DET0013",
   "analytic_name": "Analytic 0037",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "TargetPathRegex | ParentProcess | ScriptBlockPattern",
   "detection_logic_en": "Access to browser artifact locations (e.g., Chrome, Edge, Firefox) by processes like PowerShell, cmd.exe, or unknown tools, followed by file reads, decoding, or export operations indicating enumeration of bookmarks, autofill, or history databases."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1217",
   "technique_ja": "ブラウザ情報の探索",
   "technique_en": "Browser Information Discovery",
   "analytic_id": "AN0038",
   "detection_strategy_id": "DET0013",
   "analytic_name": "Analytic 0038",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Command Execution (linux:syslog)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | コマンド実行 (linux:syslog)",
   "tuning": "BrowserProfilePath | ShellRegex",
   "detection_logic_en": "Unauthorized shell or script-based access to browser config or SQLite history files, typically in ~/.config/google-chrome/, ~/.mozilla/, or ~/.var/app folders, indicating enumeration of bookmarks or saved credentials."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1217",
   "technique_ja": "ブラウザ情報の探索",
   "technique_en": "Browser Information Discovery",
   "analytic_id": "AN0039",
   "detection_strategy_id": "DET0013",
   "analytic_name": "Analytic 0039",
   "platforms": "macOS",
   "log_sources": "File Access (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "ファイルアクセス (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "BrowserDBPath | NonBrowserProcessList",
   "detection_logic_en": "Scripting or CLI tool access to ~/Library/Application Support/Google/Chrome or ~/Library/Safari bookmarks, cookies, or history databases. Detection relies on unexpected processes accessing or reading from these locations."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1482",
   "technique_ja": "ドメイン信頼関係の探索",
   "technique_en": "Domain Trust Discovery",
   "analytic_id": "AN0016",
   "detection_strategy_id": "DET0007",
   "analytic_name": "Analytic 0016",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | Active Directory Object Access (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | Active Directoryオブジェクトアクセス (WinEventLog:Security)",
   "tuning": "ParentImage | TimeWindow | UserContext | API_Name",
   "detection_logic_en": "Adversary uses nltest, PowerShell, or Win32/.NET API to enumerate domain trust relationships (via DSEnumerateDomainTrusts, GetAllTrustRelationships, or LDAP queries), followed by discovery or authentication staging."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1497",
   "technique_ja": "仮想化/サンドボックス回避",
   "technique_en": "Virtualization/Sandbox Evasion",
   "analytic_id": "AN0127",
   "detection_strategy_id": "DET0046",
   "analytic_name": "Analytic 0127",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | KnownVMArtifactList",
   "detection_logic_en": "Execution of discovery commands or API calls for virtualization artifacts (e.g., registry keys, device drivers, services), sleep/skipped execution behavior, or sandbox evasion DLLs before payload deployment."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1497",
   "technique_ja": "仮想化/サンドボックス回避",
   "technique_en": "Virtualization/Sandbox Evasion",
   "analytic_id": "AN0128",
   "detection_strategy_id": "DET0046",
   "analytic_name": "Analytic 0128",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Command Execution (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | コマンド実行 (auditd:SYSCALL)",
   "tuning": "TimeWindow | CommandArtifactMatchList",
   "detection_logic_en": "Execution of commands to enumerate virtualization-related files or processes (e.g., '/sys/class/dmi/id/product_name', dmesg, lscpu, lspci), or querying hypervisor interfaces prior to malware execution."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1497",
   "technique_ja": "仮想化/サンドボックス回避",
   "technique_en": "Virtualization/Sandbox Evasion",
   "analytic_id": "AN0129",
   "detection_strategy_id": "DET0046",
   "analytic_name": "Analytic 0129",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Module Load (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | モジュール読み込み (macos:unifiedlog)",
   "tuning": "ProcessCommandPattern | SleepThreshold",
   "detection_logic_en": "Execution of scripts or binaries that check for virtualization indicators (e.g., system_profiler, ioreg -l, kextstat), combined with delay functions or anomalous launchd activity."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1497.001",
   "technique_ja": "システムチェック",
   "technique_en": "System Checks",
   "analytic_id": "AN0478",
   "detection_strategy_id": "DET0168",
   "analytic_name": "Analytic 0478",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | ProcessAncestry | UserContext",
   "detection_logic_en": "Script or binary performs a rapid sequence of system discovery checks (e.g., CPU count, RAM size, registry keys, running processes) indicative of VM detection"
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1497.001",
   "technique_ja": "システムチェック",
   "technique_en": "System Checks",
   "analytic_id": "AN0479",
   "detection_strategy_id": "DET0168",
   "analytic_name": "Analytic 0479",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL)",
   "tuning": "TimeWindow | CommandPattern",
   "detection_logic_en": "Shell script or binary uses multiple system commands (e.g., dmidecode, lscpu, lspci) in quick succession to detect virtualization environment"
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1497.001",
   "technique_ja": "システムチェック",
   "technique_en": "System Checks",
   "analytic_id": "AN0480",
   "detection_strategy_id": "DET0168",
   "analytic_name": "Analytic 0480",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog)",
   "tuning": "ExecutionBurst | ToolName",
   "detection_logic_en": "Bash, Swift, or Objective-C programs enumerate system profile, I/O registry, or inspect kernel extensions to identify VM artifacts"
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1497.002",
   "technique_ja": "ユーザー活動ベースのチェック",
   "technique_en": "User Activity Based Checks",
   "analytic_id": "AN1182",
   "detection_strategy_id": "DET0420",
   "analytic_name": "Analytic 1182",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Logon Session Metadata (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | ログオンセッションメタデータ (WinEventLog:Security)",
   "tuning": "TimeWindow | UserContext",
   "detection_logic_en": "Process execution that probes user activity artifacts (e.g., desktop files, registry history) following recent user login/unlock events."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1497.002",
   "technique_ja": "ユーザー活動ベースのチェック",
   "technique_en": "User Activity Based Checks",
   "analytic_id": "AN1183",
   "detection_strategy_id": "DET0420",
   "analytic_name": "Analytic 1183",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Command Execution (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | コマンド実行 (auditd:SYSCALL)",
   "tuning": "ArtifactCountThreshold | KnownToolSignatures",
   "detection_logic_en": "Access to shell history or GUI input state (xdotool, xinput) for presence validation prior to payload execution."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1497.002",
   "technique_ja": "ユーザー活動ベースのチェック",
   "technique_en": "User Activity Based Checks",
   "analytic_id": "AN1184",
   "detection_strategy_id": "DET0420",
   "analytic_name": "Analytic 1184",
   "platforms": "macOS",
   "log_sources": "OS API Execution (macos:unifiedlog) | File Access (macos:unifiedlog)",
   "log_sources_ja": "OS API実行 (macos:unifiedlog) | ファイルアクセス (macos:unifiedlog)",
   "tuning": "TimeWindow | UserContext",
   "detection_logic_en": "API usage or filesystem access revealing user state or browser artifacts (e.g., Safari bookmarks, CGEventState)."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1497.003",
   "technique_ja": "時間ベースのチェック",
   "technique_en": "Time Based Checks",
   "analytic_id": "AN0396",
   "detection_strategy_id": "DET0141",
   "analytic_name": "Analytic 0396",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "SleepDurationThreshold | TimeBetweenExecutionAndNextStage | UserContext",
   "detection_logic_en": "Process creation involving suspicious delays (e.g., Sleep, ping -n loops, WaitForSingleObject), followed by sensitive system access or lateral movement behaviors."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1497.003",
   "technique_ja": "時間ベースのチェック",
   "technique_en": "Time Based Checks",
   "analytic_id": "AN0397",
   "detection_strategy_id": "DET0141",
   "analytic_name": "Analytic 0397",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Metadata (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルメタデータ (auditd:SYSCALL)",
   "tuning": "SleepLoopCount | ExecutionScriptType",
   "detection_logic_en": "Script-based execution of sleep loops or time delay commands (e.g., sleep, ping delay, while-loops) followed by file creation or network connections."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1497.003",
   "technique_ja": "時間ベースのチェック",
   "technique_en": "Time Based Checks",
   "analytic_id": "AN0398",
   "detection_strategy_id": "DET0141",
   "analytic_name": "Analytic 0398",
   "platforms": "macOS",
   "log_sources": "OS API Execution (macos:unifiedlog) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "OS API実行 (macos:unifiedlog) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "AppBundleIdentifier | TimeToNextEvent",
   "detection_logic_en": "Use of `usleep`, `nanosleep`, or `NSTimer` calls in executables or binaries with no GUI interaction, especially followed by disk/network activity."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1518",
   "technique_ja": "ソフトウェアの探索",
   "technique_en": "Software Discovery",
   "analytic_id": "AN1100",
   "detection_strategy_id": "DET0392",
   "analytic_name": "Analytic 1100",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "TimeWindow | ParentProcess",
   "detection_logic_en": "Adversary spawns a process or script to enumerate installed software using WMI, registry, or PowerShell, potentially followed by additional discovery or evasion behavior."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1518",
   "technique_ja": "ソフトウェアの探索",
   "technique_en": "Software Discovery",
   "analytic_id": "AN1101",
   "detection_strategy_id": "DET0392",
   "analytic_name": "Analytic 1101",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Command Execution (linux:shell)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | コマンド実行 (linux:shell)",
   "tuning": "ScriptName | TTYContext",
   "detection_logic_en": "Adversary invokes 'dpkg -l', 'rpm -qa', or other package managers via shell or script to enumerate installed software."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1518",
   "technique_ja": "ソフトウェアの探索",
   "technique_en": "Software Discovery",
   "analytic_id": "AN1102",
   "detection_strategy_id": "DET0392",
   "analytic_name": "Analytic 1102",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Command Execution (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | コマンド実行 (auditd:SYSCALL)",
   "tuning": "AppScope | ProcessGroup",
   "detection_logic_en": "Adversary runs 'system_profiler SPApplicationsDataType' or queries plist files to enumerate software via Terminal or scripts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1518",
   "technique_ja": "ソフトウェアの探索",
   "technique_en": "Software Discovery",
   "analytic_id": "AN1103",
   "detection_strategy_id": "DET0392",
   "analytic_name": "Analytic 1103",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Enumeration (AWS:CloudTrail) | Command Execution (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス列挙 (AWS:CloudTrail) | コマンド実行 (AWS:CloudTrail)",
   "tuning": "UserAgent | InventoryType",
   "detection_logic_en": "Adversary uses cloud-native APIs or CLI (e.g., AWS Systems Manager, Azure Resource Graph) to list installed software on cloud workloads."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1518",
   "technique_ja": "ソフトウェアの探索",
   "technique_en": "Software Discovery",
   "analytic_id": "AN1104",
   "detection_strategy_id": "DET0392",
   "analytic_name": "Analytic 1104",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:shell) | Application Log Content (esxi:hostd)",
   "log_sources_ja": "コマンド実行 (esxi:shell) | アプリケーションログ内容 (esxi:hostd)",
   "tuning": "HostAccessMode | ScriptChain",
   "detection_logic_en": "Adversary uses 'esxcli software vib list' to enumerate installed VIBs, drivers, and modules."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1518.001",
   "technique_ja": "セキュリティソフトウェアの探索",
   "technique_en": "Security Software Discovery",
   "analytic_id": "AN0048",
   "detection_strategy_id": "DET0016",
   "analytic_name": "Analytic 0048",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "ParentProcess | ImagePathContains",
   "detection_logic_en": "Adversary executes commands to enumerate installed antivirus, EDR, or firewall agents using WMI, registry queries, and built-in tools (e.g., tasklist, netsh, sc query). Correlated with elevated process privileges or scripting engine usage."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1518.001",
   "technique_ja": "セキュリティソフトウェアの探索",
   "technique_en": "Security Software Discovery",
   "analytic_id": "AN0049",
   "detection_strategy_id": "DET0016",
   "analytic_name": "Analytic 0049",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL)",
   "tuning": "ExecutableName | TimeWindow",
   "detection_logic_en": "Adversary runs discovery commands such as `ps aux`, `systemctl status`, or `cat /etc/init.d/` to enumerate security software or services. Often occurs alongside privilege escalation or bash script execution."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1518.001",
   "technique_ja": "セキュリティソフトウェアの探索",
   "technique_en": "Security Software Discovery",
   "analytic_id": "AN0050",
   "detection_strategy_id": "DET0016",
   "analytic_name": "Analytic 0050",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "ToolNameMatch",
   "detection_logic_en": "Adversary attempts to detect monitoring agents such as Little Snitch, KnockKnock, or other system daemons via process listing (`ps -e`), application folder checks, and system extension listing."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1518.002",
   "technique_ja": "バックアップソフトウェアの探索",
   "technique_en": "Backup Software Discovery",
   "analytic_id": "AN0240",
   "detection_strategy_id": "DET0088",
   "analytic_name": "Analytic 0240",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "KnownBackupVendors | UserContextScope | SuspiciousParentProcesses",
   "detection_logic_en": "Defender observes execution of commands like `tasklist`, `sc query`, `reg query`, or PowerShell WMI/Registry queries targeting known backup products (e.g., Veeam, Acronis, CrashPlan). Behavior often includes parent-child lineage involving PowerShell or cmd.exe with discovery syntax, and enumeration of services, directories, or registry paths tied to backup software."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1518.002",
   "technique_ja": "バックアップソフトウェアの探索",
   "technique_en": "Backup Software Discovery",
   "analytic_id": "AN0241",
   "detection_strategy_id": "DET0088",
   "analytic_name": "Analytic 0241",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Access (auditd:PATH)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルアクセス (auditd:PATH)",
   "tuning": "BackupConfigPaths | ToolchainScope",
   "detection_logic_en": "Defender observes use of CLI tools (`find`, `grep`, `ls`, `dpkg`, `rpm`, `systemctl`, `ps aux`) to discover backup agents or config files (e.g., rsnapshot, duplicity, veeam). This often includes command lines that recursively search `/etc/`, `/opt/`, or `/var/` directories for keywords like `backup`, and parent-child relationships involving shell or Python scripts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1518.002",
   "technique_ja": "バックアップソフトウェアの探索",
   "technique_en": "Backup Software Discovery",
   "analytic_id": "AN0242",
   "detection_strategy_id": "DET0088",
   "analytic_name": "Analytic 0242",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Access (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイルアクセス (macos:unifiedlog)",
   "tuning": "InstallLocationScope | KnownAppPlistPaths",
   "detection_logic_en": "Defender detects execution of `mdfind`, `launchctl`, or GUI-based enumeration (e.g., `/Applications/Time Machine.app`) along with command-line usage of `find`, `grep`, or `system_profiler` to identify installed backup tools like Time Machine, Carbon Copy Cloner, or Backblaze. Often triggered from Terminal sessions or within post-exploitation scripts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1526",
   "technique_ja": "クラウドサービスの探索",
   "technique_en": "Cloud Service Discovery",
   "analytic_id": "AN1127",
   "detection_strategy_id": "DET0402",
   "analytic_name": "Analytic 1127",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Enumeration (AWS:CloudTrail) | User Account Metadata (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス列挙 (AWS:CloudTrail) | ユーザーアカウントメタデータ (AWS:CloudTrail)",
   "tuning": "EnumerationRateThreshold | UserAgentFilter",
   "detection_logic_en": "Unusual enumeration of services and resources through cloud APIs such as AWS CLI `describe-*`, Azure Resource Manager queries, or GCP project listings. Defender perspective includes anomalous API calls, unexpected volume of service enumeration, and correlation of discovery with recently compromised sessions."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1526",
   "technique_ja": "クラウドサービスの探索",
   "technique_en": "Cloud Service Discovery",
   "analytic_id": "AN1128",
   "detection_strategy_id": "DET0402",
   "analytic_name": "Analytic 1128",
   "platforms": "Identity Provider",
   "log_sources": "Cloud Service Enumeration (azure:audit) | Logon Session Creation (azure:signinlogs)",
   "log_sources_ja": "クラウドサービス列挙 (azure:audit) | ログオンセッション作成 (azure:signinlogs)",
   "tuning": "QueryVolumeThreshold | PrivilegedRoleList",
   "detection_logic_en": "Enumeration of directories, applications, or service principals through APIs such as Microsoft Graph or Okta API. Defender perspective includes unexpected listing of users, roles, applications, and abnormal access to identity management endpoints."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1526",
   "technique_ja": "クラウドサービスの探索",
   "technique_en": "Cloud Service Discovery",
   "analytic_id": "AN1129",
   "detection_strategy_id": "DET0402",
   "analytic_name": "Analytic 1129",
   "platforms": "Office Suite",
   "log_sources": "Cloud Service Enumeration (m365:unified) | Logon Session Creation (m365:signinlogs)",
   "log_sources_ja": "クラウドサービス列挙 (m365:unified) | ログオンセッション作成 (m365:signinlogs)",
   "tuning": "MonitoredAppIntegrations | GeoLocationDeviation",
   "detection_logic_en": "Discovery of SaaS services connected to productivity platforms (e.g., Microsoft 365, Google Workspace). Defender perspective includes unexpected enumeration of enabled services, API integrations, or OAuth applications tied to user accounts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1526",
   "technique_ja": "クラウドサービスの探索",
   "technique_en": "Cloud Service Discovery",
   "analytic_id": "AN1130",
   "detection_strategy_id": "DET0402",
   "analytic_name": "Analytic 1130",
   "platforms": "SaaS",
   "log_sources": "Cloud Service Enumeration (saas:adminapi) | Logon Session Creation (saas:auth)",
   "log_sources_ja": "クラウドサービス列挙 (saas:adminapi) | ログオンセッション作成 (saas:auth)",
   "tuning": "IntegrationDiscoveryThreshold | ServiceAccountScope",
   "detection_logic_en": "Discovery of connected SaaS applications, APIs, or configurations within platforms like Salesforce, Slack, or Zoom. Defender perspective includes enumeration of available integrations, abnormal querying of service metadata, and follow-on attempts to exploit or persist via discovered services."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1538",
   "technique_ja": "クラウドサービスダッシュボード",
   "technique_en": "Cloud Service Dashboard",
   "analytic_id": "AN0808",
   "detection_strategy_id": "DET0291",
   "analytic_name": "Analytic 0808",
   "platforms": "IaaS",
   "log_sources": "Logon Session Creation (AWS:CloudTrail) | Cloud Storage Metadata (AWS:CloudTrail)",
   "log_sources_ja": "ログオンセッション作成 (AWS:CloudTrail) | クラウドストレージメタデータ (AWS:CloudTrail)",
   "tuning": "UserAgentFilter | TimeWindow | PrivilegedSessionThreshold",
   "detection_logic_en": "Detects web console login events followed by read-only or metadata retrieval activity from GUI sources (e.g., browser session, mobile client) rather than API/CLI sources. Correlates across CloudTrail, IAM identity logs, and user-agent context."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1538",
   "technique_ja": "クラウドサービスダッシュボード",
   "technique_en": "Cloud Service Dashboard",
   "analytic_id": "AN0809",
   "detection_strategy_id": "DET0291",
   "analytic_name": "Analytic 0809",
   "platforms": "Identity Provider",
   "log_sources": "User Account Authentication (azure:signinlogs) | Logon Session Creation (saas:okta) | Application Log Content (saas:okta)",
   "log_sources_ja": "ユーザーアカウント認証 (azure:signinlogs) | ログオンセッション作成 (saas:okta) | アプリケーションログ内容 (saas:okta)",
   "tuning": "GeoIPAnomalyThreshold | UserAgentReputation | PrivilegedPageAccess",
   "detection_logic_en": "Detects successful login to cloud identity portals (e.g., Okta, Azure AD, Google Identity) from atypical geolocations, devices, or user agents immediately followed by dashboard/portal navigation to sensitive pages such as user or app configuration."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1538",
   "technique_ja": "クラウドサービスダッシュボード",
   "technique_en": "Cloud Service Dashboard",
   "analytic_id": "AN0810",
   "detection_strategy_id": "DET0291",
   "analytic_name": "Analytic 0810",
   "platforms": "Office Suite",
   "log_sources": "User Account Authentication (m365:signinlogs) | Logon Session Creation (m365:unified) | Application Log Content (m365:unified)",
   "log_sources_ja": "ユーザーアカウント認証 (m365:signinlogs) | ログオンセッション作成 (m365:unified) | アプリケーションログ内容 (m365:unified)",
   "tuning": "AdminRoleList | DashboardNavigationSequence | GeoLocationRisk",
   "detection_logic_en": "Detects login to admin consoles (e.g., Microsoft 365 Admin Center) from unrecognized users, devices, or geolocations followed by non-API data review or configuration read actions that suggest GUI dashboard use."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1538",
   "technique_ja": "クラウドサービスダッシュボード",
   "technique_en": "Cloud Service Dashboard",
   "analytic_id": "AN0811",
   "detection_strategy_id": "DET0291",
   "analytic_name": "Analytic 0811",
   "platforms": "SaaS",
   "log_sources": "Logon Session Creation (saas:zoom) | User Account Authentication (saas:salesforce) | Application Log Content (saas:box)",
   "log_sources_ja": "ログオンセッション作成 (saas:zoom) | ユーザーアカウント認証 (saas:salesforce) | アプリケーションログ内容 (saas:box)",
   "tuning": "SaaSDashboardViewList | IPReputationThreshold | LoginBehaviorBaseline",
   "detection_logic_en": "Detects SaaS web login followed by dashboard or web GUI page views from unfamiliar locations, devices, or access patterns. Identifies use of sensitive reporting or configuration consoles accessed from high-risk accounts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1580",
   "technique_ja": "クラウドインフラの探索",
   "technique_en": "Cloud Infrastructure Discovery",
   "analytic_id": "AN0481",
   "detection_strategy_id": "DET0169",
   "analytic_name": "Analytic 0481",
   "platforms": "IaaS",
   "log_sources": "Instance Metadata (AWS:CloudTrail) | Cloud Storage Enumeration (AWS:CloudTrail) | Instance Enumeration (AWS:CloudTrail)",
   "log_sources_ja": "インスタンスメタデータ (AWS:CloudTrail) | クラウドストレージ列挙 (AWS:CloudTrail) | インスタンス列挙 (AWS:CloudTrail)",
   "tuning": "UserContext | GeoLocation | TimeWindow | APIThreshold",
   "detection_logic_en": "Defenders should monitor for suspicious enumeration of cloud infrastructure components via APIs or CLI tools. Observable behaviors include repeated listing or description operations for compute instances, snapshots, storage buckets, and volumes. From a defender’s perspective, risky activity is often identified by new or untrusted identities making discovery calls (e.g., DescribeInstances, ListBuckets, az vm list, gcloud compute instances list), enumeration from unusual geolocations or IPs, or rapid multi-service discovery in sequence. Correlating discovery API usage with later snapshot creation or instance modification provides further context of adversary behavior."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1613",
   "technique_ja": "コンテナ/リソースの探索",
   "technique_en": "Container and Resource Discovery",
   "analytic_id": "AN1352",
   "detection_strategy_id": "DET0490",
   "analytic_name": "Analytic 1352",
   "platforms": "Containers",
   "log_sources": "Pod Enumeration (kubernetes:apiserver) | Container Enumeration (docker:daemon)",
   "log_sources_ja": "Pod列挙 (kubernetes:apiserver) | コンテナ列挙 (docker:daemon)",
   "tuning": "UserAllowList | TimeWindow | PodQueryThreshold",
   "detection_logic_en": "Detection of adversary attempts to enumerate containers, pods, nodes, and related resources within containerized environments. Defenders may observe anomalous API calls to Docker or Kubernetes (e.g., 'docker ps', 'kubectl get pods', 'kubectl get nodes'), unusual account activity against the Kubernetes dashboard, or unexpected queries against container metadata endpoints. These events should be correlated with user context and network activity to reveal resource discovery attempts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1614",
   "technique_ja": "システム所在地の探索",
   "technique_en": "System Location Discovery",
   "analytic_id": "AN0119",
   "detection_strategy_id": "DET0043",
   "analytic_name": "Analytic 0119",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | OS API Execution (etw:Microsoft-Windows-Kernel-Base)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | OS API実行 (etw:Microsoft-Windows-Kernel-Base)",
   "tuning": "ParentProcessAllowList | TimeWindow",
   "detection_logic_en": "Unusual process or API usage attempting to query system locale, timezone, or keyboard layout (e.g., calls to GetLocaleInfoW, GetTimeZoneInformation). Detection can be enhanced by correlating with processes not typically associated with system configuration queries, such as unknown binaries or scripts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1614",
   "technique_ja": "システム所在地の探索",
   "technique_en": "System Location Discovery",
   "analytic_id": "AN0120",
   "detection_strategy_id": "DET0043",
   "analytic_name": "Analytic 0120",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | Process Creation (linux:Sysmon)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | プロセス生成 (linux:Sysmon)",
   "tuning": "UserContext",
   "detection_logic_en": "Detection of commands accessing locale, timezone, or language settings such as 'locale', 'timedatectl', or parsing /etc/timezone. Anomalous execution by unusual users or automation scripts should be flagged."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1614",
   "technique_ja": "システム所在地の探索",
   "technique_en": "System Location Discovery",
   "analytic_id": "AN0121",
   "detection_strategy_id": "DET0043",
   "analytic_name": "Analytic 0121",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "ExecutionPath",
   "detection_logic_en": "Detection of system calls or commands accessing system locale (e.g., 'defaults read -g AppleLocale', 'systemsetup -gettimezone'). Correlate with unusual parent processes or execution contexts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1614",
   "technique_ja": "システム所在地の探索",
   "technique_en": "System Location Discovery",
   "analytic_id": "AN0122",
   "detection_strategy_id": "DET0043",
   "analytic_name": "Analytic 0122",
   "platforms": "IaaS",
   "log_sources": "OS API Execution (AWS:CloudTrail) | Network Traffic Content (azure:vpcflow)",
   "log_sources_ja": "OS API実行 (AWS:CloudTrail) | ネットワークトラフィック内容 (azure:vpcflow)",
   "tuning": "MetadataQueryAllowList",
   "detection_logic_en": "Detection of queries to instance metadata services (e.g., AWS IMDS, Azure Metadata Service) for availability zone, region, or network geolocation details. Correlation with non-management accounts or non-standard workloads may indicate adversary reconnaissance."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1614.001",
   "technique_ja": "システム言語の探索",
   "technique_en": "System Language Discovery",
   "analytic_id": "AN1561",
   "detection_strategy_id": "DET0565",
   "analytic_name": "Analytic 1561",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Access (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | OS API Execution (ETW)",
   "log_sources_ja": "Windowsレジストリキーアクセス (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | OS API実行 (ETW)",
   "tuning": "ParentProcessAllowList | QueryThreshold",
   "detection_logic_en": "Registry access to system language keys (e.g., HKLM\\SYSTEM\\CurrentControlSet\\Control\\Nls\\Language) or suspicious processes invoking locale-related APIs (e.g., GetUserDefaultUILanguage, GetSystemDefaultUILanguage, GetKeyboardLayoutList). Defender visibility focuses on anomalous or non-standard processes issuing these queries, especially when run by unknown binaries or scripts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1614.001",
   "technique_ja": "システム言語の探索",
   "technique_en": "System Language Discovery",
   "analytic_id": "AN1562",
   "detection_strategy_id": "DET0565",
   "analytic_name": "Analytic 1562",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | Process Creation (linux:Sysmon)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | プロセス生成 (linux:Sysmon)",
   "tuning": "UserContext",
   "detection_logic_en": "Processes executing commands to query system locale and language settings, such as 'locale', 'echo $LANG', or parsing environment variables. Suspicious activity is indicated by these commands being run by unusual users, automation scripts, or non-administrative processes."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1614.001",
   "technique_ja": "システム言語の探索",
   "technique_en": "System Language Discovery",
   "analytic_id": "AN1563",
   "detection_strategy_id": "DET0565",
   "analytic_name": "Analytic 1563",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "ExecutionPath",
   "detection_logic_en": "Execution of commands to query system locale and language settings, such as 'defaults read -g AppleLocale' or 'systemsetup -gettimezone'. Unusual parent processes or execution contexts of these commands may indicate adversarial discovery."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1615",
   "technique_ja": "グループポリシーの探索",
   "technique_en": "Group Policy Discovery",
   "analytic_id": "AN0152",
   "detection_strategy_id": "DET0055",
   "analytic_name": "Analytic 0152",
   "platforms": "Windows",
   "log_sources": "Active Directory Object Access (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "Active Directoryオブジェクトアクセス (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TimeWindow | UserContext | CommandLinePatterns",
   "detection_logic_en": "Detection of adversary attempts to enumerate Group Policy settings through suspicious command execution (gpresult), PowerShell enumeration (Get-DomainGPO, Get-DomainGPOLocalGroup), and abnormal LDAP queries targeting groupPolicyContainer objects. Defenders observe unusual process lineage, script execution, or LDAP filter activity against domain controllers."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1619",
   "technique_ja": "クラウドストレージオブジェクトの探索",
   "technique_en": "Cloud Storage Object Discovery",
   "analytic_id": "AN1594",
   "detection_strategy_id": "DET0578",
   "analytic_name": "Analytic 1594",
   "platforms": "IaaS",
   "log_sources": "Cloud Storage Enumeration (AWS:CloudTrail) | Cloud Storage Access (AWS:CloudTrail)",
   "log_sources_ja": "クラウドストレージ列挙 (AWS:CloudTrail) | クラウドストレージアクセス (AWS:CloudTrail)",
   "tuning": "TimeWindow | UserContext | RegionScope",
   "detection_logic_en": "Detection of suspicious enumeration of cloud storage objects via API calls such as AWS S3 ListObjectsV2, Azure List Blobs, or GCP ListObjects. Correlate access with account role, user context, and prior authentication activity to identify anomalous usage patterns (e.g., unusual account, unexpected regions, or large-scale enumeration in short time windows)."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1622",
   "technique_ja": "デバッガ回避",
   "technique_en": "Debugger Evasion",
   "analytic_id": "AN1045",
   "detection_strategy_id": "DET0371",
   "analytic_name": "Analytic 1045",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | OS API Execution (etw:Microsoft-Windows-Kernel-Process)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | OS API実行 (etw:Microsoft-Windows-Kernel-Process)",
   "tuning": "ApiCallFrequencyThreshold | ProcessAllowList",
   "detection_logic_en": "Monitor for suspicious use of Windows API calls such as IsDebuggerPresent() and NtQueryInformationProcess(), or processes manually checking the BeingDebugged flag in the Process Environment Block (PEB). Detect sequences of OutputDebugStringW() calls in short intervals that may indicate debugger flooding attempts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1622",
   "technique_ja": "デバッガ回避",
   "technique_en": "Debugger Evasion",
   "analytic_id": "AN1046",
   "detection_strategy_id": "DET0371",
   "analytic_name": "Analytic 1046",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL)",
   "tuning": "MonitoredPaths | SyscallThreshold",
   "detection_logic_en": "Monitor access to /proc/self/status where TracerPID field is queried, as this is a common technique for debugger detection. Detect processes that attempt to trigger exceptions intentionally and monitor whether exception handling indicates presence of a debugger."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1622",
   "technique_ja": "デバッガ回避",
   "technique_en": "Debugger Evasion",
   "analytic_id": "AN1047",
   "detection_strategy_id": "DET0371",
   "analytic_name": "Analytic 1047",
   "platforms": "macOS",
   "log_sources": "OS API Execution (macos:unifiedlog)",
   "log_sources_ja": "OS API実行 (macos:unifiedlog)",
   "tuning": "PtraceInvocationThreshold | DevToolExclusionList",
   "detection_logic_en": "Detect suspicious calls to sysctl or ptrace API used to determine if a process is being debugged. Monitor for processes that flood OutputDebugString equivalents or generate abnormal exceptions to evade analysis."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1652",
   "technique_ja": "デバイスドライバの探索",
   "technique_en": "Device Driver Discovery",
   "analytic_id": "AN1595",
   "detection_strategy_id": "DET0579",
   "analytic_name": "Analytic 1595",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "AllowedUtilities | TimeWindow",
   "detection_logic_en": "Monitor for suspicious usage of driver enumeration utilities (driverquery.exe) or API calls such as EnumDeviceDrivers(). Registry queries against HKLM\\SYSTEM\\CurrentControlSet\\Services and HardwareProfiles that are abnormal may also indicate attempts to discover installed drivers and services. Correlate command execution, process creation, and registry access to build a behavioral chain of driver discovery."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1652",
   "technique_ja": "デバイスドライバの探索",
   "technique_en": "Device Driver Discovery",
   "analytic_id": "AN1596",
   "detection_strategy_id": "DET0579",
   "analytic_name": "Analytic 1596",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | File Access (auditd:FS)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ファイルアクセス (auditd:FS)",
   "tuning": "KnownAdminUsers",
   "detection_logic_en": "Detect attempts to enumerate kernel modules through lsmod, modinfo, or inspection of /proc/modules and /dev entries. Focus on unusual execution contexts such as unprivileged users or processes outside expected administrative workflows."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1652",
   "technique_ja": "デバイスドライバの探索",
   "technique_en": "Device Driver Discovery",
   "analytic_id": "AN1597",
   "detection_strategy_id": "DET0579",
   "analytic_name": "Analytic 1597",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Access (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイルアクセス (macos:unifiedlog)",
   "tuning": "AllowedMaintenanceTasks",
   "detection_logic_en": "Detect loading or inspection of kernel extensions (kextstat, kextfind) and file access to /System/Library/Extensions/. Monitor unexpected usage of these utilities by non-administrative users or scripts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1654",
   "technique_ja": "ログの列挙",
   "technique_en": "Log Enumeration",
   "analytic_id": "AN0705",
   "detection_strategy_id": "DET0255",
   "analytic_name": "Analytic 0705",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Access (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイルアクセス (WinEventLog:Security)",
   "tuning": "WhitelistedAdminTools | TimeWindow",
   "detection_logic_en": "Monitor for use of native utilities such as wevtutil.exe or PowerShell cmdlets (Get-WinEvent, Get-EventLog) to enumerate or export logs. Unusual access to security or system event channels, especially by non-administrative users or processes, should be correlated with subsequent file export or network transfer activity."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1654",
   "technique_ja": "ログの列挙",
   "technique_en": "Log Enumeration",
   "analytic_id": "AN0706",
   "detection_strategy_id": "DET0255",
   "analytic_name": "Analytic 0706",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | File Access (auditd:PATH)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ファイルアクセス (auditd:PATH)",
   "tuning": "AdminMaintenanceScripts",
   "detection_logic_en": "Monitor for suspicious use of commands such as cat, less, grep, or journalctl accessing /var/log/ files. Abnormal enumeration of authentication logs (auth.log, secure) or bulk access to multiple logs in short time windows should be flagged."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1654",
   "technique_ja": "ログの列挙",
   "technique_en": "Log Enumeration",
   "analytic_id": "AN0707",
   "detection_strategy_id": "DET0255",
   "analytic_name": "Analytic 0707",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Access (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイルアクセス (macos:unifiedlog)",
   "tuning": "DebugToolsContext",
   "detection_logic_en": "Detect abnormal access to unified logs via log show or fs_usage targeting system log files. Monitor for execution of shell utilities (cat, grep) against /var/log/system.log and for plist modifications enabling verbose logging."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1654",
   "technique_ja": "ログの列挙",
   "technique_en": "Log Enumeration",
   "analytic_id": "AN0708",
   "detection_strategy_id": "DET0255",
   "analytic_name": "Analytic 0708",
   "platforms": "IaaS",
   "log_sources": "Command Execution (AWS:CloudTrail) | File Access (azure:activity)",
   "log_sources_ja": "コマンド実行 (AWS:CloudTrail) | ファイルアクセス (azure:activity)",
   "tuning": "LogExportThreshold",
   "detection_logic_en": "Monitor for cloud API calls that export or collect guest or system logs. Abnormal use of Azure VM Agent’s CollectGuestLogs.exe or AWS CloudWatch GetLogEvents across multiple instances should be correlated with lateral movement or data staging."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1654",
   "technique_ja": "ログの列挙",
   "technique_en": "Log Enumeration",
   "analytic_id": "AN0709",
   "detection_strategy_id": "DET0255",
   "analytic_name": "Analytic 0709",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:shell) | File Access (esxi:hostd)",
   "log_sources_ja": "コマンド実行 (esxi:shell) | ファイルアクセス (esxi:hostd)",
   "tuning": "AdminSessions",
   "detection_logic_en": "Monitor ESXi shell or API access to host logs under /var/log/. Abnormal enumeration of vmkernel.log, hostd.log, or vpxa.log by unauthorized accounts should be flagged."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1673",
   "technique_ja": "仮想マシンの探索",
   "technique_en": "Virtual Machine Discovery",
   "analytic_id": "AN0572",
   "detection_strategy_id": "DET0199",
   "analytic_name": "Analytic 0572",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:shell)",
   "log_sources_ja": "コマンド実行 (esxi:shell)",
   "tuning": "ExpectedAdminUsers | UnexpectedCommandPaths",
   "detection_logic_en": "Monitor for execution of hypervisor management commands such as `esxcli vm process list` or `vim-cmd vmsvc/getallvms` that enumerate virtual machines. Defenders observe unexpected users issuing VM listing commands outside normal administrative workflows."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1673",
   "technique_ja": "仮想マシンの探索",
   "technique_en": "Virtual Machine Discovery",
   "analytic_id": "AN0573",
   "detection_strategy_id": "DET0199",
   "analytic_name": "Analytic 0573",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL)",
   "tuning": "NonRootAccounts | KnownAdminScripts",
   "detection_logic_en": "Detects attempts to enumerate VMs via hypervisor tools like `virsh`, `VBoxManage`, or `qemu-img`. Defender correlates suspicious command invocations with parent process lineage and unexpected users."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1673",
   "technique_ja": "仮想マシンの探索",
   "technique_en": "Virtual Machine Discovery",
   "analytic_id": "AN0574",
   "detection_strategy_id": "DET0199",
   "analytic_name": "Analytic 0574",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security)",
   "tuning": "ExpectedAdminAccounts | RoutineScripts",
   "detection_logic_en": "Detects enumeration of VMs using PowerShell (`Get-VM`), VMware Workstation (`vmrun.exe`), or Hyper-V (`VBoxManage.exe`). Defender observes suspicious command lines executed by unexpected users or outside normal administrative sessions."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1673",
   "technique_ja": "仮想マシンの探索",
   "technique_en": "Virtual Machine Discovery",
   "analytic_id": "AN0575",
   "detection_strategy_id": "DET0199",
   "analytic_name": "Analytic 0575",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog)",
   "tuning": "UserContext | ExecutionTimeWindow",
   "detection_logic_en": "Detects VM enumeration attempts using virtualization utilities such as VirtualBox (`VBoxManage`) or Parallels CLI. Defender observes abnormal invocation of VM listing commands correlated with non-admin users or unusual parent processes."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1680",
   "technique_ja": "ローカルストレージの探索",
   "technique_en": "Local Storage Discovery",
   "analytic_id": "AN0536",
   "detection_strategy_id": "DET0188",
   "analytic_name": "Analytic 0536",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "user_context | parent_process_name",
   "detection_logic_en": "Drive enumeration using PowerShell (`Get-PSDrive`), `wmic logicaldisk`, or Win32 API indicative of local volume enumeration by non-admin users or executed outside of baseline system inventory scripts."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1680",
   "technique_ja": "ローカルストレージの探索",
   "technique_en": "Local Storage Discovery",
   "analytic_id": "AN0537",
   "detection_strategy_id": "DET0188",
   "analytic_name": "Analytic 0537",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Command Execution (auditd:EXECVE)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | コマンド実行 (auditd:EXECVE)",
   "tuning": "TTY_type | shell_parent",
   "detection_logic_en": "Abnormal use of `lsblk`, `fdisk -l`, `lshw -class disk`, or `parted` by non-admin users or within non-interactive shells suggests suspicious disk enumeration activity."
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1680",
   "technique_ja": "ローカルストレージの探索",
   "technique_en": "Local Storage Discovery",
   "analytic_id": "AN0538",
   "detection_strategy_id": "DET0188",
   "analytic_name": "Analytic 0538",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Command Execution (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | コマンド実行 (macos:unifiedlog)",
   "tuning": "launch_agent_context | volume_name_filter",
   "detection_logic_en": "Disk enumeration via `diskutil list` or `system_profiler SPStorageDataType` run outside of user login or not associated with system inventory tools"
  },
  {
   "tactic_id": "TA0007",
   "tactic_ja": "探索",
   "technique_id": "T1680",
   "technique_ja": "ローカルストレージの探索",
   "technique_en": "Local Storage Discovery",
   "analytic_id": "AN0539",
   "detection_strategy_id": "DET0188",
   "analytic_name": "Analytic 0539",
   "platforms": "ESXi",
   "log_sources": "Process Creation (esxi:hostd) | User Account Authentication (esxi:auth)",
   "log_sources_ja": "プロセス生成 (esxi:hostd) | ユーザーアカウント認証 (esxi:auth)",
   "tuning": "ssh_source_ip | esxcli_command_scope",
   "detection_logic_en": "Use of `esxcli storage` or `vim-cmd vmsvc/getallvms` by unusual sessions or through interactive shells unrelated to administrative maintenance tasks."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021",
   "technique_ja": "リモートサービス",
   "technique_en": "Remote Services",
   "analytic_id": "AN0750",
   "detection_strategy_id": "DET0269",
   "analytic_name": "Analytic 0750",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | LogonUser | RemoteHostList",
   "detection_logic_en": "Logon via RDP or WMI by a user account followed by uncommon command execution, file manipulation, or lateral network connections."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021",
   "technique_ja": "リモートサービス",
   "technique_en": "Remote Services",
   "analytic_id": "AN0751",
   "detection_strategy_id": "DET0269",
   "analytic_name": "Analytic 0751",
   "platforms": "Linux",
   "log_sources": "Logon Session Creation (linux:syslog) | Command Execution (auditd:SYSCALL)",
   "log_sources_ja": "ログオンセッション作成 (linux:syslog) | コマンド実行 (auditd:SYSCALL)",
   "tuning": "SourceIP | CommandList",
   "detection_logic_en": "SSH session from new source IP followed by interactive shell or privilege escalation (e.g., sudo, su) and outbound lateral connection."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021",
   "technique_ja": "リモートサービス",
   "technique_en": "Remote Services",
   "analytic_id": "AN0752",
   "detection_strategy_id": "DET0269",
   "analytic_name": "Analytic 0752",
   "platforms": "macOS",
   "log_sources": "Logon Session Creation (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "ログオンセッション作成 (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "RemoteService | TargetedPath",
   "detection_logic_en": "Remote login via ARD or SSH followed by screensharingd process activity or modification of TCC-protected files."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021",
   "technique_ja": "リモートサービス",
   "technique_en": "Remote Services",
   "analytic_id": "AN0753",
   "detection_strategy_id": "DET0269",
   "analytic_name": "Analytic 0753",
   "platforms": "IaaS",
   "log_sources": "Logon Session Creation (AWS:CloudTrail) | Network Connection Creation (AWS:VPCFlowLogs)",
   "log_sources_ja": "ログオンセッション作成 (AWS:CloudTrail) | ネットワーク接続確立 (AWS:VPCFlowLogs)",
   "tuning": "SourceAssetTag | TargetPortList",
   "detection_logic_en": "Use of cloud-based bastion or VM console session followed by commands that initiate outbound SSH or RDP sessions from the cloud instance to other environments."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021",
   "technique_ja": "リモートサービス",
   "technique_en": "Remote Services",
   "analytic_id": "AN0754",
   "detection_strategy_id": "DET0269",
   "analytic_name": "Analytic 0754",
   "platforms": "ESXi",
   "log_sources": "Logon Session Creation (esxi:vmkernel) | Command Execution (esxi:shell)",
   "log_sources_ja": "ログオンセッション作成 (esxi:vmkernel) | コマンド実行 (esxi:shell)",
   "tuning": "SessionType | CommandPattern",
   "detection_logic_en": "vSphere API logins (vimService) or SSH to ESXi host followed by unauthorized shell commands or lateral remote logins from the ESXi host."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021.001",
   "technique_ja": "リモートデスクトッププロトコル",
   "technique_en": "Remote Desktop Protocol",
   "analytic_id": "AN0931",
   "detection_strategy_id": "DET0327",
   "analytic_name": "Analytic 0931",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Logon Session Metadata (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | ログオンセッションメタデータ (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext | ProcessList | HostAccessPatterns",
   "detection_logic_en": "Remote Desktop (RDP) logon by a user followed by unusual process execution, file access, or lateral movement activity within a short timeframe."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021.002",
   "technique_ja": "SMB/Windows管理共有",
   "technique_en": "SMB/Windows Admin Shares",
   "analytic_id": "AN1468",
   "detection_strategy_id": "DET0530",
   "analytic_name": "Analytic 1468",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "ShareName | TimeWindow | UserContext | ProcessList",
   "detection_logic_en": "An SMB-based remote file share access followed by lateral movement actions such as remote service creation, task scheduling, or suspicious process execution on the target host using ADMIN$ or C$ shares."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021.003",
   "technique_ja": "分散COM（DCOM）",
   "technique_en": "Distributed Component Object Model",
   "analytic_id": "AN0791",
   "detection_strategy_id": "DET0285",
   "analytic_name": "Analytic 0791",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext | ProcessName | RemoteHostList",
   "detection_logic_en": "A remote DCOM invocation by a privileged account using RPC (port 135), followed by abnormal process instantiation or module loading on the remote system indicative of code execution."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021.004",
   "technique_ja": "SSH",
   "technique_en": "SSH",
   "analytic_id": "AN1638",
   "detection_strategy_id": "DET0596",
   "analytic_name": "Analytic 1638",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:EXECVE) | Logon Session Creation (linux:syslog) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:EXECVE) | ログオンセッション作成 (linux:syslog) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "TimeWindow | SuspiciousProcessList | UsernameFilter",
   "detection_logic_en": "SSH login from a remote system (via sshd), followed by user context execution of suspicious binaries or privilege escalation behavior."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021.004",
   "technique_ja": "SSH",
   "technique_en": "SSH",
   "analytic_id": "AN1639",
   "detection_strategy_id": "DET0596",
   "analytic_name": "Analytic 1639",
   "platforms": "macOS",
   "log_sources": "Logon Session Metadata (macos:unifiedlog) | Network Traffic Content (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "ログオンセッションメタデータ (macos:unifiedlog) | ネットワークトラフィック内容 (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "TimeWindow | UserContext | CommandLineKeywords",
   "detection_logic_en": "SSH login detected via Unified Logs, followed by unusual process execution, especially outside normal user behavior patterns."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021.004",
   "technique_ja": "SSH",
   "technique_en": "SSH",
   "analytic_id": "AN1640",
   "detection_strategy_id": "DET0596",
   "analytic_name": "Analytic 1640",
   "platforms": "ESXi",
   "log_sources": "Logon Session Metadata (esxi:auth) | Command Execution (esxi:shell) | Network Traffic Flow (esxi:vmkernel)",
   "log_sources_ja": "ログオンセッションメタデータ (esxi:auth) | コマンド実行 (esxi:shell) | ネットワークトラフィックフロー (esxi:vmkernel)",
   "tuning": "AllowedUsers | TimeWindow | CommandList",
   "detection_logic_en": "SSH login via hostd or `/var/log/auth.log`, followed by CLI access to host shell or file manipulation in restricted areas."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021.005",
   "technique_ja": "VNC",
   "technique_en": "VNC",
   "analytic_id": "AN0504",
   "detection_strategy_id": "DET0178",
   "analytic_name": "Analytic 0504",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Logon Session Creation (WinEventLog:Security) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ログオンセッション作成 (WinEventLog:Security) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "TimeWindow | VNCBinaryList | LogonType",
   "detection_logic_en": "Detection of VNC service or executable starting unexpectedly, followed by user session creation and interactive desktop activity (mouse/keyboard simulation)."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021.005",
   "technique_ja": "VNC",
   "technique_en": "VNC",
   "analytic_id": "AN0505",
   "detection_strategy_id": "DET0178",
   "analytic_name": "Analytic 0505",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:EXECVE) | Logon Session Metadata (linux:syslog) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:EXECVE) | ログオンセッションメタデータ (linux:syslog) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "ListeningPort | ProcessNameFilter | UserContext",
   "detection_logic_en": "Spawning of VNC-related processes (e.g., `x11vnc`, `vncserver`) coupled with authentication logs and port listening behavior on TCP 5900."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021.005",
   "technique_ja": "VNC",
   "technique_en": "VNC",
   "analytic_id": "AN0506",
   "detection_strategy_id": "DET0178",
   "analytic_name": "Analytic 0506",
   "platforms": "macOS",
   "log_sources": "Logon Session Creation (macos:unifiedlog) | Process Creation (macos:osquery) | Network Traffic Flow (NSM:firewall)",
   "log_sources_ja": "ログオンセッション作成 (macos:unifiedlog) | プロセス生成 (macos:osquery) | ネットワークトラフィックフロー (NSM:firewall)",
   "tuning": "AuthenticationPredicate | TimeWindow | UserActivitySpike",
   "detection_logic_en": "Detection of VNC-based remote control via `screensharingd` activity in Unified Logs along with concurrent remote login activity or suspicious user interaction."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021.006",
   "technique_ja": "Windowsリモート管理（WinRM）",
   "technique_en": "Windows Remote Management",
   "analytic_id": "AN1313",
   "detection_strategy_id": "DET0477",
   "analytic_name": "Analytic 1313",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Service Metadata (WinEventLog:WinRM) | Network Traffic Flow (NSM:Connections)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | サービスメタデータ (WinEventLog:WinRM) | ネットワークトラフィックフロー (NSM:Connections)",
   "tuning": "TimeWindow | UserContext | CommandLineAnomalyScore | KnownAdminHosts",
   "detection_logic_en": "Adversaries using WinRM to remotely execute commands, launch child processes, or access WMI. The detection chain includes service use, network activity, remote session logon, and process creation within a short temporal window."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021.007",
   "technique_ja": "クラウドサービス",
   "technique_en": "Cloud Services",
   "analytic_id": "AN0017",
   "detection_strategy_id": "DET0008",
   "analytic_name": "Analytic 0017",
   "platforms": "IaaS",
   "log_sources": "Logon Session Creation (AWS:CloudTrail) | Command Execution (gcp:audit)",
   "log_sources_ja": "ログオンセッション作成 (AWS:CloudTrail) | コマンド実行 (gcp:audit)",
   "tuning": "IPGeoRiskScore | UserAgentFingerprint | SessionDuration | CloudResourceScope",
   "detection_logic_en": "Cloud login from atypical geolocation or user-agent string, followed by resource enumeration or infrastructure manipulation using cloud CLI/API"
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021.007",
   "technique_ja": "クラウドサービス",
   "technique_en": "Cloud Services",
   "analytic_id": "AN0018",
   "detection_strategy_id": "DET0008",
   "analytic_name": "Analytic 0018",
   "platforms": "Identity Provider",
   "log_sources": "Logon Session Creation (Okta:SystemLog)",
   "log_sources_ja": "ログオンセッション作成 (Okta:SystemLog)",
   "tuning": "SSOApplicationScope | ClientIDScope | LoginVelocity",
   "detection_logic_en": "Federated login using SSO or OAuth grant to cloud control plane, followed by directory or permissions enumeration"
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021.007",
   "technique_ja": "クラウドサービス",
   "technique_en": "Cloud Services",
   "analytic_id": "AN0019",
   "detection_strategy_id": "DET0008",
   "analytic_name": "Analytic 0019",
   "platforms": "Office Suite",
   "log_sources": "File Access (m365:unified) | Logon Session Creation (m365:unified)",
   "log_sources_ja": "ファイルアクセス (m365:unified) | ログオンセッション作成 (m365:unified)",
   "tuning": "DevicePlatformMismatch | SensitiveDocumentAccessPattern | AccessFrequencyThreshold",
   "detection_logic_en": "Login to M365 or Google Workspace from CLI tools or unexpected source IPs, followed by mailbox or document access"
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021.007",
   "technique_ja": "クラウドサービス",
   "technique_en": "Cloud Services",
   "analytic_id": "AN0020",
   "detection_strategy_id": "DET0008",
   "analytic_name": "Analytic 0020",
   "platforms": "SaaS",
   "log_sources": "Logon Session Creation (saas:auth)",
   "log_sources_ja": "ログオンセッション作成 (saas:auth)",
   "tuning": "OAuthTokenAge | AppScope",
   "detection_logic_en": "Remote access to third-party SaaS with OAuth or API tokens post-initial compromise, followed by sensitive data access or configuration changes"
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1021.008",
   "technique_ja": "クラウドVMへの直接接続",
   "technique_en": "Direct Cloud VM Connections",
   "analytic_id": "AN0594",
   "detection_strategy_id": "DET0211",
   "analytic_name": "Analytic 0594",
   "platforms": "IaaS",
   "log_sources": "Logon Session Creation (AWS:CloudTrail) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッション作成 (AWS:CloudTrail) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | CloudAuthMethod | SessionOriginRegion | TargetInstanceTags",
   "detection_logic_en": "Direct login to cloud-hosted virtual machines via cloud-native access methods (e.g., EC2 Instance Connect, Azure Serial Console, SSM), followed by command execution or privilege escalation on the VM"
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1072",
   "technique_ja": "ソフトウェア展開ツール",
   "technique_en": "Software Deployment Tools",
   "analytic_id": "AN0623",
   "detection_strategy_id": "DET0223",
   "analytic_name": "Analytic 0623",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Application Log Content (WinEventLog:Application)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | アプリケーションログ内容 (WinEventLog:Application)",
   "tuning": "ParentImageList | UserContext | TimeWindow",
   "detection_logic_en": "Detects SCCM, Intune, or remote push execution spawning scripts or binaries from SYSTEM context or unusual consoles (e.g., cmtrace.exe launching PowerShell or cmd.exe)."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1072",
   "technique_ja": "ソフトウェア展開ツール",
   "technique_en": "Software Deployment Tools",
   "analytic_id": "AN0624",
   "detection_strategy_id": "DET0223",
   "analytic_name": "Analytic 0624",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL)",
   "tuning": "DeployingHostAllowList | ScriptExecutionBaseline",
   "detection_logic_en": "Detects remote scripts or binaries deployed via Puppet, Chef, Ansible, or shell scripts from orchestration servers executing outside maintenance windows or in unmanaged nodes."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1072",
   "technique_ja": "ソフトウェア展開ツール",
   "technique_en": "Software Deployment Tools",
   "analytic_id": "AN0625",
   "detection_strategy_id": "DET0223",
   "analytic_name": "Analytic 0625",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Application Log Content (macos:jamf)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | アプリケーションログ内容 (macos:jamf)",
   "tuning": "SigningAuthorityList | RemoteCommandInterval",
   "detection_logic_en": "Detects script or binary execution initiated via JAMF, Munki, or custom MDM agents outside of baseline, or JAMF launching new Terminal or osascript processes from remote command payloads."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1072",
   "technique_ja": "ソフトウェア展開ツール",
   "technique_en": "Software Deployment Tools",
   "analytic_id": "AN0626",
   "detection_strategy_id": "DET0223",
   "analytic_name": "Analytic 0626",
   "platforms": "SaaS",
   "log_sources": "Command Execution (AWS:CloudTrail)",
   "log_sources_ja": "コマンド実行 (AWS:CloudTrail)",
   "tuning": "IAMRoleAllowList | ExecutionTargetList",
   "detection_logic_en": "Detects cloud-native software deployment or management (e.g., SSM Run Command, Intune) initiating script execution on endpoints outside expected org IDs, admin groups, or maintenance windows."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1072",
   "technique_ja": "ソフトウェア展開ツール",
   "technique_en": "Software Deployment Tools",
   "analytic_id": "AN0627",
   "detection_strategy_id": "DET0223",
   "analytic_name": "Analytic 0627",
   "platforms": "Network Devices",
   "log_sources": "Application Log Content (networkdevice:syslog) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (networkdevice:syslog) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "PushSourceAllowList | AuthUserPattern",
   "detection_logic_en": "Detects central router or switch config management tools (e.g., FortiManager, Cisco Prime) triggering device reboots or config pushes using abnormal accounts or IPs."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1080",
   "technique_ja": "共有コンテンツの汚染",
   "technique_en": "Taint Shared Content",
   "analytic_id": "AN1298",
   "detection_strategy_id": "DET0471",
   "analytic_name": "Analytic 1298",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Network Share Access (WinEventLog:Security)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ネットワーク共有アクセス (WinEventLog:Security)",
   "tuning": "SharedPathPrefix | ExecutableExtensions",
   "detection_logic_en": "Detects adversary tampering of shared directories via file drops (e.g., malicious LNK, EXE, VBS) followed by user execution or suspicious network activity."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1080",
   "technique_ja": "共有コンテンツの汚染",
   "technique_en": "Taint Shared Content",
   "analytic_id": "AN1299",
   "detection_strategy_id": "DET0471",
   "analytic_name": "Analytic 1299",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Network Share Access (NSM:Flow)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | ネットワーク共有アクセス (NSM:Flow)",
   "tuning": "MountPath | FilenamePattern",
   "detection_logic_en": "Detects script or binary modification within shared NFS/SMB directories followed by process execution from those paths."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1080",
   "technique_ja": "共有コンテンツの汚染",
   "technique_en": "Taint Shared Content",
   "analytic_id": "AN1300",
   "detection_strategy_id": "DET0471",
   "analytic_name": "Analytic 1300",
   "platforms": "macOS",
   "log_sources": "File Creation (fs:fsevents) | File Modification (macos:unifiedlog)",
   "log_sources_ja": "ファイル作成 (fs:fsevents) | ファイル変更 (macos:unifiedlog)",
   "tuning": "FileExtensionDeception | TargetSharedFolder",
   "detection_logic_en": "Detects modification of shared network folders via .app bundles or scripting files with hidden extensions (e.g., double extensions like docx.app)."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1080",
   "technique_ja": "共有コンテンツの汚染",
   "technique_en": "Taint Shared Content",
   "analytic_id": "AN1301",
   "detection_strategy_id": "DET0471",
   "analytic_name": "Analytic 1301",
   "platforms": "SaaS",
   "log_sources": "File Creation (gcp:workspaceaudit) | Network Share Access (m365:unified)",
   "log_sources_ja": "ファイル作成 (gcp:workspaceaudit) | ネットワーク共有アクセス (m365:unified)",
   "tuning": "UserUploadRateThreshold | MaliciousFileIndicator",
   "detection_logic_en": "Detects upload of malicious or unusual file types into cloud-shared folders, followed by user downloads or interactions."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1080",
   "technique_ja": "共有コンテンツの汚染",
   "technique_en": "Taint Shared Content",
   "analytic_id": "AN1302",
   "detection_strategy_id": "DET0471",
   "analytic_name": "Analytic 1302",
   "platforms": "Office Suite",
   "log_sources": "File Modification (m365:defender)",
   "log_sources_ja": "ファイル変更 (m365:defender)",
   "tuning": "MacroExecutionPolicy | SuspiciousKeywordMatch",
   "detection_logic_en": "Detects embedded macros or scripts added to shared documents or use of external references to execute code."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1091",
   "technique_ja": "リムーバブルメディア経由の複製",
   "technique_en": "Replication Through Removable Media",
   "analytic_id": "AN0841",
   "detection_strategy_id": "DET0301",
   "analytic_name": "Analytic 0841",
   "platforms": "Windows",
   "log_sources": "Drive Creation (WinEventLog:System) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | File Access (WinEventLog:Microsoft-Windows-Windows Defender/Operational)",
   "log_sources_ja": "ドライブ作成 (WinEventLog:System) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Microsoft-Windows-Windows Defender/Operational)",
   "tuning": "DriveLetterMatch | FileExecutionWindow | ParentProcess | FileEntropy",
   "detection_logic_en": "Execution of files originating from removable media after drive mount, with correlation to file write activity, autorun usage, or lateral spread via staged tools."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1210",
   "technique_ja": "リモートサービスの脆弱性悪用",
   "technique_en": "Exploitation of Remote Services",
   "analytic_id": "AN0327",
   "detection_strategy_id": "DET0118",
   "analytic_name": "Analytic 0327",
   "platforms": "Windows",
   "log_sources": "Application Log Content (WinEventLog:System) | Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (WinEventLog:System) | プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ServicePortSet | TimeWindow | AllowedAdminCIDRs | MinConnErrorRate",
   "detection_logic_en": "Correlates inbound network access to remote service ports (e.g., SMB/RPC 445/135, RDP 3389, WinRM 5985/5986) with near-time instability in the target service (crash, abnormal restart), suspicious child process creation under the service, and post-access lateral-movement behaviors. The chain indicates likely exploitation rather than normal administration."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1210",
   "technique_ja": "リモートサービスの脆弱性悪用",
   "technique_en": "Exploitation of Remote Services",
   "analytic_id": "AN0328",
   "detection_strategy_id": "DET0118",
   "analytic_name": "Analytic 0328",
   "platforms": "Linux",
   "log_sources": "Application Log Content (linux:syslog) | Process Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (linux:syslog) | プロセス生成 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ServiceNames | CoreDumpPaths | ShellSpawnAllowlist | TimeWindow",
   "detection_logic_en": "Links inbound network access to SSHD/SMB/NFS/Databases or custom daemons with subsequent daemon crash/restart, core dump, or spawning of shells/reverse shells from the service context, indicating remote exploitation."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1210",
   "technique_ja": "リモートサービスの脆弱性悪用",
   "technique_en": "Exploitation of Remote Services",
   "analytic_id": "AN0329",
   "detection_strategy_id": "DET0118",
   "analytic_name": "Analytic 0329",
   "platforms": "ESXi",
   "log_sources": "Application Log Content (esxi:hostd) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (esxi:hostd) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ESXiServicePorts | MgmtCIDRs | RestartKeywords",
   "detection_logic_en": "Detects exploitation targeting ESXi/vCenter by correlating attempts to reach known exploitable endpoints (OpenSLP 427, CIM 5989, Hostd/Vpxa HTTPS 443, ESXi SOAP) with vmkernel/hostd crashes, unexpected hostd/vpxa restarts, or new reverse/outbound connections from ESXi host/vCenter to internal assets."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1210",
   "technique_ja": "リモートサービスの脆弱性悪用",
   "technique_en": "Exploitation of Remote Services",
   "analytic_id": "AN0330",
   "detection_strategy_id": "DET0118",
   "analytic_name": "Analytic 0330",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | Process Creation (macos:osquery) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | プロセス生成 (macos:osquery) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ServicePortSet | AllowedAdmins | TimeWindow",
   "detection_logic_en": "Ties inbound access to exposed services (ARD/VNC 5900, SSH 22, ScreenSharing, web services) with process crashes in unified logs and abnormal child processes spawned under those services (e.g., bash, curl) to indicate exploitation."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1534",
   "technique_ja": "内部スピアフィッシング",
   "technique_en": "Internal Spearphishing",
   "analytic_id": "AN0147",
   "detection_strategy_id": "DET0054",
   "analytic_name": "Analytic 0147",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | User Account Authentication (WinEventLog:Security) | Logon Session Metadata (WinEventLog:Security) | Application Log Content (m365:unified) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | ユーザーアカウント認証 (WinEventLog:Security) | ログオンセッションメタデータ (WinEventLog:Security) | アプリケーションログ内容 (m365:unified) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext | AttachmentEntropyThreshold",
   "detection_logic_en": "Sequence of internal email sent from a recently compromised user account (preceded by abnormal logon or device activity), with attachments or links leading to execution or credential harvesting. Defender observes: internal mail delivery to peers with high entropy attachments, followed by click events, process initiation, or credential prompts."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1534",
   "technique_ja": "内部スピアフィッシング",
   "technique_en": "Internal Spearphishing",
   "analytic_id": "AN0148",
   "detection_strategy_id": "DET0054",
   "analytic_name": "Analytic 0148",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Application Log Content (Application:Mail) | Network Traffic Content (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | アプリケーションログ内容 (Application:Mail) | ネットワークトラフィック内容 (linux:syslog)",
   "tuning": "SubjectLineAnomaly | AttachmentType",
   "detection_logic_en": "Delivery of suspicious internal communication (e.g., Thunderbird, Evolution) using compromised internal accounts. Sequence of: unexpected user activity + mail transfer logs + download or execution of attachments."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1534",
   "technique_ja": "内部スピアフィッシング",
   "technique_en": "Internal Spearphishing",
   "analytic_id": "AN0149",
   "detection_strategy_id": "DET0054",
   "analytic_name": "Analytic 0149",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Content (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィック内容 (macos:unifiedlog)",
   "tuning": "ExecutionChainDepth | MailScriptFlag",
   "detection_logic_en": "Abnormal Apple Mail use, including internal email relays followed by file execution or script events (e.g., attachments launched via Preview, terminal triggered from Mail.app)"
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1534",
   "technique_ja": "内部スピアフィッシング",
   "technique_en": "Internal Spearphishing",
   "analytic_id": "AN0150",
   "detection_strategy_id": "DET0054",
   "analytic_name": "Analytic 0150",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (saas:slack)",
   "log_sources_ja": "アプリケーションログ内容 (saas:slack)",
   "tuning": "UserAnomalyThreshold | FileRiskScoring",
   "detection_logic_en": "Internal spearphishing via SaaS applications (e.g., Slack, Teams, Gmail): message sent from compromised user with attachment or URL, followed by click and credential access behavior."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1534",
   "technique_ja": "内部スピアフィッシング",
   "technique_en": "Internal Spearphishing",
   "analytic_id": "AN0151",
   "detection_strategy_id": "DET0054",
   "analytic_name": "Analytic 0151",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified) | Command Execution (WinEventLog:Security)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | コマンド実行 (WinEventLog:Security)",
   "tuning": "MacroExecutionWindow | AttachmentNameHeuristics",
   "detection_logic_en": "Outlook or Word used to forward suspicious internal attachments with macro content. Defender observes attachment forwarding, auto-opening behaviors, or macro prompt interactions."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1550",
   "technique_ja": "代替認証材料の使用",
   "technique_en": "Use Alternate Authentication Material",
   "analytic_id": "AN0954",
   "detection_strategy_id": "DET0338",
   "analytic_name": "Analytic 0954",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext",
   "detection_logic_en": "Use of stolen Kerberos tickets or token impersonation resulting in logon sessions from accounts without expected interactive logon events."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1550",
   "technique_ja": "代替認証材料の使用",
   "technique_en": "Use Alternate Authentication Material",
   "analytic_id": "AN0955",
   "detection_strategy_id": "DET0338",
   "analytic_name": "Analytic 0955",
   "platforms": "Linux",
   "log_sources": "User Account Authentication (auditd:SYSCALL) | Logon Session Creation (NSM:Connections)",
   "log_sources_ja": "ユーザーアカウント認証 (auditd:SYSCALL) | ログオンセッション作成 (NSM:Connections)",
   "tuning": "SourceIPWhitelist | AuthMethod",
   "detection_logic_en": "Access tokens or SSH keys used without corresponding login shell or PAM module activity, particularly for remote execution."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1550",
   "technique_ja": "代替認証材料の使用",
   "technique_en": "Use Alternate Authentication Material",
   "analytic_id": "AN0956",
   "detection_strategy_id": "DET0338",
   "analytic_name": "Analytic 0956",
   "platforms": "Identity Provider",
   "log_sources": "Web Credential Usage (azure:signinlogs) | User Account Authentication (m365:unified)",
   "log_sources_ja": "Web資格情報の使用 (azure:signinlogs) | ユーザーアカウント認証 (m365:unified)",
   "tuning": "MFAContextRequired | RefreshTokenReuseThreshold",
   "detection_logic_en": "Token replay or impersonation in federated logins without interactive browser session or MFA prompts."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1550",
   "technique_ja": "代替認証材料の使用",
   "technique_en": "Use Alternate Authentication Material",
   "analytic_id": "AN0957",
   "detection_strategy_id": "DET0338",
   "analytic_name": "Analytic 0957",
   "platforms": "SaaS",
   "log_sources": "Web Credential Usage (saas:googleworkspace) | User Account Authentication (saas:googleworkspace)",
   "log_sources_ja": "Web資格情報の使用 (saas:googleworkspace) | ユーザーアカウント認証 (saas:googleworkspace)",
   "tuning": "GeoIPDistanceThreshold",
   "detection_logic_en": "Unusual reuse of OAuth access tokens from different geographic regions, without full login events."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1550",
   "technique_ja": "代替認証材料の使用",
   "technique_en": "Use Alternate Authentication Material",
   "analytic_id": "AN0958",
   "detection_strategy_id": "DET0338",
   "analytic_name": "Analytic 0958",
   "platforms": "Containers",
   "log_sources": "Application Log Content (docker:runtime) | User Account Metadata (AWS:CloudTrail)",
   "log_sources_ja": "アプリケーションログ内容 (docker:runtime) | ユーザーアカウントメタデータ (AWS:CloudTrail)",
   "tuning": "ContainerLabel | CredentialPath",
   "detection_logic_en": "Container process uses mounted cloud credentials or token cache to authenticate without known orchestration."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1550",
   "technique_ja": "代替認証材料の使用",
   "technique_en": "Use Alternate Authentication Material",
   "analytic_id": "AN0959",
   "detection_strategy_id": "DET0338",
   "analytic_name": "Analytic 0959",
   "platforms": "Office Suite",
   "log_sources": "Web Credential Usage (m365:unified)",
   "log_sources_ja": "Web資格情報の使用 (m365:unified)",
   "tuning": "UserAgentCheck",
   "detection_logic_en": "Access token reuse to connect to SharePoint or Outlook APIs without interactive user context."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1550",
   "technique_ja": "代替認証材料の使用",
   "technique_en": "Use Alternate Authentication Material",
   "analytic_id": "AN0960",
   "detection_strategy_id": "DET0338",
   "analytic_name": "Analytic 0960",
   "platforms": "IaaS",
   "log_sources": "Web Credential Usage (AWS:CloudTrail) | User Account Metadata (AWS:CloudTrail)",
   "log_sources_ja": "Web資格情報の使用 (AWS:CloudTrail) | ユーザーアカウントメタデータ (AWS:CloudTrail)",
   "tuning": "TokenReuseWindow | RoleMismatchAlerting",
   "detection_logic_en": "Use of instance metadata tokens across instances or misuse of short-lived tokens issued for different roles."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1550.001",
   "technique_ja": "アプリケーションアクセストークン",
   "technique_en": "Application Access Token",
   "analytic_id": "AN0526",
   "detection_strategy_id": "DET0185",
   "analytic_name": "Analytic 0526",
   "platforms": "IaaS",
   "log_sources": "Web Credential Usage (AWS:CloudTrail) | User Account Authentication (AWS:CloudTrail)",
   "log_sources_ja": "Web資格情報の使用 (AWS:CloudTrail) | ユーザーアカウント認証 (AWS:CloudTrail)",
   "tuning": "GeoIPDistanceThreshold | RoleScope",
   "detection_logic_en": "Use of AWS STS or GCP IAM APIs to request temporary tokens or federation sessions inconsistent with normal account activity, including from unexpected principals or regions."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1550.001",
   "technique_ja": "アプリケーションアクセストークン",
   "technique_en": "Application Access Token",
   "analytic_id": "AN0527",
   "detection_strategy_id": "DET0185",
   "analytic_name": "Analytic 0527",
   "platforms": "Identity Provider",
   "log_sources": "Web Credential Usage (azure:signinlogs) | User Account Authentication (m365:unified)",
   "log_sources_ja": "Web資格情報の使用 (azure:signinlogs) | ユーザーアカウント認証 (m365:unified)",
   "tuning": "MFAEnforcement | TokenReuseWindow",
   "detection_logic_en": "OAuth or SAML access tokens reused across multiple sessions or clients without corresponding MFA or login activity."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1550.001",
   "technique_ja": "アプリケーションアクセストークン",
   "technique_en": "Application Access Token",
   "analytic_id": "AN0528",
   "detection_strategy_id": "DET0185",
   "analytic_name": "Analytic 0528",
   "platforms": "SaaS",
   "log_sources": "Web Credential Usage (saas:googleworkspace) | User Account Authentication (saas:salesforce)",
   "log_sources_ja": "Web資格情報の使用 (saas:googleworkspace) | ユーザーアカウント認証 (saas:salesforce)",
   "tuning": "ApplicationScopeAllowlist | TokenLifetime",
   "detection_logic_en": "Application access tokens used to call APIs (e.g., Google Workspace, Salesforce) without interactive logins, often with unusual scopes or elevated permissions."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1550.001",
   "technique_ja": "アプリケーションアクセストークン",
   "technique_en": "Application Access Token",
   "analytic_id": "AN0529",
   "detection_strategy_id": "DET0185",
   "analytic_name": "Analytic 0529",
   "platforms": "Office Suite",
   "log_sources": "Web Credential Usage (m365:unified)",
   "log_sources_ja": "Web資格情報の使用 (m365:unified)",
   "tuning": "ClientAppIDWhitelist",
   "detection_logic_en": "OAuth token usage for Exchange Online or SharePoint API access without preceding login or from unauthorized clients."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1550.001",
   "technique_ja": "アプリケーションアクセストークン",
   "technique_en": "Application Access Token",
   "analytic_id": "AN0530",
   "detection_strategy_id": "DET0185",
   "analytic_name": "Analytic 0530",
   "platforms": "Containers",
   "log_sources": "Web Credential Usage (kubernetes:apiserver) | User Account Authentication (AWS:CloudTrail)",
   "log_sources_ja": "Web資格情報の使用 (kubernetes:apiserver) | ユーザーアカウント認証 (AWS:CloudTrail)",
   "tuning": "NamespaceScope",
   "detection_logic_en": "Compromised service account tokens mounted inside containers and reused for external API calls or lateral movement across services."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1550.002",
   "technique_ja": "パス・ザ・ハッシュ",
   "technique_en": "Pass the Hash",
   "analytic_id": "AN1144",
   "detection_strategy_id": "DET0409",
   "analytic_name": "Analytic 1144",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Active Directory Credential Request (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | Active Directory資格情報要求 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | SourceAccountAnomalyThreshold | LogonTypeFilter",
   "detection_logic_en": "Detects anomalous NTLM LogonType 3 authentications that occur without accompanying domain logon events, especially from lateral systems or involving built-in administrative tools. Monitors for mismatches between source user context and system being accessed. Correlates LogonSession creation, NTLM authentications, and process/service initiation to identify suspicious use of stolen password hashes for remote access or service logon without password entry. Detects overpass-the-hash by combining Kerberos ticket issuance with NTLM-based lateral movement."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1550.003",
   "technique_ja": "パス・ザ・チケット",
   "technique_en": "Pass the Ticket",
   "analytic_id": "AN1000",
   "detection_strategy_id": "DET0352",
   "analytic_name": "Analytic 1000",
   "platforms": "Windows",
   "log_sources": "User Account Authentication (WinEventLog:Security) | Active Directory Credential Request (WinEventLog:Security) | Logon Session Creation (WinEventLog:Security) | Process Access (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "ユーザーアカウント認証 (WinEventLog:Security) | Active Directory資格情報要求 (WinEventLog:Security) | ログオンセッション作成 (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | HostContextScope | LSASSAccessAnomalyThreshold",
   "detection_logic_en": "Detects unauthorized Kerberos ticket injection by correlating service ticket (TGS - 4769) requests with absent corresponding account logons (4624) and prior Ticket Granting Ticket (TGT - 4768) activity. Highlights anomalous service ticket generation chains involving unexpected users, hosts, or times, and suspicious injection of tickets via mimikatz-like tooling into LSASS memory. Behavior also includes network lateral movement using Kerberos authentication absent expected interactive logon patterns."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1550.004",
   "technique_ja": "Webセッションクッキー",
   "technique_en": "Web Session Cookie",
   "analytic_id": "AN0201",
   "detection_strategy_id": "DET0074",
   "analytic_name": "Analytic 0201",
   "platforms": "IaaS",
   "log_sources": "Web Credential Usage (AWS:CloudTrail) | Logon Session Creation (AWS:CloudTrail)",
   "log_sources_ja": "Web資格情報の使用 (AWS:CloudTrail) | ログオンセッション作成 (AWS:CloudTrail)",
   "tuning": "TimeWindow | IPGeolocationDistance",
   "detection_logic_en": "Anomalous access to cloud web applications using session tokens without corresponding MFA/credential validation, often from unusual locations or device fingerprints."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1550.004",
   "technique_ja": "Webセッションクッキー",
   "technique_en": "Web Session Cookie",
   "analytic_id": "AN0202",
   "detection_strategy_id": "DET0074",
   "analytic_name": "Analytic 0202",
   "platforms": "SaaS",
   "log_sources": "Web Credential Usage (m365:unified) | User Account Authentication (saas:okta)",
   "log_sources_ja": "Web資格情報の使用 (m365:unified) | ユーザーアカウント認証 (saas:okta)",
   "tuning": "BrowserFingerprintMatch | SessionReuseTimeout",
   "detection_logic_en": "Session cookie reuse on unmanaged browsers, devices, or client types deviating from user baseline (e.g., switching from Chrome to curl)."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1550.004",
   "technique_ja": "Webセッションクッキー",
   "technique_en": "Web Session Cookie",
   "analytic_id": "AN0203",
   "detection_strategy_id": "DET0074",
   "analytic_name": "Analytic 0203",
   "platforms": "Office Suite",
   "log_sources": "Logon Session Creation (m365:unified)",
   "log_sources_ja": "ログオンセッション作成 (m365:unified)",
   "tuning": "EndpointTokenSyncGap",
   "detection_logic_en": "Web session tokens reused in native Office apps (e.g., Outlook, Teams) without associated token refresh or login behavior on the endpoint."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1563",
   "technique_ja": "リモートサービスセッションの乗っ取り",
   "technique_en": "Remote Service Session Hijacking",
   "analytic_id": "AN0216",
   "detection_strategy_id": "DET0079",
   "analytic_name": "Analytic 0216",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "ExpectedUserSessionMap | TimeWindow",
   "detection_logic_en": "Detection of anomalous RDP or remote service session activity where a logon session is hijacked rather than newly created. Indicators include mismatched user credentials vs. active session tokens, service session takeovers without corresponding successful logon events, or RDP shadowing activity without user consent."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1563",
   "technique_ja": "リモートサービスセッションの乗っ取り",
   "technique_en": "Remote Service Session Hijacking",
   "analytic_id": "AN0217",
   "detection_strategy_id": "DET0079",
   "analytic_name": "Analytic 0217",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | Logon Session Creation (NSM:Connections) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ログオンセッション作成 (NSM:Connections) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "MonitoredServicePorts",
   "detection_logic_en": "Detection of SSH/Telnet session hijacking via discrepancies between authentication logs and active session tables. Adversary behavior includes reusing or stealing active PTY sessions, attaching to screen/tmux, or issuing commands without corresponding login events."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1563",
   "technique_ja": "リモートサービスセッションの乗っ取り",
   "technique_en": "Remote Service Session Hijacking",
   "analytic_id": "AN0218",
   "detection_strategy_id": "DET0079",
   "analytic_name": "Analytic 0218",
   "platforms": "macOS",
   "log_sources": "Logon Session Creation (macos:unifiedlog) | Process Creation (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ログオンセッション作成 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "SessionIdleThreshold",
   "detection_logic_en": "Detection of hijacked VNC or SSH sessions on macOS where adversaries take over an existing session rather than authenticating directly. Indicators include process execution from active sessions without new logon events, manipulation of TTY sessions, or anomalous network activity tied to dormant sessions."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1563.001",
   "technique_ja": "SSHハイジャック",
   "technique_en": "SSH Hijacking",
   "analytic_id": "AN0710",
   "detection_strategy_id": "DET0256",
   "analytic_name": "Analytic 0710",
   "platforms": "Linux",
   "log_sources": "Network Connection Creation (auditd:SYSCALL) | Process Creation (auditd:EXECVE) | Logon Session Creation (NSM:Connections)",
   "log_sources_ja": "ネットワーク接続確立 (auditd:SYSCALL) | プロセス生成 (auditd:EXECVE) | ログオンセッション作成 (NSM:Connections)",
   "tuning": "UserContext | TimeWindow",
   "detection_logic_en": "Suspicious reuse of SSH agent sockets across multiple users or processes, anomalous access to ~/.ssh/ or /tmp/ssh-* sockets, and abnormal patterns of lateral movement via SSH without new authentication events. Defender view: detect when one process accesses another user's SSH agent or when an existing SSH connection is used to pivot unexpectedly."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1563.001",
   "technique_ja": "SSHハイジャック",
   "technique_en": "SSH Hijacking",
   "analytic_id": "AN0711",
   "detection_strategy_id": "DET0256",
   "analytic_name": "Analytic 0711",
   "platforms": "macOS",
   "log_sources": "Process Metadata (macos:unifiedlog) | Process Creation (macos:unifiedlog) | Logon Session Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセスメタデータ (macos:unifiedlog) | プロセス生成 (macos:unifiedlog) | ログオンセッション作成 (macos:unifiedlog)",
   "tuning": "SocketPathScope | BaselineUsers",
   "detection_logic_en": "Unusual access to SSH agent sockets in /tmp/ or /private/tmp, process access to another user’s $SSH_AUTH_SOCK, and lateral SSH activity without corresponding login events. Defender view: correlation of socket access with anomalous network flows to internal systems."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1563.002",
   "technique_ja": "RDPハイジャック",
   "technique_en": "RDP Hijacking",
   "analytic_id": "AN1620",
   "detection_strategy_id": "DET0588",
   "analytic_name": "Analytic 1620",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Service Creation (WinEventLog:System)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | サービス作成 (WinEventLog:System)",
   "tuning": "ExpectedRDPHosts | TimeWindow | SessionIDMapping",
   "detection_logic_en": "Detection of suspicious use of `tscon.exe` or equivalent methods to hijack legitimate RDP sessions. Defenders can observe anomalies such as session reassignments without corresponding authentication, processes spawned in the context of hijacked sessions, or unusual RDP network traffic flows that deviate from expected baselines."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1570",
   "technique_ja": "横展開ツール転送",
   "technique_en": "Lateral Tool Transfer",
   "analytic_id": "AN0516",
   "detection_strategy_id": "DET0183",
   "analytic_name": "Analytic 0516",
   "platforms": "Windows",
   "log_sources": "Network Share Access (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワーク共有アクセス (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext | FilePathWhitelist",
   "detection_logic_en": "Correlate suspicious file transfers over SMB or Admin$ shares with process creation events (e.g., cmd.exe, powershell.exe, certutil.exe) that do not align with normal administrative behavior. Detect remote file writes followed by execution of transferred binaries."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1570",
   "technique_ja": "横展開ツール転送",
   "technique_en": "Lateral Tool Transfer",
   "analytic_id": "AN0517",
   "detection_strategy_id": "DET0183",
   "analytic_name": "Analytic 0517",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | File Creation (auditd:FILE)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ファイル作成 (auditd:FILE)",
   "tuning": "AllowedTools | DestinationDirectories",
   "detection_logic_en": "Monitor scp, rsync, curl, sftp, or ftp processes initiating transfers to internal systems combined with file creation events in unusual directories. Correlate transfer activity with subsequent execution of those binaries."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1570",
   "technique_ja": "横展開ツール転送",
   "technique_en": "Lateral Tool Transfer",
   "analytic_id": "AN0518",
   "detection_strategy_id": "DET0183",
   "analytic_name": "Analytic 0518",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:unifiedlog)",
   "tuning": "SyncApplications | EntropyThreshold",
   "detection_logic_en": "Detect anomalous use of scp, rsync, curl, or third-party sync apps transferring executables into user directories. Correlate new file creation with immediate execution events."
  },
  {
   "tactic_id": "TA0008",
   "tactic_ja": "横展開",
   "technique_id": "T1570",
   "technique_ja": "横展開ツール転送",
   "technique_en": "Lateral Tool Transfer",
   "analytic_id": "AN0519",
   "detection_strategy_id": "DET0183",
   "analytic_name": "Analytic 0519",
   "platforms": "ESXi",
   "log_sources": "File Metadata (esxi:vmkernel) | Command Execution (esxi:hostd)",
   "log_sources_ja": "ファイルメタデータ (esxi:vmkernel) | コマンド実行 (esxi:hostd)",
   "tuning": "DatastoreWhitelist | TransferProtocol",
   "detection_logic_en": "Identify lateral transfer via datastore file uploads or internal scp/ssh sessions that result in new VMX/VMDK or script files. Correlate transfer with VM execution or datastore modification."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1005",
   "technique_ja": "ローカルシステムからのデータ",
   "technique_en": "Data from Local System",
   "analytic_id": "AN1070",
   "detection_strategy_id": "DET0380",
   "analytic_name": "Analytic 1070",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "TargetFilePathRegex | ParentProcessFilter",
   "detection_logic_en": "Adversaries collecting local files via PowerShell, WMI, or direct file API calls often include recursive file listings, targeted file reads, and temporary file staging."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1005",
   "technique_ja": "ローカルシステムからのデータ",
   "technique_en": "Data from Local System",
   "analytic_id": "AN1071",
   "detection_strategy_id": "DET0380",
   "analytic_name": "Analytic 1071",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "TimeWindow | ScriptToolName",
   "detection_logic_en": "Adversaries using bash scripts or tools to recursively enumerate user home directories, config files, or SSH keys."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1005",
   "technique_ja": "ローカルシステムからのデータ",
   "technique_en": "Data from Local System",
   "analytic_id": "AN1072",
   "detection_strategy_id": "DET0380",
   "analytic_name": "Analytic 1072",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Access (fs:fsusage)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイルアクセス (fs:fsusage)",
   "tuning": "UserContext | TargetVolume",
   "detection_logic_en": "Adversary use of bash/zsh or AppleScript to locate files and exfil targets like user keychains or documents."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1005",
   "technique_ja": "ローカルシステムからのデータ",
   "technique_en": "Data from Local System",
   "analytic_id": "AN1073",
   "detection_strategy_id": "DET0380",
   "analytic_name": "Analytic 1073",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:cli)",
   "log_sources_ja": "コマンド実行 (networkdevice:cli)",
   "tuning": "CommandScope | AuthenticatedUserList",
   "detection_logic_en": "Collection of device configuration via CLI commands (e.g., `show running-config`, `copy flash`, `more`), often followed by TFTP/SCP transfers."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1005",
   "technique_ja": "ローカルシステムからのデータ",
   "technique_en": "Data from Local System",
   "analytic_id": "AN1074",
   "detection_strategy_id": "DET0380",
   "analytic_name": "Analytic 1074",
   "platforms": "ESXi",
   "log_sources": "File Access (esxis:vmkernel) | Command Execution (esxi:hostd)",
   "log_sources_ja": "ファイルアクセス (esxis:vmkernel) | コマンド実行 (esxi:hostd)",
   "tuning": "AccessPathRegex | InteractiveShellUsage",
   "detection_logic_en": "Adversaries accessing datastore or configuration files via `vim-cmd`, `esxcli`, or SCP to extract logs, VMs, or host configurations."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1025",
   "technique_ja": "リムーバブルメディアからのデータ",
   "technique_en": "Data from Removable Media",
   "analytic_id": "AN1410",
   "detection_strategy_id": "DET0511",
   "analytic_name": "Analytic 1410",
   "platforms": "Windows",
   "log_sources": "File Access (WinEventLog:Security) | Drive Creation (WinEventLog:System) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイルアクセス (WinEventLog:Security) | ドライブ作成 (WinEventLog:System) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "VolumeLabel | TimeWindow | TargetFileType",
   "detection_logic_en": "Adversary mounts a USB device and begins enumerating, copying, or compressing files using scripting engines, cmd, or remote access tools."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1025",
   "technique_ja": "リムーバブルメディアからのデータ",
   "technique_en": "Data from Removable Media",
   "analytic_id": "AN1411",
   "detection_strategy_id": "DET0511",
   "analytic_name": "Analytic 1411",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Drive Creation (journald:systemd) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | ドライブ作成 (journald:systemd) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "MountPathRegex | AccessMask",
   "detection_logic_en": "Adversary mounts external drive to /media or /mnt then accesses or copies targeted data via shell, cp, or tar."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1025",
   "technique_ja": "リムーバブルメディアからのデータ",
   "technique_en": "Data from Removable Media",
   "analytic_id": "AN1412",
   "detection_strategy_id": "DET0511",
   "analytic_name": "Analytic 1412",
   "platforms": "macOS",
   "log_sources": "Drive Creation (macos:unifiedlog) | File Access (fs:fsusage) | Process Creation (macos:osquery)",
   "log_sources_ja": "ドライブ作成 (macos:unifiedlog) | ファイルアクセス (fs:fsusage) | プロセス生成 (macos:osquery)",
   "tuning": "VolumePath | UserContext",
   "detection_logic_en": "Adversary attaches USB drive and accesses sensitive files using Finder, cp, or bash scripts."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1039",
   "technique_ja": "ネットワーク共有ドライブからのデータ",
   "technique_en": "Data from Network Shared Drive",
   "analytic_id": "AN1145",
   "detection_strategy_id": "DET0410",
   "analytic_name": "Analytic 1145",
   "platforms": "Windows",
   "log_sources": "Network Share Access (WinEventLog:Security) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワーク共有アクセス (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "ShareName | ProcessName | TimeWindow",
   "detection_logic_en": "Monitoring of file access to network shares (e.g., C$, Admin$) followed by unusual read or copy operations by processes not typically associated with such activity (e.g., PowerShell, certutil)."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1039",
   "technique_ja": "ネットワーク共有ドライブからのデータ",
   "technique_en": "Data from Network Shared Drive",
   "analytic_id": "AN1146",
   "detection_strategy_id": "DET0410",
   "analytic_name": "Analytic 1146",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Drive Access (linux:syslog)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | ドライブアクセス (linux:syslog)",
   "tuning": "MountPoint | UID",
   "detection_logic_en": "Unusual access or copying of files from mounted network drives (e.g., NFS, CIFS/SMB) by user shells or scripts followed by large data transfer."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1039",
   "technique_ja": "ネットワーク共有ドライブからのデータ",
   "technique_en": "Data from Network Shared Drive",
   "analytic_id": "AN1147",
   "detection_strategy_id": "DET0410",
   "analytic_name": "Analytic 1147",
   "platforms": "macOS",
   "log_sources": "File Access (macos:unifiedlog) | Drive Access (fs:fsusage)",
   "log_sources_ja": "ファイルアクセス (macos:unifiedlog) | ドライブアクセス (fs:fsusage)",
   "tuning": "ProcessPath | SharePath",
   "detection_logic_en": "Detection of file access from mounted SMB shares followed by copy or exfil commands from Terminal or script interpreter processes."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1056",
   "technique_ja": "入力キャプチャ",
   "technique_en": "Input Capture",
   "analytic_id": "AN0282",
   "detection_strategy_id": "DET0102",
   "analytic_name": "Analytic 0282",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | File Access (WinEventLog:Security)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Security)",
   "tuning": "TargetImage | TimeWindow",
   "detection_logic_en": "Monitors for abnormal process behavior and API calls like SetWindowsHookEx, GetAsyncKeyState, or device input polling commonly used for keystroke logging."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1056",
   "technique_ja": "入力キャプチャ",
   "technique_en": "Input Capture",
   "analytic_id": "AN0283",
   "detection_strategy_id": "DET0102",
   "analytic_name": "Analytic 0283",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | File Modification (auditd:SYSCALL) | OS API Execution (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL) | OS API実行 (auditd:SYSCALL)",
   "tuning": "ProcessName | DevicePath",
   "detection_logic_en": "Detects use of tools/scripts accessing input devices like /dev/input/* or evdev via suspicious processes lacking GUI context."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1056",
   "technique_ja": "入力キャプチャ",
   "technique_en": "Input Capture",
   "analytic_id": "AN0284",
   "detection_strategy_id": "DET0102",
   "analytic_name": "Analytic 0284",
   "platforms": "macOS",
   "log_sources": "Process Metadata (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "プロセスメタデータ (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "Service | ParentProcess",
   "detection_logic_en": "Monitors for TCC-bypassing or unauthorized access to input services like IOHIDSystem or Quartz Event Services used in keylogging or screen monitoring."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1056",
   "technique_ja": "入力キャプチャ",
   "technique_en": "Input Capture",
   "analytic_id": "AN0285",
   "detection_strategy_id": "DET0102",
   "analytic_name": "Analytic 0285",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Content (NSM:Flow) | Network Connection Creation (NSM:Firewall)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow) | ネットワーク接続確立 (NSM:Firewall)",
   "tuning": "UserAgent | URL_Path",
   "detection_logic_en": "Detects web-based credential phishing by analyzing traffic to suspicious URLs that mimic login portals and POST credential content."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1056.001",
   "technique_ja": "キーロギング",
   "technique_en": "Keylogging",
   "analytic_id": "AN0243",
   "detection_strategy_id": "DET0089",
   "analytic_name": "Analytic 0243",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | File Access (WinEventLog:Security) | Service Creation (WinEventLog:System) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Security) | サービス作成 (WinEventLog:System) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "TargetImage | AccessMask | TimeWindow",
   "detection_logic_en": "Monitors suspicious usage of Windows API calls like SetWindowsHookEx, GetKeyState, or polling functions within non-UI service processes, combined with Registry or driver modifications."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1056.001",
   "technique_ja": "キーロギング",
   "technique_en": "Keylogging",
   "analytic_id": "AN0244",
   "detection_strategy_id": "DET0089",
   "analytic_name": "Analytic 0244",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | OS API Execution (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | OS API実行 (auditd:SYSCALL)",
   "tuning": "ProcessName | DevicePath",
   "detection_logic_en": "Detects non-system processes accessing /dev/input/* or issuing ptrace/evdev syscalls used for reading keystroke buffers directly."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1056.001",
   "technique_ja": "キーロギング",
   "technique_en": "Keylogging",
   "analytic_id": "AN0245",
   "detection_strategy_id": "DET0089",
   "analytic_name": "Analytic 0245",
   "platforms": "macOS",
   "log_sources": "Process Metadata (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "プロセスメタデータ (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "Service | ExecutablePath",
   "detection_logic_en": "Detects unauthorized TCC access or use of Quartz Event Services (CGEventTapCreate) or IOHID for event tap installation within unexpected processes."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1056.001",
   "technique_ja": "キーロギング",
   "technique_en": "Keylogging",
   "analytic_id": "AN0246",
   "detection_strategy_id": "DET0089",
   "analytic_name": "Analytic 0246",
   "platforms": "Network Devices",
   "log_sources": "Firmware Modification (networkdevice:syslog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ファームウェア変更 (networkdevice:syslog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "FirmwareVersion | Protocol",
   "detection_logic_en": "Keylogging on legacy network devices via unauthorized system image modification or remote capture of console keystrokes (telnet, SSH) through altered firmware or man-in-the-middle key sniffing."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1056.002",
   "technique_ja": "GUI入力キャプチャ",
   "technique_en": "GUI Input Capture",
   "analytic_id": "AN1440",
   "detection_strategy_id": "DET0521",
   "analytic_name": "Analytic 1440",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "CommandLine | ParentProcessName | TimeWindow",
   "detection_logic_en": "Detects suspicious use of PowerShell, .NET, or script interpreters to spawn processes that mimic UAC prompts, often with credential capture dialogue boxes invoked from non-standard parent processes."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1056.002",
   "technique_ja": "GUI入力キャプチャ",
   "technique_en": "GUI Input Capture",
   "analytic_id": "AN1441",
   "detection_strategy_id": "DET0521",
   "analytic_name": "Analytic 1441",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Command Execution (linux:cli)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | コマンド実行 (linux:cli)",
   "tuning": "ExecutableName | PromptString",
   "detection_logic_en": "Detects GUI-based credential prompts invoked via zenity/kdialog/dialog or X11 APIs from non-user-facing scripts or background shell sessions, often with authentication-related text."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1056.002",
   "technique_ja": "GUI入力キャプチャ",
   "technique_en": "GUI Input Capture",
   "analytic_id": "AN1442",
   "detection_strategy_id": "DET0521",
   "analytic_name": "Analytic 1442",
   "platforms": "macOS",
   "log_sources": "Script Execution (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "スクリプト実行 (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "ScriptContent | ProcessPath",
   "detection_logic_en": "Detects AppleScript or Objective-C usage to generate fake authentication windows (e.g., using display dialog or NSAlert) from user-launched or persistence-related processes."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1056.003",
   "technique_ja": "Webポータルキャプチャ",
   "technique_en": "Web Portal Capture",
   "analytic_id": "AN1320",
   "detection_strategy_id": "DET0480",
   "analytic_name": "Analytic 1320",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "MonitoredFilePaths | TimeWindow",
   "detection_logic_en": "Detects unauthorized modifications to login-facing web server files (e.g., index.php, login.js) typically tied to VPN, SSO, or intranet portals. Correlates suspicious file changes with remote access artifacts or web shell behavior."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1056.003",
   "technique_ja": "Webポータルキャプチャ",
   "technique_en": "Web Portal Capture",
   "analytic_id": "AN1321",
   "detection_strategy_id": "DET0480",
   "analytic_name": "Analytic 1321",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Network Traffic Content (WinEventLog:iis)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (WinEventLog:iis)",
   "tuning": "FilePath | ProcessName",
   "detection_logic_en": "Detects tampering of IIS-based login pages (e.g., default.aspx, login.aspx) tied to VPN, OWA, or SharePoint via script injection or unexpected editor processes modifying web roots."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1056.003",
   "technique_ja": "Webポータルキャプチャ",
   "technique_en": "Web Portal Capture",
   "analytic_id": "AN1322",
   "detection_strategy_id": "DET0480",
   "analytic_name": "Analytic 1322",
   "platforms": "macOS",
   "log_sources": "File Modification (fs:fsusage) | Network Traffic Content (macos:unifiedlog)",
   "log_sources_ja": "ファイル変更 (fs:fsusage) | ネットワークトラフィック内容 (macos:unifiedlog)",
   "tuning": "WebRootPath | AnomalousProcess",
   "detection_logic_en": "Detects unauthorized changes to locally hosted login pages on macOS (common in developer VPN environments) and links file edits to cron jobs, background scripts, or SUID binaries."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1056.004",
   "technique_ja": "認証情報APIフック",
   "technique_en": "Credential API Hooking",
   "analytic_id": "AN0389",
   "detection_strategy_id": "DET0139",
   "analytic_name": "Analytic 0389",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Process Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | プロセス変更 (WinEventLog:Sysmon)",
   "tuning": "TargetProcess | AccessMask | TimeWindow",
   "detection_logic_en": "Detects credential harvesting via userland API hooking (e.g., SetWindowsHookEx, IAT, or inline patching) by correlating memory modifications with hook installation functions and suspicious module loads in credential-sensitive processes like lsass.exe, explorer.exe, or winlogon.exe."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1056.004",
   "technique_ja": "認証情報APIフック",
   "technique_en": "Credential API Hooking",
   "analytic_id": "AN0390",
   "detection_strategy_id": "DET0139",
   "analytic_name": "Analytic 0390",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Module Load (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | モジュール読み込み (auditd:SYSCALL)",
   "tuning": "InjectedLibraryName | TargetProcessName",
   "detection_logic_en": "Detects credential interception via malicious LD_PRELOAD-based shared libraries loaded into ssh, sudo, or scp processes. Correlates environment variable injection, unexpected library loads, and memory patching behavior."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1056.004",
   "technique_ja": "認証情報APIフック",
   "technique_en": "Credential API Hooking",
   "analytic_id": "AN0391",
   "detection_strategy_id": "DET0139",
   "analytic_name": "Analytic 0391",
   "platforms": "macOS",
   "log_sources": "Module Load (macos:unifiedlog) | File Access (fs:fsusage) | Process Modification (macos:osquery)",
   "log_sources_ja": "モジュール読み込み (macos:unifiedlog) | ファイルアクセス (fs:fsusage) | プロセス変更 (macos:osquery)",
   "tuning": "DYLDInjectedPath | ParentProcessName",
   "detection_logic_en": "Detects DYLD_INSERT_LIBRARIES abuse to hook credential-sensitive applications by correlating process spawns with unauthorized library injection and monitoring changes to the __TEXT segment (code) of credential handling binaries."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1074",
   "technique_ja": "データのステージング",
   "technique_en": "Data Staged",
   "analytic_id": "AN0040",
   "detection_strategy_id": "DET0014",
   "analytic_name": "Analytic 0040",
   "platforms": "Windows",
   "log_sources": "File Access (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイルアクセス (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "StagingDirectoryList | CompressionToolList | TimeWindow",
   "detection_logic_en": "Detects staging of sensitive files into temporary or public directories, compression with 7zip/WinRAR, or batch copy prior to exfiltration."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1074",
   "technique_ja": "データのステージング",
   "technique_en": "Data Staged",
   "analytic_id": "AN0041",
   "detection_strategy_id": "DET0014",
   "analytic_name": "Analytic 0041",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイル作成 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "StagingDirectoryList | ArchivingCommandPatterns | UserContext",
   "detection_logic_en": "Detects script or user activity copying files to a central temp or /mnt directory followed by archive/compression utilities."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1074",
   "technique_ja": "データのステージング",
   "technique_en": "Data Staged",
   "analytic_id": "AN0042",
   "detection_strategy_id": "DET0014",
   "analytic_name": "Analytic 0042",
   "platforms": "macOS",
   "log_sources": "File Access (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ファイルアクセス (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "CompressionUtilityList | SharedDirectoryIndicators | ScriptInvocationContext",
   "detection_logic_en": "Detects files collected into user temp or shared directories followed by compression with ditto, zip, or custom scripts."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1074",
   "technique_ja": "データのステージング",
   "technique_en": "Data Staged",
   "analytic_id": "AN0043",
   "detection_strategy_id": "DET0014",
   "analytic_name": "Analytic 0043",
   "platforms": "IaaS",
   "log_sources": "Cloud Storage Access (AWS:CloudTrail) | File Access (gcp:audit)",
   "log_sources_ja": "クラウドストレージアクセス (AWS:CloudTrail) | ファイルアクセス (gcp:audit)",
   "tuning": "CloudBucketList | InstanceTag | ObjectWriteThreshold",
   "detection_logic_en": "Detects virtual disk expansion or file copy operations to cloud buckets or mounted volumes from isolated instances."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1074",
   "technique_ja": "データのステージング",
   "technique_en": "Data Staged",
   "analytic_id": "AN0044",
   "detection_strategy_id": "DET0014",
   "analytic_name": "Analytic 0044",
   "platforms": "ESXi",
   "log_sources": "File Access (esxi:vmkernel) | Command Execution (esxi:shell)",
   "log_sources_ja": "ファイルアクセス (esxi:vmkernel) | コマンド実行 (esxi:shell)",
   "tuning": "SnapshotFrequency | AccessUserList | CLIContext",
   "detection_logic_en": "Detects snapshots or data stored in VMFS volumes from root CLI or remote agents."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1074.001",
   "technique_ja": "ローカルデータステージング",
   "technique_en": "Local Data Staging",
   "analytic_id": "AN0724",
   "detection_strategy_id": "DET0261",
   "analytic_name": "Analytic 0724",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | File Access (WinEventLog:Security)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Security)",
   "tuning": "StagingDirList | ArchivingToolPatterns | TimeWindow",
   "detection_logic_en": "Detects file reads across locations followed by writes to temp or staging directories, often compressed or encrypted, indicating local staging behavior."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1074.001",
   "technique_ja": "ローカルデータステージング",
   "technique_en": "Local Data Staging",
   "analytic_id": "AN0725",
   "detection_strategy_id": "DET0261",
   "analytic_name": "Analytic 0725",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "StagingDirs | ArchiveUtilities | UserThreshold",
   "detection_logic_en": "Detects aggregation of files from different directories into /tmp, /mnt, or user-specified directories with archiving tools like tar or gzip."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1074.001",
   "technique_ja": "ローカルデータステージング",
   "technique_en": "Local Data Staging",
   "analytic_id": "AN0726",
   "detection_strategy_id": "DET0261",
   "analytic_name": "Analytic 0726",
   "platforms": "macOS",
   "log_sources": "File Access (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ファイルアクセス (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "StagingTargets | CompressionBinaries | TimeWindow",
   "detection_logic_en": "Detects staged data aggregated in /Users/Shared, /private/tmp with compression tools like ditto or zip, initiated via Terminal or AppleScript."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1074.001",
   "technique_ja": "ローカルデータステージング",
   "technique_en": "Local Data Staging",
   "analytic_id": "AN0727",
   "detection_strategy_id": "DET0261",
   "analytic_name": "Analytic 0727",
   "platforms": "ESXi",
   "log_sources": "Snapshot Creation (esxi:vmkernel) | Command Execution (esxi:shell)",
   "log_sources_ja": "スナップショット作成 (esxi:vmkernel) | コマンド実行 (esxi:shell)",
   "tuning": "SnapshotThreshold | CLIInvoker | VMFSWriteRate",
   "detection_logic_en": "Detects local staging behavior via snapshot creation or files written into VMFS partitions by scripts or unauthorized shell access."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1074.002",
   "technique_ja": "リモートデータステージング",
   "technique_en": "Remote Data Staging",
   "analytic_id": "AN0194",
   "detection_strategy_id": "DET0071",
   "analytic_name": "Analytic 0194",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Network Share Access (WinEventLog:Microsoft-Windows-SMBClient/Security) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ネットワーク共有アクセス (WinEventLog:Microsoft-Windows-SMBClient/Security) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "StagingDirectory | RemotePathPatterns | CopyToolPatterns",
   "detection_logic_en": "Detects file transfers or mounting operations from remote hosts followed by write actions into a local staging directory, often using SMB or remote shell activity."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1074.002",
   "technique_ja": "リモートデータステージング",
   "technique_en": "Remote Data Staging",
   "analytic_id": "AN0195",
   "detection_strategy_id": "DET0071",
   "analytic_name": "Analytic 0195",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "RemoteHosts | MountTargets | TransferVolumeThreshold",
   "detection_logic_en": "Detects inbound SCP, rsync, or NFS mounts from remote systems followed by aggregation of files into known staging paths like /mnt/staging or /var/tmp."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1074.002",
   "technique_ja": "リモートデータステージング",
   "technique_en": "Remote Data Staging",
   "analytic_id": "AN0196",
   "detection_strategy_id": "DET0071",
   "analytic_name": "Analytic 0196",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "StagingPaths | CompressionIndicators | TimeWindow",
   "detection_logic_en": "Detects rsync or scp inbound from other hosts that then aggregate content into /Users/Shared or /private/tmp, often involving compressed files or scripts."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1074.002",
   "technique_ja": "リモートデータステージング",
   "technique_en": "Remote Data Staging",
   "analytic_id": "AN0197",
   "detection_strategy_id": "DET0071",
   "analytic_name": "Analytic 0197",
   "platforms": "ESXi",
   "log_sources": "File Creation (esxi:vmkernel) | Network Traffic Content (esxi:vob) | Command Execution (esxi:shell)",
   "log_sources_ja": "ファイル作成 (esxi:vmkernel) | ネットワークトラフィック内容 (esxi:vob) | コマンド実行 (esxi:shell)",
   "tuning": "SnapshotFrequency | RemoteWriteVolume | StorageMountPaths",
   "detection_logic_en": "Detects remote writes or snapshots mounted from other systems into a central ESXi VMFS path or NFS store used for remote staging of files before exfiltration."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1074.002",
   "technique_ja": "リモートデータステージング",
   "technique_en": "Remote Data Staging",
   "analytic_id": "AN0198",
   "detection_strategy_id": "DET0071",
   "analytic_name": "Analytic 0198",
   "platforms": "IaaS",
   "log_sources": "Cloud Storage Access (AWS:CloudTrail) | Network Traffic Content (AWS:VPCFlowLogs) | Process Creation (esxi:hostd)",
   "log_sources_ja": "クラウドストレージアクセス (AWS:CloudTrail) | ネットワークトラフィック内容 (AWS:VPCFlowLogs) | プロセス生成 (esxi:hostd)",
   "tuning": "BucketNamePatterns | IAMContext | TransferWindow",
   "detection_logic_en": "Detects remote write activity across cloud VMs or object storage buckets within the same region/account that correlate with data aggregation across hosts."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1113",
   "technique_ja": "画面キャプチャ",
   "technique_en": "Screen Capture",
   "analytic_id": "AN0980",
   "detection_strategy_id": "DET0346",
   "analytic_name": "Analytic 0980",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "ParentProcessName | TimeWindow | ImageExtension",
   "detection_logic_en": "Unusual use of screen capture APIs (e.g., CopyFromScreen) or command-line tools to write image files to disk."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1113",
   "technique_ja": "画面キャプチャ",
   "technique_en": "Screen Capture",
   "analytic_id": "AN0981",
   "detection_strategy_id": "DET0346",
   "analytic_name": "Analytic 0981",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog)",
   "tuning": "CommandLineRegex | ParentProcessName",
   "detection_logic_en": "Invocation of built-in commands like screencapture or use of undocumented APIs from suspicious parent processes."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1113",
   "technique_ja": "画面キャプチャ",
   "technique_en": "Screen Capture",
   "analytic_id": "AN0982",
   "detection_strategy_id": "DET0346",
   "analytic_name": "Analytic 0982",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL)",
   "tuning": "TerminalSession | ExecutablePath",
   "detection_logic_en": "Use of tools like xwd or import to generate screenshots, especially under non-GUI parent processes."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1114",
   "technique_ja": "メール収集",
   "technique_en": "Email Collection",
   "analytic_id": "AN1309",
   "detection_strategy_id": "DET0476",
   "analytic_name": "Analytic 1309",
   "platforms": "Windows",
   "log_sources": "Network Share Access (WinEventLog:Security) | Command Execution (WinEventLog:PowerShell) | Application Log Content (WinEventLog:Application) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワーク共有アクセス (WinEventLog:Security) | コマンド実行 (WinEventLog:PowerShell) | アプリケーションログ内容 (WinEventLog:Application) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext | SMTPDomainList",
   "detection_logic_en": "Correlates creation of email forwarding rules or header anomalies (e.g., X-MS-Exchange-Organization-AutoForwarded) with suspicious process execution, file access of .pst/.ost files, and network connections to external SMTP servers."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1114",
   "technique_ja": "メール収集",
   "technique_en": "Email Collection",
   "analytic_id": "AN1310",
   "detection_strategy_id": "DET0476",
   "analytic_name": "Analytic 1310",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Network Connection Creation (linux:syslog) | Process Creation (linux:osquery)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | ネットワーク接続確立 (linux:syslog) | プロセス生成 (linux:osquery)",
   "tuning": "WatchedMailDirs | ProcessNameList | TimeWindow",
   "detection_logic_en": "Detects file access to mbox/maildir files in conjunction with curl/wget/postfix execution, or anomalous shell scripts harvesting user mail directories."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1114",
   "technique_ja": "メール収集",
   "technique_en": "Email Collection",
   "analytic_id": "AN1311",
   "detection_strategy_id": "DET0476",
   "analytic_name": "Analytic 1311",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | File Access (macos:endpointsecurity)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | ファイルアクセス (macos:endpointsecurity)",
   "tuning": "ScriptProcessNameList | WatchedMailFiles",
   "detection_logic_en": "Monitors Mail.app database or maildir file access, automation via AppleScript, and abnormal mail rule creation using scripting or UI automation frameworks."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1114",
   "technique_ja": "メール収集",
   "technique_en": "Email Collection",
   "analytic_id": "AN1312",
   "detection_strategy_id": "DET0476",
   "analytic_name": "Analytic 1312",
   "platforms": "Office Suite",
   "log_sources": "Command Execution (m365:unified) | Application Log Content (m365:exchange) | Logon Session Creation (azure:ad)",
   "log_sources_ja": "コマンド実行 (m365:unified) | アプリケーションログ内容 (m365:exchange) | ログオンセッション作成 (azure:ad)",
   "tuning": "UserAgentList | ExternalSMTPDomainList | TimeWindow",
   "detection_logic_en": "Correlates unusual auto-forwarding rule creation via Exchange Web Services or Outlook rules engine, presence of X-MS-Exchange-Organization-AutoForwarded headers, and logon session anomalies from abnormal IPs."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1114.001",
   "technique_ja": "ローカルメール収集",
   "technique_en": "Local Email Collection",
   "analytic_id": "AN0130",
   "detection_strategy_id": "DET0047",
   "analytic_name": "Analytic 0130",
   "platforms": "Windows",
   "log_sources": "File Access (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイルアクセス (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TargetFilePathPattern | TimeWindow | UserContext | ProcessAllowList",
   "detection_logic_en": "Detection focuses on processes that attempt to locate, access, or exfiltrate local Outlook data files (.pst/.ost) using file system access, native Windows utilities (e.g., PowerShell, WMI), or remote access tools with file browsing capabilities. The behavior chain includes directory enumeration, file access, optional compression or staging, and network transfer."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1114.002",
   "technique_ja": "リモートメール収集",
   "technique_en": "Remote Email Collection",
   "analytic_id": "AN0131",
   "detection_strategy_id": "DET0048",
   "analytic_name": "Analytic 0131",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (azure:signinlogs) | Application Log Content (m365:purview) | Command Execution (WinEventLog:PowerShell) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッション作成 (azure:signinlogs) | アプリケーションログ内容 (m365:purview) | コマンド実行 (WinEventLog:PowerShell) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "UserAgentPattern | TimeWindow | KnownIPLocations | PrivilegedUserList",
   "detection_logic_en": "Detects adversaries accessing remote mail systems (e.g., Exchange Online, O365) using stolen credentials or OAuth tokens, followed by scripted access to mailbox contents via PowerShell, AADInternals, or unattended API queries. Detection focuses on abnormal logon sessions, user agents, IP locations, and scripted or tool-based email data access."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1114.002",
   "technique_ja": "リモートメール収集",
   "technique_en": "Remote Email Collection",
   "analytic_id": "AN0132",
   "detection_strategy_id": "DET0048",
   "analytic_name": "Analytic 0132",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:purview) | Logon Session Creation (azure:signinlogs) | Command Execution (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (m365:purview) | ログオンセッション作成 (azure:signinlogs) | コマンド実行 (m365:unified)",
   "tuning": "MailAccessVolumeThreshold | OAuthClientIDAllowList | KeywordSearchFrequency | LoginGeolocationVariance",
   "detection_logic_en": "Monitors programmatic access to user mailboxes in cloud-based email systems (e.g., O365, Exchange Online) using APIs or tokens. Focuses on OAuth misuse, suspicious MailItemsAccessed patterns, scripted keyword searches, and connections from untrusted agents or locations."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1114.003",
   "technique_ja": "メール転送ルール",
   "technique_en": "Email Forwarding Rule",
   "analytic_id": "AN1589",
   "detection_strategy_id": "DET0576",
   "analytic_name": "Analytic 1589",
   "platforms": "Windows",
   "log_sources": "Command Execution (WinEventLog:PowerShell) | Process Creation (WinEventLog:Security) | Cloud Service Metadata (m365:exchange)",
   "log_sources_ja": "コマンド実行 (WinEventLog:PowerShell) | プロセス生成 (WinEventLog:Security) | クラウドサービスメタデータ (m365:exchange)",
   "tuning": "UserContext | TimeWindow | TargetMailbox",
   "detection_logic_en": "Creation of inbox rules via PowerShell (New-InboxRule) or transport rules using Exchange cmdlets. Correlates user behavior, cmdlet usage, and rule properties."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1114.003",
   "technique_ja": "メール転送ルール",
   "technique_en": "Email Forwarding Rule",
   "analytic_id": "AN1590",
   "detection_strategy_id": "DET0576",
   "analytic_name": "Analytic 1590",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | File Modification (fs:plist_monitoring)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ファイル変更 (fs:plist_monitoring)",
   "tuning": "RuleFilePath | ScriptTrigger",
   "detection_logic_en": "Creation or modification of Apple Mail rules by accessing plist files or GUI automation (AppleScript)."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1114.003",
   "technique_ja": "メール転送ルール",
   "technique_en": "Email Forwarding Rule",
   "analytic_id": "AN1591",
   "detection_strategy_id": "DET0576",
   "analytic_name": "Analytic 1591",
   "platforms": "Office Suite",
   "log_sources": "Cloud Service Metadata (m365:unified) | Application Log Content (m365:messagetrace)",
   "log_sources_ja": "クラウドサービスメタデータ (m365:unified) | アプリケーションログ内容 (m365:messagetrace)",
   "tuning": "ForwardingSMTPAddress | ActorId",
   "detection_logic_en": "Creation of email forwarding/redirect rules in Exchange Online via New-InboxRule or transport rule cmdlets, including auto-forwarding address field usage."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1114.003",
   "technique_ja": "メール転送ルール",
   "technique_en": "Email Forwarding Rule",
   "analytic_id": "AN1592",
   "detection_strategy_id": "DET0576",
   "analytic_name": "Analytic 1592",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Command Execution (linux:cli)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | コマンド実行 (linux:cli)",
   "tuning": ".forwardPath | ExecContext",
   "detection_logic_en": "Modification of Thunderbird message filters file or execution of CLI tools (e.g., formail/procmail) that alter .forward behavior."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1115",
   "technique_ja": "クリップボードデータ",
   "technique_en": "Clipboard Data",
   "analytic_id": "AN0965",
   "detection_strategy_id": "DET0341",
   "analytic_name": "Analytic 0965",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext | ParentProcessName",
   "detection_logic_en": "Detection of clipboard access via OS utilities (e.g., clip.exe, Get-Clipboard) by non-interactive or abnormal parent processes, potentially chained with staging or exfiltration commands."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1115",
   "technique_ja": "クリップボードデータ",
   "technique_en": "Clipboard Data",
   "analytic_id": "AN0966",
   "detection_strategy_id": "DET0341",
   "analytic_name": "Analytic 0966",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog)",
   "tuning": "ExecutionChainLength | TerminalSession | BinaryPath",
   "detection_logic_en": "Detection of pbpaste/pbcopy clipboard access by processes without terminal sessions or linked to launch agents, potentially staged for collection."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1115",
   "technique_ja": "クリップボードデータ",
   "technique_en": "Clipboard Data",
   "analytic_id": "AN0967",
   "detection_strategy_id": "DET0341",
   "analytic_name": "Analytic 0967",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL)",
   "tuning": "ClipboardCommand | CorrelationWindow | TTYLinked",
   "detection_logic_en": "Detection of xclip or xsel access to clipboard buffers outside of user terminal context, especially when chained to staging (gzip, base64) or network exfiltration (curl, scp)."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1119",
   "technique_ja": "自動収集",
   "technique_en": "Automated Collection",
   "analytic_id": "AN0531",
   "detection_strategy_id": "DET0186",
   "analytic_name": "Analytic 0531",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | SuspiciousFileExtensions | ProcessCountThreshold",
   "detection_logic_en": "Automated execution of native utilities and scripts to discover, enumerate, and exfiltrate files and clipboard content. Focus is on detecting repeated file access, scripting engine use, and use of command-line utilities commonly leveraged by collection scripts."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1119",
   "technique_ja": "自動収集",
   "technique_en": "Automated Collection",
   "analytic_id": "AN0532",
   "detection_strategy_id": "DET0186",
   "analytic_name": "Analytic 0532",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Access (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイルアクセス (auditd:SYSCALL)",
   "tuning": "AccessPath | ScriptInterpreterList",
   "detection_logic_en": "Repeated or automated access to user document directories or clipboard using shell scripts or utilities like xclip/pbpaste. Detectable via auditd syscall logs or osquery file events."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1119",
   "technique_ja": "自動収集",
   "technique_en": "Automated Collection",
   "analytic_id": "AN0533",
   "detection_strategy_id": "DET0186",
   "analytic_name": "Analytic 0533",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Script Execution (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | スクリプト実行 (macos:unifiedlog)",
   "tuning": "AutomationTool | ClipboardCheckRate",
   "detection_logic_en": "Use of pbpaste, AppleScript, or third-party automation frameworks (e.g., Automator) to collect clipboard or file content in bursts. Observable via unified logs."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1119",
   "technique_ja": "自動収集",
   "technique_en": "Automated Collection",
   "analytic_id": "AN0534",
   "detection_strategy_id": "DET0186",
   "analytic_name": "Analytic 0534",
   "platforms": "SaaS",
   "log_sources": "User Account Authentication (azure:signinlogs)",
   "log_sources_ja": "ユーザーアカウント認証 (azure:signinlogs)",
   "tuning": "UserAgentFilter | ExpectedClientIPList | DeviceProperties",
   "detection_logic_en": "Suspicious sign-ins to Graph API or sensitive resources using non-browser scripting agents (e.g., Python, PowerShell), often for programmatic access to mailbox or OneDrive content."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1123",
   "technique_ja": "音声キャプチャ",
   "technique_en": "Audio Capture",
   "analytic_id": "AN0619",
   "detection_strategy_id": "DET0221",
   "analytic_name": "Analytic 0619",
   "platforms": "Windows",
   "log_sources": "Process Access (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Security)",
   "log_sources_ja": "プロセスアクセス (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Security)",
   "tuning": "TimeWindow | TargetProcess | WriteDirectory",
   "detection_logic_en": "Unusual or unauthorized processes accessing microphone APIs (e.g., winmm.dll, avrt.dll) followed by audio file writes to user-accessible or temp directories."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1123",
   "technique_ja": "音声キャプチャ",
   "technique_en": "Audio Capture",
   "analytic_id": "AN0620",
   "detection_strategy_id": "DET0221",
   "analytic_name": "Analytic 0620",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Process Creation (linux:Sysmon) | File Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | プロセス生成 (linux:Sysmon) | ファイル作成 (auditd:SYSCALL)",
   "tuning": "ExecutableName | DevicePath | UserContext",
   "detection_logic_en": "Processes accessing ALSA/PulseAudio devices or executing audio capture binaries like 'arecord', followed by file creation or suspicious child process spawning."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1123",
   "technique_ja": "音声キャプチャ",
   "technique_en": "Audio Capture",
   "analytic_id": "AN0621",
   "detection_strategy_id": "DET0221",
   "analytic_name": "Analytic 0621",
   "platforms": "macOS",
   "log_sources": "OS API Execution (macos:unifiedlog) | Process Access (Apple TCC Logs) | File Creation (fs:fsusage)",
   "log_sources_ja": "OS API実行 (macos:unifiedlog) | プロセスアクセス (Apple TCC Logs) | ファイル作成 (fs:fsusage)",
   "tuning": "FrameworkCall | TargetDirectory | AnomalousParent",
   "detection_logic_en": "Processes invoking AVFoundation or CoreAudio frameworks, accessing input devices via TCC logs or Unified Logs, followed by writing AIFF/WAV/MP3 files to disk."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1125",
   "technique_ja": "映像キャプチャ",
   "technique_en": "Video Capture",
   "analytic_id": "AN0568",
   "detection_strategy_id": "DET0197",
   "analytic_name": "Analytic 0568",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | OS API Execution (WinEventLog:Security) | Process Metadata (WinEventLog:Microsoft-Windows-Windows Camera Frame Server/Operational)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | OS API実行 (WinEventLog:Security) | プロセスメタデータ (WinEventLog:Microsoft-Windows-Windows Camera Frame Server/Operational)",
   "tuning": "TimeWindow | AllowedProcesses | VideoExtensions | RarePathRegex | MinFileSizeMB | ParentProcessAllowList",
   "detection_logic_en": "A non-standard process (or script-hosted process) loads camera/video-capture libraries (e.g., avicap32.dll, mf.dll, ksproxy.ax), opens the Camera Frame Server/device, writes video/image artifacts (e.g., .mp4/.avi/.yuv) to unusual locations, and optionally initiates outbound transfer shortly after."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1125",
   "technique_ja": "映像キャプチャ",
   "technique_en": "Video Capture",
   "analytic_id": "AN0569",
   "detection_strategy_id": "DET0197",
   "analytic_name": "Analytic 0569",
   "platforms": "Linux",
   "log_sources": "OS API Execution (auditd:SYSCALL) | File Access (auditd:SYSCALL) | Process Metadata (linux:osquery) | Command Execution (linux:syslog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "OS API実行 (auditd:SYSCALL) | ファイルアクセス (auditd:SYSCALL) | プロセスメタデータ (linux:osquery) | コマンド実行 (linux:syslog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "SyscallSet | AllowedCallers | VideoExtensions | MinContinuousReadCount | TimeWindow",
   "detection_logic_en": "A process opens/reads /dev/video* (V4L2), performs ioctl/read loops, writes large/continuous video artifacts to disk, and/or quickly establishes outbound connections for exfiltration."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1125",
   "technique_ja": "映像キャプチャ",
   "technique_en": "Video Capture",
   "analytic_id": "AN0570",
   "detection_strategy_id": "DET0197",
   "analytic_name": "Analytic 0570",
   "platforms": "macOS",
   "log_sources": "OS API Execution (macos:unifiedlog) | File Access (macos:endpointsecurity) | Process Creation (macos:endpointsecurity) | File Creation (macos:unifiedlog)",
   "log_sources_ja": "OS API実行 (macos:unifiedlog) | ファイルアクセス (macos:endpointsecurity) | プロセス生成 (macos:endpointsecurity) | ファイル作成 (macos:unifiedlog)",
   "tuning": "TCCAllowList | VideoExtensions | TimeWindow | MinFileSizeMB | LaunchAgentPaths",
   "detection_logic_en": "A non-whitelisted process receives TCC camera entitlement (kTCCServiceCamera), opens AppleCamera/AVFoundation device handles, writes .mov/.mp4 artifacts to unusual locations, and/or beacons/exfiltrates soon after."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1185",
   "technique_ja": "ブラウザセッションの乗っ取り",
   "technique_en": "Browser Session Hijacking",
   "analytic_id": "AN1398",
   "detection_strategy_id": "DET0507",
   "analytic_name": "Analytic 1398",
   "platforms": "Windows",
   "log_sources": "Logon Session Metadata (WinEventLog:Security) | User Account Metadata (WinEventLog:Security) | Logon Session Creation (WinEventLog:Security) | Process Access (WinEventLog:Sysmon) | Process Modification (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッションメタデータ (WinEventLog:Security) | ユーザーアカウントメタデータ (WinEventLog:Security) | ログオンセッション作成 (WinEventLog:Security) | プロセスアクセス (WinEventLog:Sysmon) | プロセス変更 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "BrowserList | AccessMaskSet | SignerAllowList | InternalCIDR | TimeWindow | ParentAllowList | UserContext",
   "detection_logic_en": "Adversary gains high integrity or special privileges (e.g., SeDebugPrivilege), locates a running browser process, opens it with write/inject rights, and modifies it (e.g., CreateRemoteThread / DLL load) to inherit cookies/tokens or establish a browser pivot. Optional step: create a new logon session or use explicit credentials, then drive the victim browser to intranet resources."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1213",
   "technique_ja": "情報リポジトリからのデータ",
   "technique_en": "Data from Information Repositories",
   "analytic_id": "AN1160",
   "detection_strategy_id": "DET0413",
   "analytic_name": "Analytic 1160",
   "platforms": "Windows",
   "log_sources": "Network Share Access (WinEventLog:Security) | Cloud Storage Access (m365:unified)",
   "log_sources_ja": "ネットワーク共有アクセス (WinEventLog:Security) | クラウドストレージアクセス (m365:unified)",
   "tuning": "UserContext | AccessVolumeThreshold | TimeWindow",
   "detection_logic_en": "Programmatic or excessive access to file shares, SharePoint, or database repositories by users not typically interacting with them. This includes abnormal access by privileged accounts, enumeration of large numbers of files, or downloads of sensitive content in bursts."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1213",
   "technique_ja": "情報リポジトリからのデータ",
   "technique_en": "Data from Information Repositories",
   "analytic_id": "AN1161",
   "detection_strategy_id": "DET0413",
   "analytic_name": "Analytic 1161",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | Network Connection Creation (linux:Sysmon)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ネットワーク接続確立 (linux:Sysmon)",
   "tuning": "CommandRegex | TimeWindow",
   "detection_logic_en": "Command-line tools (e.g., curl, rsync, wget, or custom Python scripts) used to scrape documentation systems or internal REST APIs. Unusual access patterns to knowledge base folders or shared team drives."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1213",
   "technique_ja": "情報リポジトリからのデータ",
   "technique_en": "Data from Information Repositories",
   "analytic_id": "AN1162",
   "detection_strategy_id": "DET0413",
   "analytic_name": "Analytic 1162",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (saas:confluence) | Cloud Service Modification (saas:slack)",
   "log_sources_ja": "アプリケーションログ内容 (saas:confluence) | クラウドサービス変更 (saas:slack)",
   "tuning": "APIUsageThreshold | KnownSafeIPs",
   "detection_logic_en": "Abuse of SaaS platforms such as Confluence, GitHub, SharePoint Online, or Slack to access excessive internal documentation or export source code/data. Includes use of tokens or browser automation from unapproved IPs."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1213",
   "technique_ja": "情報リポジトリからのデータ",
   "technique_en": "Data from Information Repositories",
   "analytic_id": "AN1163",
   "detection_strategy_id": "DET0413",
   "analytic_name": "Analytic 1163",
   "platforms": "macOS",
   "log_sources": "File Access (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "ファイルアクセス (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "AccessedMountPath | UserGroup",
   "detection_logic_en": "Access of mounted cloud shares or document repositories via browser, terminal, or Finder by users not typically interacting with those resources. Includes script-based enumeration or mass download."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1213.001",
   "technique_ja": "Confluence",
   "technique_en": "Confluence",
   "analytic_id": "AN1019",
   "detection_strategy_id": "DET0358",
   "analytic_name": "Analytic 1019",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (saas:confluence) | Logon Session Creation (saas:confluence) | Network Traffic Content (saas:confluence)",
   "log_sources_ja": "アプリケーションログ内容 (saas:confluence) | ログオンセッション作成 (saas:confluence) | ネットワークトラフィック内容 (saas:confluence)",
   "tuning": "TimeWindow | UserContext | AccessThreshold | AgentFilter",
   "detection_logic_en": "Detection of excessive or programmatic access to Confluence spaces or pages, particularly by privileged users, through a combination of access logs, API usage, and identity context. Correlates logon sessions, user roles, and abnormal document viewing or export behavior. Identifies burst access patterns and tools/scripts abusing the Confluence API for mass enumeration or data scraping."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1213.002",
   "technique_ja": "SharePoint",
   "technique_en": "Sharepoint",
   "analytic_id": "AN1380",
   "detection_strategy_id": "DET0500",
   "analytic_name": "Analytic 1380",
   "platforms": "Windows",
   "log_sources": "Application Log Content (m365:unified) | Logon Session Creation (azure:signinlogs) | Cloud Service Metadata (m365:sharepoint)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | ログオンセッション作成 (azure:signinlogs) | クラウドサービスメタデータ (m365:sharepoint)",
   "tuning": "UserContext | TimeWindow | DownloadThreshold | SiteScope",
   "detection_logic_en": "Privileged or rarely used accounts performing bulk access to SharePoint files or metadata over a short time window, indicating potential scripted collection of sensitive internal documents."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1213.003",
   "technique_ja": "コードリポジトリ",
   "technique_en": "Code Repositories",
   "analytic_id": "AN0732",
   "detection_strategy_id": "DET0263",
   "analytic_name": "Analytic 0732",
   "platforms": "SaaS",
   "log_sources": "Cloud Service Metadata (saas:github) | Logon Session Creation (saas:github) | Application Log Content (saas:github)",
   "log_sources_ja": "クラウドサービスメタデータ (saas:github) | ログオンセッション作成 (saas:github) | アプリケーションログ内容 (saas:github)",
   "tuning": "TimeWindow | UserContext | GeoAnomalyThreshold | RepoSensitivityTag",
   "detection_logic_en": "Anomalous or bulk download activity from private or restricted repositories by non-developer or privileged accounts, often preceded by unusual login behavior (e.g., unfamiliar geo, OAuth token use, elevated API rate)."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1213.004",
   "technique_ja": "顧客関係管理（CRM）ソフトウェア",
   "technique_en": "Customer Relationship Management Software",
   "analytic_id": "AN1520",
   "detection_strategy_id": "DET0550",
   "analytic_name": "Analytic 1520",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (saas:salesforce) | Logon Session Creation (m365:signinlogs)",
   "log_sources_ja": "アプリケーションログ内容 (saas:salesforce) | ログオンセッション作成 (m365:signinlogs)",
   "tuning": "TimeWindow | UserContext | AnomalousExportThreshold | SourceLocation",
   "detection_logic_en": "Anomalous high-volume access to customer records in CRM software by a non-CRM admin user account, especially following initial authentication from a rare location or device. Behavior includes abnormal access to PII fields or data exports within a short time window."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1213.005",
   "technique_ja": "メッセージングアプリ",
   "technique_en": "Messaging Applications",
   "analytic_id": "AN1565",
   "detection_strategy_id": "DET0567",
   "analytic_name": "Analytic 1565",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (saas:slack) | Logon Session Creation (m365:signinlogs)",
   "log_sources_ja": "アプリケーションログ内容 (saas:slack) | ログオンセッション作成 (m365:signinlogs)",
   "tuning": "TimeWindow | MessageExportThreshold | UserContext | AccessMethod",
   "detection_logic_en": "Atypical access to Slack or Teams conversations via APIs, automation tokens, or bulk message export functionality, particularly after an account takeover or rare sign-in pattern. Often includes mass retrieval of chat history, download of message content, or scraping of workspace/channel metadata."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1213.005",
   "technique_ja": "メッセージングアプリ",
   "technique_en": "Messaging Applications",
   "analytic_id": "AN1566",
   "detection_strategy_id": "DET0567",
   "analytic_name": "Analytic 1566",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified) | Logon Session Creation (m365:signinlogs)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | ログオンセッション作成 (m365:signinlogs)",
   "tuning": "UserRole | GeoRiskScore | AccessVolume",
   "detection_logic_en": "Suspicious access to Microsoft Teams chat messages via eDiscovery, Graph API, or export methods after rare or compromised sign-in. Often associated with excessive file access, sensitive content review, or anomaly from expected user behavior."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1213.006",
   "technique_ja": "データベース",
   "technique_en": "Databases",
   "analytic_id": "AN0676",
   "detection_strategy_id": "DET0242",
   "analytic_name": "Analytic 0676",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Creation (auditd:PATH) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル作成 (auditd:PATH) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "AllowedDBClients | DumpFilePattern | TimeWindow",
   "detection_logic_en": "Unusual database command-line access (e.g., `psql`, `mysql`, `mongo`) from non-admin users, occurring outside typical automation windows or without known service context. Often followed by data dumps to .sql/.csv files or outbound data transfers. Defender sees CLI tools launched interactively or by unusual parent processes, file writes to dump-like filenames, and external connections shortly after."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1213.006",
   "technique_ja": "データベース",
   "technique_en": "Databases",
   "analytic_id": "AN0677",
   "detection_strategy_id": "DET0242",
   "analytic_name": "Analytic 0677",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "KnownDBToolPaths | ExportExtensionPatterns | MaxTransferVolume",
   "detection_logic_en": "Database client execution (e.g., sqlcmd.exe, isql.exe) by users or from locations not tied to enterprise automation or backups. Often followed by creation of .sql/.bak/.csv files, registry artifacts for ODBC/JDBC drivers, or encrypted ZIPs. Defender sees SQL tools launched by explorer.exe, Powershell, or odd parent processes, plus file writes in user temp locations."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1213.006",
   "technique_ja": "データベース",
   "technique_en": "Databases",
   "analytic_id": "AN0678",
   "detection_strategy_id": "DET0242",
   "analytic_name": "Analytic 0678",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "CloudSyncDomainList | UserPrivilegeLevel",
   "detection_logic_en": "Execution of Java-based or CLI database tools (e.g., DBeaver, Beekeeper, mysql, psql) from user profiles not tied to dev/admin roles, especially when followed by file writes and cloud sync activity. Defender correlates GUI tool launches, file write events in ~/Downloads or ~/Documents, and outbound API calls to known cloud services."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1213.006",
   "technique_ja": "データベース",
   "technique_en": "Databases",
   "analytic_id": "AN0679",
   "detection_strategy_id": "DET0242",
   "analytic_name": "Analytic 0679",
   "platforms": "IaaS",
   "log_sources": "Cloud Service Metadata (AWS:CloudTrail) | Cloud Storage Access (AWS:CloudTrail) | Network Connection Creation (AWS:VPCFlowLogs)",
   "log_sources_ja": "クラウドサービスメタデータ (AWS:CloudTrail) | クラウドストレージアクセス (AWS:CloudTrail) | ネットワーク接続確立 (AWS:VPCFlowLogs)",
   "tuning": "IAMAccessPatterns | S3ExportThreshold | DBQueryVerbosityThreshold",
   "detection_logic_en": "Database enumeration and export activity (e.g., `SELECT * FROM`, `SHOW DATABASES`) issued via ephemeral VMs, admin APIs, or cloud shell from non-monitoring accounts. Defender correlates audit logs (CloudTrail, GCP Admin, AzureDiagnostics), storage write ops, and cross-region transfers by identities not tied to DB operations."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1213.006",
   "technique_ja": "データベース",
   "technique_en": "Databases",
   "analytic_id": "AN0680",
   "detection_strategy_id": "DET0242",
   "analytic_name": "Analytic 0680",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (saas:Snowflake) | File Access (m365:unified)",
   "log_sources_ja": "アプリケーションログ内容 (saas:Snowflake) | ファイルアクセス (m365:unified)",
   "tuning": "BaselineQueryTemplates | OffHoursAccessWindow",
   "detection_logic_en": "Unusual or excessive database/table exports from SaaS database platforms (e.g., Snowflake, Firebase, BigQuery, Airtable) by users or apps not in known analytics or dev groups. Defender observes access patterns outside baseline working hours or with new query templates, and correlates those with audit logs or file downloads."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1530",
   "technique_ja": "クラウドストレージからのデータ",
   "technique_en": "Data from Cloud Storage",
   "analytic_id": "AN1328",
   "detection_strategy_id": "DET0484",
   "analytic_name": "Analytic 1328",
   "platforms": "IaaS",
   "log_sources": "Cloud Storage Access (AWS:CloudTrail) | User Account Metadata (AWS:CloudTrail) | Network Traffic Content (AWS:VPCFlowLogs)",
   "log_sources_ja": "クラウドストレージアクセス (AWS:CloudTrail) | ユーザーアカウントメタデータ (AWS:CloudTrail) | ネットワークトラフィック内容 (AWS:VPCFlowLogs)",
   "tuning": "TimeWindow | ExternalIPAllowList",
   "detection_logic_en": "Spike in object access from new IAM user or role followed by data exfiltration to external IPs"
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1530",
   "technique_ja": "クラウドストレージからのデータ",
   "technique_en": "Data from Cloud Storage",
   "analytic_id": "AN1329",
   "detection_strategy_id": "DET0484",
   "analytic_name": "Analytic 1329",
   "platforms": "SaaS",
   "log_sources": "Cloud Storage Access (m365:unified)",
   "log_sources_ja": "クラウドストレージアクセス (m365:unified)",
   "tuning": "AppRegistrationNamePattern | DownloadThresholdMB",
   "detection_logic_en": "OAuth token granted to external app followed by download of high-volume files in OneDrive/Google Drive"
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1530",
   "technique_ja": "クラウドストレージからのデータ",
   "technique_en": "Data from Cloud Storage",
   "analytic_id": "AN1330",
   "detection_strategy_id": "DET0484",
   "analytic_name": "Analytic 1330",
   "platforms": "Office Suite",
   "log_sources": "Cloud Storage Access (m365:sharepoint) | User Account Authentication (azure:signinlogs)",
   "log_sources_ja": "クラウドストレージアクセス (m365:sharepoint) | ユーザーアカウント認証 (azure:signinlogs)",
   "tuning": "LinkVisibilityScope | DownloadBurstThreshold",
   "detection_logic_en": "Internal user account accesses shared links outside org followed by mass file download"
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1557",
   "technique_ja": "中間者（AiTM）",
   "technique_en": "Adversary-in-the-Middle",
   "analytic_id": "AN0823",
   "detection_strategy_id": "DET0296",
   "analytic_name": "Analytic 0823",
   "platforms": "Windows",
   "log_sources": "Windows Registry Key Modification (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "Windowsレジストリキー変更 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "MonitoredRegistryPaths | DowngradeCipherList | TimeWindow",
   "detection_logic_en": "Detects suspicious DNS/ARP poisoning attempts, unauthorized modifications to registry/network configuration, or abnormal TLS downgrade activity. Correlates changes in system configuration with subsequent unusual network flows or authentication events."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1557",
   "technique_ja": "中間者（AiTM）",
   "technique_en": "Adversary-in-the-Middle",
   "analytic_id": "AN0824",
   "detection_strategy_id": "DET0296",
   "analytic_name": "Analytic 0824",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "MonitoredFiles | ARPThreshold",
   "detection_logic_en": "Detects unauthorized edits to /etc/hosts, /etc/resolv.conf, or suspicious ARP broadcasts. Correlates file modifications with subsequent unexpected network sessions or service creation."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1557",
   "technique_ja": "中間者（AiTM）",
   "technique_en": "Adversary-in-the-Middle",
   "analytic_id": "AN0825",
   "detection_strategy_id": "DET0296",
   "analytic_name": "Analytic 0825",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ProfileIdentifiers | TLSVersionThreshold",
   "detection_logic_en": "Detects unauthorized edits to system configuration profiles, unexpected certificate trust changes, or abnormal ARP/DNS patterns indicative of interception."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1557",
   "technique_ja": "中間者（AiTM）",
   "technique_en": "Adversary-in-the-Middle",
   "analytic_id": "AN0826",
   "detection_strategy_id": "DET0296",
   "analytic_name": "Analytic 0826",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Flow (NSM:Flow) | File Modification (networkdevice:config)",
   "log_sources_ja": "ネットワークトラフィックフロー (NSM:Flow) | ファイル変更 (networkdevice:config)",
   "tuning": "RoutingPolicyBaseline | FirmwareChecksum",
   "detection_logic_en": "Detects unauthorized firmware or configuration changes enabling adversary-in-the-middle positioning (e.g., route injection, DNS spoofing, SSL downgrade). Behavioral analytics focus on sudden changes to routing tables or image file integrity failures."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1557.001",
   "technique_ja": "名前解決ポイズニングとSMBリレー",
   "technique_en": "Name Resolution Poisoning and SMB Relay",
   "analytic_id": "AN1274",
   "detection_strategy_id": "DET0462",
   "analytic_name": "Analytic 1274",
   "platforms": "Windows",
   "log_sources": "Service Creation (WinEventLog:Security) | Windows Registry Key Modification (WinEventLog:Security) | Network Traffic Content (NSM:Flow) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "サービス作成 (WinEventLog:Security) | Windowsレジストリキー変更 (WinEventLog:Security) | ネットワークトラフィック内容 (NSM:Flow) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "TrustedResponderList | TimeWindow | SMBServiceBaseline",
   "detection_logic_en": "Detects anomalous network traffic on UDP 5355 (LLMNR) and UDP 137 (NBT-NS) combined with unauthorized SMB relay attempts, registry modifications re-enabling multicast name resolution, or suspicious service creation indicative of adversary-in-the-middle credential interception."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1557.002",
   "technique_ja": "ARPキャッシュポイズニング",
   "technique_en": "ARP Cache Poisoning",
   "analytic_id": "AN1091",
   "detection_strategy_id": "DET0387",
   "analytic_name": "Analytic 1091",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Flow (WinEventLog:Security)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィックフロー (WinEventLog:Security)",
   "tuning": "TrustedGatewayMAC | TimeWindow",
   "detection_logic_en": "Detects anomalous ARP traffic or cache modifications on Windows endpoints that indicate ARP poisoning. Behavioral focus is on multiple IP addresses resolving to a single MAC, or unsolicited ARP replies from unauthorized devices."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1557.002",
   "technique_ja": "ARPキャッシュポイズニング",
   "technique_en": "ARP Cache Poisoning",
   "analytic_id": "AN1092",
   "detection_strategy_id": "DET0387",
   "analytic_name": "Analytic 1092",
   "platforms": "Linux",
   "log_sources": "Network Traffic Content (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィック内容 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "AllowedARPUpdates | AlertThreshold",
   "detection_logic_en": "Detects suspicious gratuitous ARP responses or inconsistent IP-to-MAC mappings using auditd and packet capture. Behavioral focus is on unsolicited replies overriding legitimate ARP ownership."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1557.002",
   "technique_ja": "ARPキャッシュポイズニング",
   "technique_en": "ARP Cache Poisoning",
   "analytic_id": "AN1093",
   "detection_strategy_id": "DET0387",
   "analytic_name": "Analytic 1093",
   "platforms": "macOS",
   "log_sources": "Network Traffic Flow (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィックフロー (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "GatewayMACBaseline | CorrelationDepth",
   "detection_logic_en": "Detects anomalous ARP cache changes and unsolicited ARP broadcasts using unified logs and packet capture. Behavioral detection includes multiple IP addresses mapped to the same MAC address and repeated gratuitous ARP traffic."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1557.003",
   "technique_ja": "DHCPスプーフィング",
   "technique_en": "DHCP Spoofing",
   "analytic_id": "AN1290",
   "detection_strategy_id": "DET0468",
   "analytic_name": "Analytic 1290",
   "platforms": "Windows",
   "log_sources": "Application Log Content (WinEventLog:System) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (WinEventLog:System) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "AuthorizedDHCPServers | TimeWindow",
   "detection_logic_en": "Detects rogue DHCP server activity and anomalous DHCP OFFER/ACK messages assigning unexpected DNS or gateway values. Detection correlates DHCP server role changes, DHCP exhaustion warnings, and sudden network configuration changes across endpoints."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1557.003",
   "technique_ja": "DHCPスプーフィング",
   "technique_en": "DHCP Spoofing",
   "analytic_id": "AN1291",
   "detection_strategy_id": "DET0468",
   "analytic_name": "Analytic 1291",
   "platforms": "Linux",
   "log_sources": "Application Log Content (linux:syslog) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (linux:syslog) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "AllowedDHCPMACs | DHCPLeaseChangeThreshold",
   "detection_logic_en": "Detects rogue DHCP activity by monitoring syslog for dhclient messages assigning unauthorized DNS/gateway values. Packet capture or IDS can detect multiple competing DHCP OFFERs from non-authorized servers."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1557.003",
   "technique_ja": "DHCPスプーフィング",
   "technique_en": "DHCP Spoofing",
   "analytic_id": "AN1292",
   "detection_strategy_id": "DET0468",
   "analytic_name": "Analytic 1292",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "BaselineDNS | AlertSensitivity",
   "detection_logic_en": "Detects DHCP spoofing by monitoring unified logs for unexpected DHCP ACK/OFFER parameters and correlating with packet captures for multiple DHCP servers. Behavioral emphasis is on inconsistent DNS and gateway assignments that redirect traffic."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1557.004",
   "technique_ja": "イーブルツイン",
   "technique_en": "Evil Twin",
   "analytic_id": "AN1069",
   "detection_strategy_id": "DET0379",
   "analytic_name": "Analytic 1069",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Flow (WLANLogs:Association) | Network Traffic Content (NSM:Flow) | Application Log Content (networkdevice:syslog)",
   "log_sources_ja": "ネットワークトラフィックフロー (WLANLogs:Association) | ネットワークトラフィック内容 (NSM:Flow) | アプリケーションログ内容 (networkdevice:syslog)",
   "tuning": "KnownSSIDs | AllowedBSSIDs | SignalStrengthThreshold | CaptivePortalDomains",
   "detection_logic_en": "Detects rogue Wi-Fi access points broadcasting the same SSID as legitimate APs with stronger signal strength, unexpected MAC/BSSID values, or inconsistent encryption settings. Correlates authentication attempts, captive portal redirections, and anomalous traffic flows through unauthorized APs."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1560",
   "technique_ja": "収集データのアーカイブ",
   "technique_en": "Archive Collected Data",
   "analytic_id": "AN1458",
   "detection_strategy_id": "DET0526",
   "analytic_name": "Analytic 1458",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "ArchiveExtensions | ProcessAllowlist | FileSizeThresholdMB",
   "detection_logic_en": "Detects adversarial archiving of files prior to exfiltration by correlating execution of compression/encryption utilities (e.g., makecab.exe, rar.exe, 7z.exe, powershell Compress-Archive) with subsequent creation of large compressed or encrypted files. Identifies abnormal process lineage involving crypt32.dll usage, command-line arguments invoking compression switches, and file write operations to temporary or staging directories."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1560",
   "technique_ja": "収集データのアーカイブ",
   "technique_en": "Archive Collected Data",
   "analytic_id": "AN1459",
   "detection_strategy_id": "DET0526",
   "analytic_name": "Analytic 1459",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | File Creation (auditd:FILE)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ファイル作成 (auditd:FILE)",
   "tuning": "ArchiveCommands | SuspiciousDirectories | TimeWindow",
   "detection_logic_en": "Detects adversarial archiving activity through invocation of utilities like tar, gzip, bzip2, or openssl used in non-administrative or unusual contexts. Correlates command execution patterns with file creation of compressed/encrypted outputs in staging directories (e.g., /tmp, /var/tmp)."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1560",
   "technique_ja": "収集データのアーカイブ",
   "technique_en": "Archive Collected Data",
   "analytic_id": "AN1460",
   "detection_strategy_id": "DET0526",
   "analytic_name": "Analytic 1460",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:unifiedlog)",
   "tuning": "AllowedArchiveUtilities | UserContext | PayloadEntropyThreshold",
   "detection_logic_en": "Detects use of macOS-native archiving or encryption tools (zip, ditto, hdiutil) for staging collected data. Identifies unexpected invocation of archive utilities by Office apps, browsers, or background daemons. Correlates file creation of .zip/.dmg containers with process lineage anomalies."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1560.001",
   "technique_ja": "ユーティリティによるアーカイブ",
   "technique_en": "Archive via Utility",
   "analytic_id": "AN0831",
   "detection_strategy_id": "DET0298",
   "analytic_name": "Analytic 0831",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "SuspiciousExtensions | ProcessAllowlist | FileSizeThresholdMB",
   "detection_logic_en": "Detects adversarial archiving using built-in or third-party utilities (makecab, diantz, xcopy, certutil, 7z, WinRAR, WinZip). Correlates suspicious process creation events with command-line arguments for compression/encoding, followed by creation of archive files (.cab, .zip, .7z, .rar). Identifies anomalous loading of crypt32.dll for encryption operations or execution of diantz.exe to compress remotely staged files."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1560.001",
   "technique_ja": "ユーティリティによるアーカイブ",
   "technique_en": "Archive via Utility",
   "analytic_id": "AN0832",
   "detection_strategy_id": "DET0298",
   "analytic_name": "Analytic 0832",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | File Creation (auditd:FILE)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ファイル作成 (auditd:FILE)",
   "tuning": "ArchiveCommands | MonitoredDirectories | TimeWindow",
   "detection_logic_en": "Detects execution of archiving utilities (tar, gzip, bzip2, xz, zip, openssl) followed by suspicious archive file creation. Correlates archive creation in temporary or staging directories with execution of commands involving compression or encryption options."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1560.001",
   "technique_ja": "ユーティリティによるアーカイブ",
   "technique_en": "Archive via Utility",
   "analytic_id": "AN0833",
   "detection_strategy_id": "DET0298",
   "analytic_name": "Analytic 0833",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:unifiedlog)",
   "tuning": "AllowedArchivers | UserContext | PayloadEntropyThreshold",
   "detection_logic_en": "Detects invocation of macOS-native archiving utilities (zip, ditto, hdiutil) or openssl used for encryption. Correlates execution with archive or encrypted file creation (.zip, .dmg, .tar.gz) in user or temporary directories. Identifies anomalous use of archiving commands by Office applications or daemons."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1560.002",
   "technique_ja": "ライブラリによるアーカイブ",
   "technique_en": "Archive via Library",
   "analytic_id": "AN0747",
   "detection_strategy_id": "DET0268",
   "analytic_name": "Analytic 0747",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Module Load (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | モジュール読み込み (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "LibraryAllowlist | SuspiciousExtensions | TimeWindow",
   "detection_logic_en": "Detects adversarial archiving using libraries (zlib, zip APIs) invoked by scripts or binaries. Correlates process executions of Python, PowerShell, or custom .NET binaries with DLL/module loads linked to compression libraries, followed by archive file creation."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1560.002",
   "technique_ja": "ライブラリによるアーカイブ",
   "technique_en": "Archive via Library",
   "analytic_id": "AN0748",
   "detection_strategy_id": "DET0268",
   "analytic_name": "Analytic 0748",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | Module Load (auditd:MMAP) | File Creation (auditd:FILE)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | モジュール読み込み (auditd:MMAP) | ファイル作成 (auditd:FILE)",
   "tuning": "MonitoredLibraries | ArchivePaths | EntropyThreshold",
   "detection_logic_en": "Detects adversarial archiving by scripts or binaries calling compression libraries (libzip, zlib, bzip2). Correlates execution of Python, Perl, or compiled binaries with dynamic linking to archiving libraries and creation of compressed files in /tmp or user directories."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1560.002",
   "technique_ja": "ライブラリによるアーカイブ",
   "technique_en": "Archive via Library",
   "analytic_id": "AN0749",
   "detection_strategy_id": "DET0268",
   "analytic_name": "Analytic 0749",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Module Load (macos:unifiedlog) | File Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | モジュール読み込み (macos:unifiedlog) | ファイル作成 (macos:unifiedlog)",
   "tuning": "AllowedProcesses | UserContext | FileExtensionFilter",
   "detection_logic_en": "Detects malicious archiving via system or third-party libraries (libz, libarchive) invoked by Python, Swift, or Objective-C binaries. Correlates unified logs of library loads with creation of compressed or encrypted archives (.zip, .gz, .bz2, .dmg)."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1560.003",
   "technique_ja": "独自方式によるアーカイブ",
   "technique_en": "Archive via Custom Method",
   "analytic_id": "AN1213",
   "detection_strategy_id": "DET0438",
   "analytic_name": "Analytic 1213",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon)",
   "tuning": "EntropyThreshold | AllowedProcesses | TimeWindow",
   "detection_logic_en": "Detects suspicious custom compression/encryption routines through anomalous script or binary execution that produces high-entropy files without standard archiving utilities. Correlates script execution, memory API usage (bitwise ops, CryptoAPI calls), and creation of archive-like files with uncommon headers."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1560.003",
   "technique_ja": "独自方式によるアーカイブ",
   "technique_en": "Archive via Custom Method",
   "analytic_id": "AN1214",
   "detection_strategy_id": "DET0438",
   "analytic_name": "Analytic 1214",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | File Creation (auditd:FILE) | Process Modification (linux:osquery)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ファイル作成 (auditd:FILE) | プロセス変更 (linux:osquery)",
   "tuning": "ArchivePaths | EntropyThreshold | ScriptAllowlist",
   "detection_logic_en": "Detects custom archive routines by correlating script execution (Python, Perl, Bash) with creation of high-entropy files in temporary or user directories. Flags processes performing unusual bitwise operations or writing files without standard compression headers."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1560.003",
   "technique_ja": "独自方式によるアーカイブ",
   "technique_en": "Archive via Custom Method",
   "analytic_id": "AN1215",
   "detection_strategy_id": "DET0438",
   "analytic_name": "Analytic 1215",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (macos:unifiedlog) | Process Modification (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:unifiedlog) | プロセス変更 (macos:unifiedlog)",
   "tuning": "UserContext | EntropyThreshold | AllowedApps",
   "detection_logic_en": "Detects custom archiving by monitoring execution of Swift/Objective-C apps or scripts producing high-entropy files with non-standard headers. Correlates unified logs of abnormal NSFileHandle/NSData operations, memory use of XOR/bitwise operations, and file creation events."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1602",
   "technique_ja": "構成リポジトリからのデータ",
   "technique_en": "Data from Configuration Repository",
   "analytic_id": "AN1630",
   "detection_strategy_id": "DET0592",
   "analytic_name": "Analytic 1630",
   "platforms": "Network Devices",
   "log_sources": "Network Connection Creation (NSM:Flow) | Network Traffic Content (networkdevice:syslog)",
   "log_sources_ja": "ネットワーク接続確立 (NSM:Flow) | ネットワークトラフィック内容 (networkdevice:syslog)",
   "tuning": "AuthorizedAdminIPs | NormalAccessTimeWindow | QueryVolumeThreshold | ProtocolUsageBaseline",
   "detection_logic_en": "Defenders may observe adversary attempts to extract configuration data from management repositories by monitoring for anomalous SNMP queries, API calls, or protocol requests (e.g., NETCONF, RESTCONF) that enumerate system configuration. Suspicious sequences include repeated queries from untrusted IPs, abnormal query types requesting sensitive configuration data, or repository access occurring outside of normal administrative maintenance windows. Abnormal authentication attempts, sudden enumeration of device inventory, or bulk data transfer of configuration files may also be observed."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1602.001",
   "technique_ja": "SNMP（MIBダンプ）",
   "technique_en": "SNMP (MIB Dump)",
   "analytic_id": "AN1249",
   "detection_strategy_id": "DET0453",
   "analytic_name": "Analytic 1249",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Content (networkdevice:syslog) | Network Connection Creation (NSM:Flow) | File Modification (networkdevice:audit)",
   "log_sources_ja": "ネットワークトラフィック内容 (networkdevice:syslog) | ネットワーク接続確立 (NSM:Flow) | ファイル変更 (networkdevice:audit)",
   "tuning": "AuthorizedAdminIPs | NormalSNMPQueryRate | CommunityStringPatterns | TimeWindow",
   "detection_logic_en": "Defenders may observe suspicious SNMP MIB enumeration through abnormal queries for large sets of OIDs, repeated SNMP GETBULK/GETNEXT requests, or queries originating from non-administrative IP addresses. Anomalous use of community strings, authentication failures, or enumeration activity outside maintenance windows may also indicate attempts to dump MIB contents. Correlation across syslog, NetFlow, and SNMP audit data can reveal chains of behavior such as repeated authentication failures followed by successful large-scale OID retrieval."
  },
  {
   "tactic_id": "TA0009",
   "tactic_ja": "収集",
   "technique_id": "T1602.002",
   "technique_ja": "ネットワークデバイス構成ダンプ",
   "technique_en": "Network Device Configuration Dump",
   "analytic_id": "AN0647",
   "detection_strategy_id": "DET0233",
   "analytic_name": "Analytic 0647",
   "platforms": "Network Devices",
   "log_sources": "User Account Authentication (networkdevice:syslog) | Command Execution (networkdevice:cli) | Network Traffic Content (NSM:Flow) | Network Connection Creation (snmp:access)",
   "log_sources_ja": "ユーザーアカウント認証 (networkdevice:syslog) | コマンド実行 (networkdevice:cli) | ネットワークトラフィック内容 (NSM:Flow) | ネットワーク接続確立 (snmp:access)",
   "tuning": "AuthorizedAdminIPs | NormalConfigExportRate | AllowedTransferProtocols | TimeWindow",
   "detection_logic_en": "Defenders may observe adversary attempts to collect or export full device configurations by detecting unusual SNMP queries, Smart Install (SMI) activity, or CLI/API commands that request running or startup configuration dumps. Correlated behaviors include high-volume read requests for sensitive OIDs, repeated use of 'show running-config' or equivalent commands from untrusted IPs, or unexpected TFTP/SCP/FTP transfers containing configuration files. These behaviors often appear in sequence: anomalous authentication or privilege escalation, followed by bulk configuration retrieval and outbound transfer."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1001",
   "technique_ja": "データ難読化",
   "technique_en": "Data Obfuscation",
   "analytic_id": "AN0144",
   "detection_strategy_id": "DET0053",
   "analytic_name": "Analytic 0144",
   "platforms": "Windows",
   "log_sources": "Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "OutboundByteThreshold | ProcessAllowlist",
   "detection_logic_en": "Detects excessive outbound traffic to remote host over HTTP(S) from uncommon or previously unseen processes."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1001",
   "technique_ja": "データ難読化",
   "technique_en": "Data Obfuscation",
   "analytic_id": "AN0145",
   "detection_strategy_id": "DET0053",
   "analytic_name": "Analytic 0145",
   "platforms": "Linux",
   "log_sources": "Network Connection Creation (auditd:SYSCALL)",
   "log_sources_ja": "ネットワーク接続確立 (auditd:SYSCALL)",
   "tuning": "UserProcessBaseline",
   "detection_logic_en": "Identifies custom or previously unseen userland processes initiating high-volume HTTP connections with low response volume."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1001",
   "technique_ja": "データ難読化",
   "technique_en": "Data Obfuscation",
   "analytic_id": "AN0146",
   "detection_strategy_id": "DET0053",
   "analytic_name": "Analytic 0146",
   "platforms": "macOS",
   "log_sources": "Network Traffic Content (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ネットワークトラフィック内容 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "SessionDuration",
   "detection_logic_en": "Flags unexpected user applications initiating long-lived HTTP(S) sessions with irregular traffic patterns."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1001.001",
   "technique_ja": "ジャンクデータ",
   "technique_en": "Junk Data",
   "analytic_id": "AN0030",
   "detection_strategy_id": "DET0011",
   "analytic_name": "Analytic 0030",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Access (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセスアクセス (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "PayloadEntropyThreshold | TimeWindow | UserContext",
   "detection_logic_en": "Processes generating large outbound connections with disproportionate send/receive ratios, often to uncommon ports or hosts, potentially inserting meaningless data into protocol payloads."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1001.001",
   "technique_ja": "ジャンクデータ",
   "technique_en": "Junk Data",
   "analytic_id": "AN0031",
   "detection_strategy_id": "DET0011",
   "analytic_name": "Analytic 0031",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "EntropyScore | ProcessWhitelist | DataRatioThreshold",
   "detection_logic_en": "Outbound traffic with anomalous payload sizes and patterns from non-networking processes, often observed via packet inspection or connection logs."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1001.001",
   "technique_ja": "ジャンクデータ",
   "technique_en": "Junk Data",
   "analytic_id": "AN0032",
   "detection_strategy_id": "DET0011",
   "analytic_name": "Analytic 0032",
   "platforms": "macOS",
   "log_sources": "Network Connection Creation (macos:unifiedlog) | Process Creation (macos:osquery) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (macos:unifiedlog) | プロセス生成 (macos:osquery) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ParentProcessCheck | HostWhitelist",
   "detection_logic_en": "Previously unseen applications generating outbound connections with atypical data flow characteristics, such as excessive data with no return response."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1001.001",
   "technique_ja": "ジャンクデータ",
   "technique_en": "Junk Data",
   "analytic_id": "AN0033",
   "detection_strategy_id": "DET0011",
   "analytic_name": "Analytic 0033",
   "platforms": "ESXi",
   "log_sources": "Network Traffic Content (esxi:vmkernel) | Network Connection Creation (esxi:hostd)",
   "log_sources_ja": "ネットワークトラフィック内容 (esxi:vmkernel) | ネットワーク接続確立 (esxi:hostd)",
   "tuning": "TLSFingerprintMismatch | UnusualDestinationPorts",
   "detection_logic_en": "Anomalous traffic from ESXi host management daemons (like hostd or vpxa) embedding non-standard payloads in management protocols (e.g., HTTPS) or beaconing behavior."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1001.002",
   "technique_ja": "ステガノグラフィ",
   "technique_en": "Steganography",
   "analytic_id": "AN0651",
   "detection_strategy_id": "DET0235",
   "analytic_name": "Analytic 0651",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "FileExtensionFilter | PayloadEntropyThreshold | ExecutionToExfilTimeWindow",
   "detection_logic_en": "Detect the creation or modification of common media file formats (e.g., .jpg, .png, .wav) following suspicious process activity like compression or encryption, especially when paired with lateral movement or exfiltration behavior."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1001.002",
   "technique_ja": "ステガノグラフィ",
   "technique_en": "Steganography",
   "analytic_id": "AN0652",
   "detection_strategy_id": "DET0235",
   "analytic_name": "Analytic 0652",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow) | File Metadata (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow) | ファイルメタデータ (NSM:Flow)",
   "tuning": "ToolNameMatch | OutboundTrafficPattern",
   "detection_logic_en": "Unusual use of steganographic or media processing binaries (e.g., `steghide`, `ffmpeg`, `imagemagick`) followed by outbound communication to external IPs with high data output and media MIME types."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1001.002",
   "technique_ja": "ステガノグラフィ",
   "technique_en": "Steganography",
   "analytic_id": "AN0653",
   "detection_strategy_id": "DET0235",
   "analytic_name": "Analytic 0653",
   "platforms": "macOS",
   "log_sources": "File Creation (macos:unifiedlog) | Process Creation (macos:osquery) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ファイル作成 (macos:unifiedlog) | プロセス生成 (macos:osquery) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ParentProcessBaseline | TimeDelta",
   "detection_logic_en": "Abnormal usage of Preview, ImageMagick, or binary editors to alter images/documents, followed by exfiltration or outbound connections with mismatched file MIME types or payload structure."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1001.002",
   "technique_ja": "ステガノグラフィ",
   "technique_en": "Steganography",
   "analytic_id": "AN0654",
   "detection_strategy_id": "DET0235",
   "analytic_name": "Analytic 0654",
   "platforms": "ESXi",
   "log_sources": "File Metadata (esxi:vmkernel) | Network Connection Creation (esxi:hostd) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ファイルメタデータ (esxi:vmkernel) | ネットワーク接続確立 (esxi:hostd) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "FilenamePattern | UnusualDestinationIP",
   "detection_logic_en": "Suspicious modification of file artifacts (e.g., logs, ISO templates) on ESXi datastores, followed by beaconing or POST operations to external IPs potentially hiding payloads in file-like traffic."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1001.003",
   "technique_ja": "プロトコル/サービスのなりすまし",
   "technique_en": "Protocol or Service Impersonation",
   "analytic_id": "AN1294",
   "detection_strategy_id": "DET0470",
   "analytic_name": "Analytic 1294",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "IssuerOrgFilter | UserContext | HeaderSignatureMatch",
   "detection_logic_en": "Untrusted processes creating outbound TLS/HTTPS connections with malformed certificates or header fields, often mismatched with target service behavior. Detects protocol impersonation attempts via traffic metadata analysis and host process lineage."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1001.003",
   "technique_ja": "プロトコル/サービスのなりすまし",
   "technique_en": "Protocol or Service Impersonation",
   "analytic_id": "AN1295",
   "detection_strategy_id": "DET0470",
   "analytic_name": "Analytic 1295",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ProtocolMatchConfidence | TimeWindow",
   "detection_logic_en": "Detection of binaries spawning encrypted sessions using OpenSSL or curl to external services with mismatched ports/protocols. Identifies behavior where internal services simulate trusted cloud service traffic patterns."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1001.003",
   "technique_ja": "プロトコル/サービスのなりすまし",
   "technique_en": "Protocol or Service Impersonation",
   "analytic_id": "AN1296",
   "detection_strategy_id": "DET0470",
   "analytic_name": "Analytic 1296",
   "platforms": "macOS",
   "log_sources": "Network Connection Creation (macos:unifiedlog) | Process Metadata (macos:osquery) | Network Traffic Content (NSM:Content)",
   "log_sources_ja": "ネットワーク接続確立 (macos:unifiedlog) | プロセスメタデータ (macos:osquery) | ネットワークトラフィック内容 (NSM:Content)",
   "tuning": "ParentProcessFilter | HeaderAnomalyScore",
   "detection_logic_en": "Unsigned or suspicious applications initiating network traffic claiming to be browser, mail, or cloud clients. Detects impersonation via TLS fingerprint and User-Agent string deviation."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1001.003",
   "technique_ja": "プロトコル/サービスのなりすまし",
   "technique_en": "Protocol or Service Impersonation",
   "analytic_id": "AN1297",
   "detection_strategy_id": "DET0470",
   "analytic_name": "Analytic 1297",
   "platforms": "ESXi",
   "log_sources": "Network Connection Creation (esxi:hostd) | Network Traffic Content (NSM:Content)",
   "log_sources_ja": "ネットワーク接続確立 (esxi:hostd) | ネットワークトラフィック内容 (NSM:Content)",
   "tuning": "TLSFingerprintMatch | AllowedServicePorts",
   "detection_logic_en": "ESXi hosts initiating connections from non-standard daemons mimicking HTTP/HTTPS or SNMP traffic, but with irregular payload formats or expired/unsigned TLS certificates."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1008",
   "technique_ja": "フォールバックチャネル",
   "technique_en": "Fallback Channels",
   "analytic_id": "AN1376",
   "detection_strategy_id": "DET0499",
   "analytic_name": "Analytic 1376",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "DestinationPort | ProcessName | DataVolumeRatio | TimeWindow",
   "detection_logic_en": "Establishing network connections on uncommon ports or protocols following C2 disruption or blocking. Often executed by processes that typically exhibit no network activity."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1008",
   "technique_ja": "フォールバックチャネル",
   "technique_en": "Fallback Channels",
   "analytic_id": "AN1377",
   "detection_strategy_id": "DET0499",
   "analytic_name": "Analytic 1377",
   "platforms": "Linux",
   "log_sources": "Network Connection Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "ProtocolType | UserContext",
   "detection_logic_en": "Creation of outbound connections on alternate ports or using covert transport (e.g., ICMP, DNS) from non-network-intensive processes, following known disruption or blocked traffic."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1008",
   "technique_ja": "フォールバックチャネル",
   "technique_en": "Fallback Channels",
   "analytic_id": "AN1378",
   "detection_strategy_id": "DET0499",
   "analytic_name": "Analytic 1378",
   "platforms": "macOS",
   "log_sources": "Network Connection Creation (macos:unifiedlog) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (macos:unifiedlog) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "LaunchAgentContext | PayloadEntropy",
   "detection_logic_en": "Outbound fallback traffic from low-profile or background launch agents using unusual protocols or destinations after primary channel inactivity."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1008",
   "technique_ja": "フォールバックチャネル",
   "technique_en": "Fallback Channels",
   "analytic_id": "AN1379",
   "detection_strategy_id": "DET0499",
   "analytic_name": "Analytic 1379",
   "platforms": "ESXi",
   "log_sources": "Network Connection Creation (esxi:vmkernel) | Network Traffic Flow (esxi:vpxd)",
   "log_sources_ja": "ネットワーク接続確立 (esxi:vmkernel) | ネットワークトラフィックフロー (esxi:vpxd)",
   "tuning": "InterfaceName | FallbackIPRanges",
   "detection_logic_en": "Outbound traffic from host management services or guest-to-host interactions over unusual interfaces (e.g., backdoor API endpoints or external VPN tunnels)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071",
   "technique_ja": "アプリケーション層プロトコル",
   "technique_en": "Application Layer Protocol",
   "analytic_id": "AN1225",
   "detection_strategy_id": "DET0444",
   "analytic_name": "Analytic 1225",
   "platforms": "Windows",
   "log_sources": "Network Traffic Content (NSM:Flow) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "ProtocolList | DataVolumeThreshold | UnusualProcessList",
   "detection_logic_en": "Detects suspicious usage of common application-layer protocols (e.g., HTTP, HTTPS, DNS, SMB) by abnormal processes, with high outbound byte counts or irregular ports, possibly indicating command and control or data exfiltration."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071",
   "technique_ja": "アプリケーション層プロトコル",
   "technique_en": "Application Layer Protocol",
   "analytic_id": "AN1226",
   "detection_strategy_id": "DET0444",
   "analytic_name": "Analytic 1226",
   "platforms": "Linux",
   "log_sources": "Network Traffic Content (NSM:Flow) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "KnownPortsToMonitor | BeaconTimingThreshold",
   "detection_logic_en": "Detects suspicious curl, wget, or custom socket traffic that leverages DNS, HTTPS, or IRC-style protocols with unbalanced traffic or beacon-like intervals."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071",
   "technique_ja": "アプリケーション層プロトコル",
   "technique_en": "Application Layer Protocol",
   "analytic_id": "AN1227",
   "detection_strategy_id": "DET0444",
   "analytic_name": "Analytic 1227",
   "platforms": "macOS",
   "log_sources": "Network Traffic Flow (macos:osquery) | Command Execution (macos:unifiedlog)",
   "log_sources_ja": "ネットワークトラフィックフロー (macos:osquery) | コマンド実行 (macos:unifiedlog)",
   "tuning": "SocketParentProcessMatch | DataFlowImbalanceRatio",
   "detection_logic_en": "Detects applications using abnormal protocols or high volume traffic not previously associated with the process image, such as Automator or AppleScript invoking curl or python sockets."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071",
   "technique_ja": "アプリケーション層プロトコル",
   "technique_en": "Application Layer Protocol",
   "analytic_id": "AN1228",
   "detection_strategy_id": "DET0444",
   "analytic_name": "Analytic 1228",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "AppProtocolAbusePattern | NorthSouthEgressFilter",
   "detection_logic_en": "Detects application-layer tunneling or unauthorized app protocols like DNS-over-HTTPS, embedded C2 in TLS/HTTP headers, or misused SMB traffic crossing VLANs."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.001",
   "technique_ja": "Webプロトコル",
   "technique_en": "Web Protocols",
   "analytic_id": "AN0075",
   "detection_strategy_id": "DET0027",
   "analytic_name": "Analytic 0075",
   "platforms": "Windows",
   "log_sources": "Network Traffic Content (NSM:Flow) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "ProcessNameExclusions | UserAgentAnomalies | OutboundByteRatioThreshold",
   "detection_logic_en": "Detects unexpected or high-volume HTTP/S/WebSocket communication from suspicious processes (e.g., PowerShell, rundll32) using uncommon user agents or mimicking browser traffic to unusual domains or IPs."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.001",
   "technique_ja": "Webプロトコル",
   "technique_en": "Web Protocols",
   "analytic_id": "AN0076",
   "detection_strategy_id": "DET0027",
   "analytic_name": "Analytic 0076",
   "platforms": "Linux",
   "log_sources": "Network Traffic Content (NSM:Flow) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "CommandLinePatternMatch | BeaconIntervalWindow",
   "detection_logic_en": "Detects curl, wget, Python requests, or custom HTTP clients communicating over non-standard ports, with repetitive or beacon-like patterns or POST-heavy behavior to rare domains."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.001",
   "technique_ja": "Webプロトコル",
   "technique_en": "Web Protocols",
   "analytic_id": "AN0077",
   "detection_strategy_id": "DET0027",
   "analytic_name": "Analytic 0077",
   "platforms": "macOS",
   "log_sources": "Network Traffic Flow (macos:osquery) | Command Execution (macos:unifiedlog)",
   "log_sources_ja": "ネットワークトラフィックフロー (macos:osquery) | コマンド実行 (macos:unifiedlog)",
   "tuning": "SuspiciousParentProcess | URIEntropyThreshold",
   "detection_logic_en": "Detects applications such as Automator, AppleScript, or LaunchDaemons invoking HTTP/S traffic to non-standard domains or using suspicious headers (e.g., Base64 in URIs or cookie fields)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.001",
   "technique_ja": "Webプロトコル",
   "technique_en": "Web Protocols",
   "analytic_id": "AN0078",
   "detection_strategy_id": "DET0027",
   "analytic_name": "Analytic 0078",
   "platforms": "ESXi",
   "log_sources": "Network Traffic Content (NSM:Flow) | Process Creation (esxi:shell)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow) | プロセス生成 (esxi:shell)",
   "tuning": "ShellScriptMatch | ExternalConnectionFilter",
   "detection_logic_en": "Detects HTTP or HTTPS communication initiated by shell-based scripts or management daemons, especially those reaching public IPs over ports 80/443 using embedded curl or wget."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.001",
   "technique_ja": "Webプロトコル",
   "technique_en": "Web Protocols",
   "analytic_id": "AN0079",
   "detection_strategy_id": "DET0027",
   "analytic_name": "Analytic 0079",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "HeaderEncodingPattern | TLSFingerprintMismatch",
   "detection_logic_en": "Detects Web protocol misuse such as encoded HTTP headers, WebSocket upgrade requests with abnormal payloads, or TLS handshake anomalies suggesting embedded C2 channels."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.002",
   "technique_ja": "ファイル転送プロトコル",
   "technique_en": "File Transfer Protocols",
   "analytic_id": "AN1169",
   "detection_strategy_id": "DET0416",
   "analytic_name": "Analytic 1169",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ProcessImageFilter | DataFlowDirectionThreshold | FilenamePattern",
   "detection_logic_en": "Detects FTP, SMB, or TFTP traffic initiated by suspicious processes like PowerShell, cmd.exe, or rundll32.exe—especially with large outbound file transfers or unbalanced traffic volume."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.002",
   "technique_ja": "ファイル転送プロトコル",
   "technique_en": "File Transfer Protocols",
   "analytic_id": "AN1170",
   "detection_strategy_id": "DET0416",
   "analytic_name": "Analytic 1170",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TransferSizeThreshold | CommandLinePatternMatch",
   "detection_logic_en": "Detects usage of FTP, SCP, or TFTP by non-interactive shells or automation scripts transferring large data volumes to untrusted IPs."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.002",
   "technique_ja": "ファイル転送プロトコル",
   "technique_en": "File Transfer Protocols",
   "analytic_id": "AN1171",
   "detection_strategy_id": "DET0416",
   "analytic_name": "Analytic 1171",
   "platforms": "macOS",
   "log_sources": "Network Traffic Flow (macos:osquery) | Command Execution (macos:unifiedlog)",
   "log_sources_ja": "ネットワークトラフィックフロー (macos:osquery) | コマンド実行 (macos:unifiedlog)",
   "tuning": "FilePathAccessed | NetworkPortAnomaly",
   "detection_logic_en": "Detects Automator, AppleScript, or Terminal executing curl, lftp, or TFTP for binary transfer to untrusted IPs or unusual ports."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.002",
   "technique_ja": "ファイル転送プロトコル",
   "technique_en": "File Transfer Protocols",
   "analytic_id": "AN1172",
   "detection_strategy_id": "DET0416",
   "analytic_name": "Analytic 1172",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:shell) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (esxi:shell) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TransferTargetDomainOrIP | SourceDirectoryFilter",
   "detection_logic_en": "Detects file movement or outbound TFTP/FTP transfers from ESXi host initiated via shell commands or injected scripts, particularly from scratch partitions or /tmp."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.002",
   "technique_ja": "ファイル転送プロトコル",
   "technique_en": "File Transfer Protocols",
   "analytic_id": "AN1173",
   "detection_strategy_id": "DET0416",
   "analytic_name": "Analytic 1173",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "AppLayerProtocolMatch | OutboundDataRateThreshold",
   "detection_logic_en": "Detects internal hosts generating large outbound FTP/TFTP/SMB sessions to external IPs, or file transfers using non-standard ports and application mismatches (e.g., FTP over port 80)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.003",
   "technique_ja": "メールプロトコル",
   "technique_en": "Mail Protocols",
   "analytic_id": "AN0379",
   "detection_strategy_id": "DET0135",
   "analytic_name": "Analytic 0379",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ProcessImageName | DestPortFilter | AttachmentType",
   "detection_logic_en": "Detects unauthorized use of SMTP/IMAP/POP3 by suspicious binaries (e.g., PowerShell, rundll32) to exfiltrate data or beacon via email, often bypassing proxy or content filters."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.003",
   "technique_ja": "メールプロトコル",
   "technique_en": "Mail Protocols",
   "analytic_id": "AN0380",
   "detection_strategy_id": "DET0135",
   "analytic_name": "Analytic 0380",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TransferSizeThreshold | ScriptNameFilter",
   "detection_logic_en": "Detects non-interactive or script-driven email transmission using tools like `sendmail`, `mailx`, or custom SMTP scripts by background processes, especially when sending attachments or large payloads."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.003",
   "technique_ja": "メールプロトコル",
   "technique_en": "Mail Protocols",
   "analytic_id": "AN0381",
   "detection_strategy_id": "DET0135",
   "analytic_name": "Analytic 0381",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Flow (macos:osquery)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィックフロー (macos:osquery)",
   "tuning": "UserContext | TimeWindow",
   "detection_logic_en": "Detects email-sending behavior via Terminal, AppleScript, or Automator that interfaces with SMTP or IMAP, typically using curl or mail-related APIs in unsanctioned contexts."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.003",
   "technique_ja": "メールプロトコル",
   "technique_en": "Mail Protocols",
   "analytic_id": "AN0382",
   "detection_strategy_id": "DET0135",
   "analytic_name": "Analytic 0382",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ExternalMailRelayFilter | OutflowToInflowRatio",
   "detection_logic_en": "Detects hosts transmitting large volumes of SMTP, IMAP, or POP3 traffic to external IPs or relays that aren't associated with the enterprise mail infrastructure."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.004",
   "technique_ja": "DNS",
   "technique_en": "DNS",
   "analytic_id": "AN1121",
   "detection_strategy_id": "DET0400",
   "analytic_name": "Analytic 1121",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "QueryLengthThreshold | ProcessImageFilter | TimeWindow",
   "detection_logic_en": "Detects high-frequency or anomalous DNS queries initiated by non-browser, non-system processes (e.g., PowerShell, rundll32, python.exe) used to establish command and control via DNS tunneling."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.004",
   "technique_ja": "DNS",
   "technique_en": "DNS",
   "analytic_id": "AN1122",
   "detection_strategy_id": "DET0400",
   "analytic_name": "Analytic 1122",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "SubdomainEntropyScore | DaemonAllowList",
   "detection_logic_en": "Detects local daemons or scripts generating outbound DNS queries with long or frequent subdomains, indicative of DNS tunneling via tools like `iodine`, `dnscat2`, or `dig` from cronjobs or reverse shells."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.004",
   "technique_ja": "DNS",
   "technique_en": "DNS",
   "analytic_id": "AN1123",
   "detection_strategy_id": "DET0400",
   "analytic_name": "Analytic 1123",
   "platforms": "macOS",
   "log_sources": "Network Traffic Flow (macos:unifiedlog)",
   "log_sources_ja": "ネットワークトラフィックフロー (macos:unifiedlog)",
   "tuning": "EntropyThreshold | UncommonProcessContext",
   "detection_logic_en": "Detects scripting environments (AppleScript, osascript, curl) or non-native tools performing DNS queries with encoded subdomains, often used for data exfiltration or beaconing."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.004",
   "technique_ja": "DNS",
   "technique_en": "DNS",
   "analytic_id": "AN1124",
   "detection_strategy_id": "DET0400",
   "analytic_name": "Analytic 1124",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "DomainReputationFeed | QueryRatePerClient",
   "detection_logic_en": "Detects clients issuing DNS queries with high volume, long subdomain lengths, encoded payload patterns, or to known malicious infrastructure; indicative of DNS-based C2 channels."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.004",
   "technique_ja": "DNS",
   "technique_en": "DNS",
   "analytic_id": "AN1125",
   "detection_strategy_id": "DET0400",
   "analytic_name": "Analytic 1125",
   "platforms": "ESXi",
   "log_sources": "Network Traffic Flow (esxi:syslog) | Network Traffic Content (NSM:FLow)",
   "log_sources_ja": "ネットワークトラフィックフロー (esxi:syslog) | ネットワークトラフィック内容 (NSM:FLow)",
   "tuning": "OutboundDNSVolume | KnownGoodVIBs",
   "detection_logic_en": "Detects unusual outbound DNS traffic from ESXi hosts, often from shell scripts, custom daemons, or malicious VIBs interacting with external DNS infrastructure outside the management plane."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.005",
   "technique_ja": "Publish/Subscribeプロトコル",
   "technique_en": "Publish/Subscribe Protocols",
   "analytic_id": "AN0002",
   "detection_strategy_id": "DET0002",
   "analytic_name": "Analytic 0002",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "UnusualProcessList | TimeWindow | ProtocolPortList",
   "detection_logic_en": "Detects non-standard processes (e.g., PowerShell, python.exe, rundll32.exe) making outbound connections using publish/subscribe protocols (e.g., MQTT, AMQP) over non-browser, encrypted channels, often beaconing to message brokers."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.005",
   "technique_ja": "Publish/Subscribeプロトコル",
   "technique_en": "Publish/Subscribe Protocols",
   "analytic_id": "AN0003",
   "detection_strategy_id": "DET0002",
   "analytic_name": "Analytic 0003",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "BrokerAllowList | TopicAnomalyScore",
   "detection_logic_en": "Detects CLI tools (e.g., mosquitto_pub, nc, python scripts) interacting with pub/sub brokers using unusual topic names, high-frequency publication rates, or obfuscated payloads to non-standard hosts."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.005",
   "technique_ja": "Publish/Subscribeプロトコル",
   "technique_en": "Publish/Subscribe Protocols",
   "analytic_id": "AN0004",
   "detection_strategy_id": "DET0002",
   "analytic_name": "Analytic 0004",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Flow (macos:osquery)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィックフロー (macos:osquery)",
   "tuning": "AppContextFilter | URIPathRegex",
   "detection_logic_en": "Detects osascript, curl, or custom binaries interacting with XMPP/MQTT brokers in unapproved destinations with encrypted payloads or frequent POST-like requests to broker URIs."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1071.005",
   "technique_ja": "Publish/Subscribeプロトコル",
   "technique_en": "Publish/Subscribe Protocols",
   "analytic_id": "AN0005",
   "detection_strategy_id": "DET0002",
   "analytic_name": "Analytic 0005",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "BrokerReputationList | PayloadLengthThreshold",
   "detection_logic_en": "Detects pub/sub traffic over unusual ports, high-frequency topic publications, and connections to known-bad or dynamic broker endpoints outside allowlisted infrastructure."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090",
   "technique_ja": "プロキシ",
   "technique_en": "Proxy",
   "analytic_id": "AN1229",
   "detection_strategy_id": "DET0445",
   "analytic_name": "Analytic 1229",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Network Traffic Flow (NSM:Connections)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ネットワークトラフィックフロー (NSM:Connections)",
   "tuning": "ParentProcessName | DestinationPort | TimeWindow",
   "detection_logic_en": "Suspicious process spawning (e.g., `rundll32`, `svchost`, `powershell`, or `netsh`) followed by network connection creation to internal hosts or uncommon external endpoints on high or non-standard ports."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090",
   "technique_ja": "プロキシ",
   "technique_en": "Proxy",
   "analytic_id": "AN1230",
   "detection_strategy_id": "DET0445",
   "analytic_name": "Analytic 1230",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "CommandLinePattern | OutboundPortRange | ProcessUserContext",
   "detection_logic_en": "User-space tools (e.g., `socat`, `ncat`, `iptables`, `ssh`) used in non-standard ways to establish reverse shells, port-forwarding, or inter-host connections. Often chained with uncommon outbound destinations or SSH tunnels."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090",
   "technique_ja": "プロキシ",
   "technique_en": "Proxy",
   "analytic_id": "AN1231",
   "detection_strategy_id": "DET0445",
   "analytic_name": "Analytic 1231",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Flow (NSM:Firewall) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィックフロー (NSM:Firewall) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "TargetDomain | AppleScriptUsage | LaunchAgentSource",
   "detection_logic_en": "AppleScript, LaunchAgents, or remote login services (`ssh`, `networksetup`) establishing proxy tunnels or dynamic port forwards to external IPs or alternate local hosts."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090",
   "technique_ja": "プロキシ",
   "technique_en": "Proxy",
   "analytic_id": "AN1232",
   "detection_strategy_id": "DET0445",
   "analytic_name": "Analytic 1232",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:shell) | Network Traffic Flow (esxi:vmkernel) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (esxi:shell) | ネットワークトラフィックフロー (esxi:vmkernel) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "CLICommand | DestinationIP | UserContext",
   "detection_logic_en": "Direct use of `nc`, `socat`, or reverse tunnel scripts initiated by abnormal user contexts or unauthorized VIBs initiating connections from hypervisor to external systems."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090",
   "technique_ja": "プロキシ",
   "technique_en": "Proxy",
   "analytic_id": "AN1233",
   "detection_strategy_id": "DET0445",
   "analytic_name": "Analytic 1233",
   "platforms": "Network Devices",
   "log_sources": "Firewall Rule Modification (NSM:Firewall) | Network Traffic Flow (NSM:Flow) | Command Execution (networkdevice:cli)",
   "log_sources_ja": "ファイアウォールルール変更 (NSM:Firewall) | ネットワークトラフィックフロー (NSM:Flow) | コマンド実行 (networkdevice:cli)",
   "tuning": "RuleType | ChangeUser | FlowVolumeDelta",
   "detection_logic_en": "Dynamic or static port forwarding rules added to route traffic through an internal host, or configuration changes to proxy firewall rules not aligned with baselined policy."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.001",
   "technique_ja": "内部プロキシ",
   "technique_en": "Internal Proxy",
   "analytic_id": "AN0204",
   "detection_strategy_id": "DET0075",
   "analytic_name": "Analytic 0204",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Network Traffic Flow (Windows Firewall Log)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ネットワークトラフィックフロー (Windows Firewall Log)",
   "tuning": "InternalConnectionPattern | DestinationPort | TimeWindow",
   "detection_logic_en": "Anomalous process (e.g., `rundll32`, `svchost`, `cmd`) initiates connections to internal peer hosts not seen in typical communication baselines, used to proxy or forward traffic internally, often using SMB, RPC, or high ports."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.001",
   "technique_ja": "内部プロキシ",
   "technique_en": "Internal Proxy",
   "analytic_id": "AN0205",
   "detection_strategy_id": "DET0075",
   "analytic_name": "Analytic 0205",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Connections) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Connections) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "UserContext | PortRange | ProcessPattern",
   "detection_logic_en": "`socat`, `ssh`, `iptables`, or `ncat` invoked from user space or cron jobs to create port forwarding, reverse shells, or inter-host tunnels between compromised Linux systems. Behavior is typically paired with socket activity and high entropy traffic."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.001",
   "technique_ja": "内部プロキシ",
   "technique_en": "Internal Proxy",
   "analytic_id": "AN0206",
   "detection_strategy_id": "DET0075",
   "analytic_name": "Analytic 0206",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Flow (NSM:Flow) | Service Creation (macos:osquery)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィックフロー (NSM:Flow) | サービス作成 (macos:osquery)",
   "tuning": "LaunchAgentPath | PortBindings | AppleScriptUsage",
   "detection_logic_en": "Execution of AppleScript or Automator services launching `ssh -L`, `socat`, or `launchctl` items that dynamically reroute traffic from one Mac endpoint to another. LaunchAgents used to establish permanent internal tunnels."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.001",
   "technique_ja": "内部プロキシ",
   "technique_en": "Internal Proxy",
   "analytic_id": "AN0207",
   "detection_strategy_id": "DET0075",
   "analytic_name": "Analytic 0207",
   "platforms": "ESXi",
   "log_sources": "Process Creation (esxi:shell) | Network Traffic Flow (esxi:vmkernel) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (esxi:shell) | ネットワークトラフィックフロー (esxi:vmkernel) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "CLICommandPattern | VMInitiator | ConnectionDirectionality",
   "detection_logic_en": "ESXi shell execution of tools/scripts (`nc`, `socat`, `perl`) relaying network traffic to other internal hosts, especially when initiated by unauthorized users or VMs."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.001",
   "technique_ja": "内部プロキシ",
   "technique_en": "Internal Proxy",
   "analytic_id": "AN0208",
   "detection_strategy_id": "DET0075",
   "analytic_name": "Analytic 0208",
   "platforms": "Network Devices",
   "log_sources": "Firewall Rule Modification (Firewall Audit Logs) | Network Traffic Flow (NSM:Flow) | Command Execution (networkdevice:cli)",
   "log_sources_ja": "ファイアウォールルール変更 (Firewall Audit Logs) | ネットワークトラフィックフロー (NSM:Flow) | コマンド実行 (networkdevice:cli)",
   "tuning": "ProxyTarget | ConfigChangeUser | FlowThreshold",
   "detection_logic_en": "Configuration of internal NAT or proxy rules that redirect traffic between client segments internally (e.g., site-to-site port forwarding). Often used to relay internal beaconing or move traffic laterally through trust zones."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.002",
   "technique_ja": "外部プロキシ",
   "technique_en": "External Proxy",
   "analytic_id": "AN0922",
   "detection_strategy_id": "DET0325",
   "analytic_name": "Analytic 0922",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Network Traffic Content (WinEventLog:Microsoft-Windows-Windows Defender/Operational)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (WinEventLog:Microsoft-Windows-Windows Defender/Operational)",
   "tuning": "DestinationASN | ParentProcess | EntropyThreshold",
   "detection_logic_en": "Unusual process (e.g., `rundll32`, `mshta`, `wscript`, or custom payloads) initiates network connection to external IPs/domains that proxy C2 traffic, often over uncommon ports or high entropy HTTP/S connections."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.002",
   "technique_ja": "外部プロキシ",
   "technique_en": "External Proxy",
   "analytic_id": "AN0923",
   "detection_strategy_id": "DET0325",
   "analytic_name": "Analytic 0923",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "CommandLinePattern | ExternalIPList | UserContext",
   "detection_logic_en": "`curl`, `wget`, `ncat`, `socat`, or custom binaries initiate outbound traffic to Internet-based proxies (e.g., via VPS or CDN). Behavior may include reverse shell constructs or persistent outbound beacons."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.002",
   "technique_ja": "外部プロキシ",
   "technique_en": "External Proxy",
   "analytic_id": "AN0924",
   "detection_strategy_id": "DET0325",
   "analytic_name": "Analytic 0924",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Flow (NSM:Flow) | Network Connection Creation (macos:osquery)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィックフロー (NSM:Flow) | ネットワーク接続確立 (macos:osquery)",
   "tuning": "LaunchAgentPath | ExternalPort | ProcessReputation",
   "detection_logic_en": "AppleScript or terminal sessions launch tools (`curl`, `nc`, `ssh`) to external IPs not commonly accessed. Outbound connections are made by LaunchAgents/LaunchDaemons, often masquerading as system services."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.002",
   "technique_ja": "外部プロキシ",
   "technique_en": "External Proxy",
   "analytic_id": "AN0925",
   "detection_strategy_id": "DET0325",
   "analytic_name": "Analytic 0925",
   "platforms": "ESXi",
   "log_sources": "Process Creation (esxi:shell) | Network Traffic Flow (esxi:vmkernel) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (esxi:shell) | ネットワークトラフィックフロー (esxi:vmkernel) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "VMOutboundPatterns | ProxyHostPattern | ConnectionDirectionality",
   "detection_logic_en": "ESXi shell or guest VM tools initiate external connections via scripted traffic forwarding to Internet-based proxies. Detected by firewall or shell audit logs showing outbound connection spikes from hypervisor or guest VM to remote proxy nodes."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.002",
   "technique_ja": "外部プロキシ",
   "technique_en": "External Proxy",
   "analytic_id": "AN0926",
   "detection_strategy_id": "DET0325",
   "analytic_name": "Analytic 0926",
   "platforms": "Network Devices",
   "log_sources": "Firewall Rule Modification (Firewall Audit Logs) | Network Traffic Flow (NSM:Flow) | Network Connection Creation (networkdevice:syslog)",
   "log_sources_ja": "ファイアウォールルール変更 (Firewall Audit Logs) | ネットワークトラフィックフロー (NSM:Flow) | ネットワーク接続確立 (networkdevice:syslog)",
   "tuning": "FlowThreshold | DestinationIPCategory | ConfigChangeUser",
   "detection_logic_en": "Changes to NAT/firewall policies enabling outbound port forwarding from internal IPs to Internet-based proxy endpoints. Log spikes in outbound flows to CDN, VPS, or anomalous ASNs with few return packets."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.003",
   "technique_ja": "多段プロキシ",
   "technique_en": "Multi-hop Proxy",
   "analytic_id": "AN1020",
   "detection_strategy_id": "DET0359",
   "analytic_name": "Analytic 1020",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Network Traffic Flow (dns:query)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ネットワークトラフィックフロー (dns:query)",
   "tuning": "DomainCategory | ProcessParent | ConnectionDuration",
   "detection_logic_en": "Suspicious processes (e.g., Tor clients, relays, unknown binaries) launch with sustained encrypted outbound traffic to known anonymity infrastructure (e.g., Tor, I2P), and may relay to additional internal systems via reverse proxying, ICMP tunneling, or socket forwarding."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.003",
   "technique_ja": "多段プロキシ",
   "technique_en": "Multi-hop Proxy",
   "analytic_id": "AN1021",
   "detection_strategy_id": "DET0359",
   "analytic_name": "Analytic 1021",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow) | Network Traffic Content (Netfilter/iptables)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow) | ネットワークトラフィック内容 (Netfilter/iptables)",
   "tuning": "ExecutablePath | RelayCount | ProtocolType",
   "detection_logic_en": "Tools such as `tor`, `nglite`, `proxychains`, `chisel`, or custom daemons repeatedly initiate outbound sessions to multiple nodes before final destination. This behavior is abnormal for Linux services outside of VPN, monitoring, or CDN relay contexts."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.003",
   "technique_ja": "多段プロキシ",
   "technique_en": "Multi-hop Proxy",
   "analytic_id": "AN1022",
   "detection_strategy_id": "DET0359",
   "analytic_name": "Analytic 1022",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Connection Creation (macos:osquery) | Network Traffic Flow (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワーク接続確立 (macos:osquery) | ネットワークトラフィックフロー (macos:unifiedlog)",
   "tuning": "LaunchdLabel | UnsignedBinary | SOCKSPortUsage",
   "detection_logic_en": "LaunchAgents or LaunchDaemons initiate persistent Tor or relay processes that make encrypted outbound connections. May be paired with sandbox bypasses or unsigned executables communicating over SOCKS proxies."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.003",
   "technique_ja": "多段プロキシ",
   "technique_en": "Multi-hop Proxy",
   "analytic_id": "AN1023",
   "detection_strategy_id": "DET0359",
   "analytic_name": "Analytic 1023",
   "platforms": "ESXi",
   "log_sources": "Network Connection Creation (esxi:esxupdate) | Network Traffic Flow (esxi:vmkernel) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (esxi:esxupdate) | ネットワークトラフィックフロー (esxi:vmkernel) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "HopCount | ShellAccess | VPSIPRange",
   "detection_logic_en": "Outbound encrypted traffic initiated from hypervisor shell or via VM backdoor mechanisms to relays in VPS infrastructure, especially if traversing multiple nodes before reaching Internet destination. Packet captures or firewall logs show non-VM communication paths."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.003",
   "technique_ja": "多段プロキシ",
   "technique_en": "Multi-hop Proxy",
   "analytic_id": "AN1024",
   "detection_strategy_id": "DET0359",
   "analytic_name": "Analytic 1024",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Flow (NSM:Flow) | Network Traffic Content (NSM:Firewall) | Firmware Modification (networkdevice:syslog)",
   "log_sources_ja": "ネットワークトラフィックフロー (NSM:Flow) | ネットワークトラフィック内容 (NSM:Firewall) | ファームウェア変更 (networkdevice:syslog)",
   "tuning": "VPNConfigWhitelist | ICMPPayloadEntropy | RelayChainSignature",
   "detection_logic_en": "Encrypted traffic or ICMP tunneling from border routers to internal routers or unknown external IPs. Forwarded traffic shows consistent hop-to-hop relaying without matching configured VPN or expected network topology."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.004",
   "technique_ja": "ドメインフロンティング",
   "technique_en": "Domain Fronting",
   "analytic_id": "AN0564",
   "detection_strategy_id": "DET0196",
   "analytic_name": "Analytic 0564",
   "platforms": "Windows",
   "log_sources": "Network Traffic Content (NSM:Connections) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Connections) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "SNIHostMismatch | CDNAllowList | ProcessInitiator",
   "detection_logic_en": "Suspicious outbound HTTPS connections where the TLS Server Name Indication (SNI) does not match the HTTP Host header, indicating potential use of domain fronting to mask C2 traffic via CDNs."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.004",
   "technique_ja": "ドメインフロンティング",
   "technique_en": "Domain Fronting",
   "analytic_id": "AN0565",
   "detection_strategy_id": "DET0196",
   "analytic_name": "Analytic 0565",
   "platforms": "Linux",
   "log_sources": "Network Traffic Content (NSM:Flow) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "SNIFieldAbsent | AllowedTools | ProcessContext",
   "detection_logic_en": "Applications such as `curl`, `wget`, or custom binaries initiate HTTPS connections where the TLS SNI is mismatched or absent while HTTP Host targets CDN-available C2 endpoints."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.004",
   "technique_ja": "ドメインフロンティング",
   "technique_en": "Domain Fronting",
   "analytic_id": "AN0566",
   "detection_strategy_id": "DET0196",
   "analytic_name": "Analytic 0566",
   "platforms": "macOS",
   "log_sources": "Network Traffic Content (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "ネットワークトラフィック内容 (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "UnsignedBinary | HostHeaderMatch | SOCKSPortAnomaly",
   "detection_logic_en": "Unsigned or user-space apps initiate TLS connections with one hostname and HTTP headers requesting a different domain, commonly abused in CDN-resident domain fronting techniques."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1090.004",
   "technique_ja": "ドメインフロンティング",
   "technique_en": "Domain Fronting",
   "analytic_id": "AN0567",
   "detection_strategy_id": "DET0196",
   "analytic_name": "Analytic 0567",
   "platforms": "ESXi",
   "log_sources": "Network Traffic Content (NSM:Firewall) | Process Creation (esxi:shell)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Firewall) | プロセス生成 (esxi:shell)",
   "tuning": "AdminPortAccess | TLSHandshakeOutliers | DomainMismatchThreshold",
   "detection_logic_en": "Traffic originating from ESXi hosts or management interfaces displays SNI-to-Host mismatch behavior, particularly anomalous given typical infrastructure communication patterns."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1092",
   "technique_ja": "リムーバブルメディア経由の通信",
   "technique_en": "Communication Through Removable Media",
   "analytic_id": "AN0247",
   "detection_strategy_id": "DET0090",
   "analytic_name": "Analytic 0247",
   "platforms": "Windows",
   "log_sources": "Drive Creation (WinEventLog:System) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ドライブ作成 (WinEventLog:System) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "RemovableDriveLetter | WriteToReadTimeWindow | FileNamePattern",
   "detection_logic_en": "Behavioral sequence where removable media is mounted, files are written/updated, and subsequently read/executed on a separate host, suggesting removable-media relay communication."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1092",
   "technique_ja": "リムーバブルメディア経由の通信",
   "technique_en": "Communication Through Removable Media",
   "analytic_id": "AN0248",
   "detection_strategy_id": "DET0090",
   "analytic_name": "Analytic 0248",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:SYSCALL) | Drive Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイル作成 (auditd:SYSCALL) | ドライブ作成 (auditd:SYSCALL)",
   "tuning": "MountPathPattern | TimeWindowBetweenHosts",
   "detection_logic_en": "Detection of file write-access to USB-mount directories (e.g., /media/, /run/media/) followed by same-file access or execution on another host."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1092",
   "technique_ja": "リムーバブルメディア経由の通信",
   "technique_en": "Communication Through Removable Media",
   "analytic_id": "AN0249",
   "detection_strategy_id": "DET0090",
   "analytic_name": "Analytic 0249",
   "platforms": "macOS",
   "log_sources": "Drive Creation (macos:unifiedlog) | File Creation (fs:fsusage)",
   "log_sources_ja": "ドライブ作成 (macos:unifiedlog) | ファイル作成 (fs:fsusage)",
   "tuning": "VolumeNameFilter | ProcessContext",
   "detection_logic_en": "Correlates removable volume mounts (disk arbitration) with file I/O events on that volume, followed by same file execution shortly after insert."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1095",
   "technique_ja": "非アプリケーション層プロトコル",
   "technique_en": "Non-Application Layer Protocol",
   "analytic_id": "AN1254",
   "detection_strategy_id": "DET0457",
   "analytic_name": "Analytic 1254",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ProcessContextAllowList | ByteTransferAnomalyThreshold | ProtocolUsageBaseline",
   "detection_logic_en": "Anomalous use of ICMP or UDP by non-network service processes for data exfiltration or remote control, especially if traffic bypasses proxy infrastructure or shows unusual flow patterns."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1095",
   "technique_ja": "非アプリケーション層プロトコル",
   "technique_en": "Non-Application Layer Protocol",
   "analytic_id": "AN1255",
   "detection_strategy_id": "DET0457",
   "analytic_name": "Analytic 1255",
   "platforms": "Linux",
   "log_sources": "Network Connection Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "RawSocketExecutionPath | TimeWindow",
   "detection_logic_en": "ICMP or raw socket traffic generated by user-mode processes like bash, Python, or nc, typically using `ping`, `hping3`, or crafted packets via libpcap or scapy."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1095",
   "technique_ja": "非アプリケーション層プロトコル",
   "technique_en": "Non-Application Layer Protocol",
   "analytic_id": "AN1256",
   "detection_strategy_id": "DET0457",
   "analytic_name": "Analytic 1256",
   "platforms": "macOS",
   "log_sources": "Network Traffic Flow (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィックフロー (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "UnsignedBinaryNetworkUsage",
   "detection_logic_en": "Unsigned binaries or interpreted scripts initiating non-standard protocols (ICMP, UDP, SOCKS) outside of baseline network behavior."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1095",
   "technique_ja": "非アプリケーション層プロトコル",
   "technique_en": "Non-Application Layer Protocol",
   "analytic_id": "AN1257",
   "detection_strategy_id": "DET0457",
   "analytic_name": "Analytic 1257",
   "platforms": "ESXi",
   "log_sources": "Network Traffic Content (esxi:vmkernel)",
   "log_sources_ja": "ネットワークトラフィック内容 (esxi:vmkernel)",
   "tuning": "VMCIBackdoorProcess | GuestToHostCommPattern",
   "detection_logic_en": "VMCI (Virtual Machine Communication Interface) traffic between guest and host, or between VMs, originating from non-management tools or unauthorized binaries."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1095",
   "technique_ja": "非アプリケーション層プロトコル",
   "technique_en": "Non-Application Layer Protocol",
   "analytic_id": "AN1258",
   "detection_strategy_id": "DET0457",
   "analytic_name": "Analytic 1258",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Content (NSM:Firewall) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Firewall) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "ProtocolEntropyThreshold | SessionDurationThreshold",
   "detection_logic_en": "Non-standard port/protocol pairings or low-entropy ICMP traffic resembling tunneling patterns (e.g., fixed-size pings with delays)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1102",
   "technique_ja": "Webサービス",
   "technique_en": "Web Service",
   "analytic_id": "AN1189",
   "detection_strategy_id": "DET0425",
   "analytic_name": "Analytic 1189",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ProcessName | DataTransferThreshold | TimeWindow",
   "detection_logic_en": "Detects unusual outbound connections to web services from uncommon processes using SSL/TLS, particularly those exhibiting high outbound data volume or persistence."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1102",
   "technique_ja": "Webサービス",
   "technique_en": "Web Service",
   "analytic_id": "AN1190",
   "detection_strategy_id": "DET0425",
   "analytic_name": "Analytic 1190",
   "platforms": "Linux",
   "log_sources": "Network Connection Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ParentProcess | HostnamePattern | RequestFrequency",
   "detection_logic_en": "Detects command-line tools, agents, or scripts making outbound HTTPS connections to popular web services like Discord, Slack, Dropbox, or Graph API in an unusual context."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1102",
   "technique_ja": "Webサービス",
   "technique_en": "Web Service",
   "analytic_id": "AN1191",
   "detection_strategy_id": "DET0425",
   "analytic_name": "Analytic 1191",
   "platforms": "macOS",
   "log_sources": "Network Traffic Content (macos:unifiedlog) | Network Connection Creation (macos:osquery)",
   "log_sources_ja": "ネットワークトラフィック内容 (macos:unifiedlog) | ネットワーク接続確立 (macos:osquery)",
   "tuning": "ProcessSignature | ConnectionInterval",
   "detection_logic_en": "Detects user agents or background services making unauthorized or unscheduled web API calls to cloud/web services over HTTPS."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1102",
   "technique_ja": "Webサービス",
   "technique_en": "Web Service",
   "analytic_id": "AN1192",
   "detection_strategy_id": "DET0425",
   "analytic_name": "Analytic 1192",
   "platforms": "ESXi",
   "log_sources": "Network Connection Creation (esxi:vmkernel) | Network Traffic Flow (vpxd.log)",
   "log_sources_ja": "ネットワーク接続確立 (esxi:vmkernel) | ネットワークトラフィックフロー (vpxd.log)",
   "tuning": "RemoteIPRange | VMContext",
   "detection_logic_en": "Detects guest VMs or management agents issuing HTTP(S) traffic to external services without a valid patch management or backup justification."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1102.001",
   "technique_ja": "デッドドロップリゾルバ",
   "technique_en": "Dead Drop Resolver",
   "analytic_id": "AN0158",
   "detection_strategy_id": "DET0058",
   "analytic_name": "Analytic 0158",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Content (etw:Microsoft-Windows-NDIS-PacketCapture)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (etw:Microsoft-Windows-NDIS-PacketCapture)",
   "tuning": "TargetDomain | TimeWindow | UserContext",
   "detection_logic_en": "Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1102.001",
   "technique_ja": "デッドドロップリゾルバ",
   "technique_en": "Dead Drop Resolver",
   "analytic_id": "AN0159",
   "detection_strategy_id": "DET0058",
   "analytic_name": "Analytic 0159",
   "platforms": "Linux",
   "log_sources": "Network Connection Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TargetDomain | PayloadEntropyThreshold | TimeWindow",
   "detection_logic_en": "Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1102.001",
   "technique_ja": "デッドドロップリゾルバ",
   "technique_en": "Dead Drop Resolver",
   "analytic_id": "AN0160",
   "detection_strategy_id": "DET0058",
   "analytic_name": "Analytic 0160",
   "platforms": "macOS",
   "log_sources": "Network Traffic Content (macos:unifiedlog) | Network Connection Creation (macos:osquery)",
   "log_sources_ja": "ネットワークトラフィック内容 (macos:unifiedlog) | ネットワーク接続確立 (macos:osquery)",
   "tuning": "TargetService | UserContext | TimeWindow",
   "detection_logic_en": "Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1102.001",
   "technique_ja": "デッドドロップリゾルバ",
   "technique_en": "Dead Drop Resolver",
   "analytic_id": "AN0161",
   "detection_strategy_id": "DET0058",
   "analytic_name": "Analytic 0161",
   "platforms": "ESXi",
   "log_sources": "Network Traffic Flow (esxi:vobd) | Network Connection Creation (NSM:Firewall)",
   "log_sources_ja": "ネットワークトラフィックフロー (esxi:vobd) | ネットワーク接続確立 (NSM:Firewall)",
   "tuning": "DestinationIP | Protocol | TimeWindow",
   "detection_logic_en": "Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1102.002",
   "technique_ja": "双方向通信",
   "technique_en": "Bidirectional Communication",
   "analytic_id": "AN0100",
   "detection_strategy_id": "DET0035",
   "analytic_name": "Analytic 0100",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Network Traffic Content (etw:Microsoft-Windows-WinINet)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (etw:Microsoft-Windows-WinINet)",
   "tuning": "TimeWindow | DomainPattern | PayloadSizeThreshold | ProcessNameExclusionList",
   "detection_logic_en": "Suspicious processes initiating encrypted HTTPS connections to common web service domains, followed by abnormal data upload behavior or automated posting behavior indicative of C2 bidirectional traffic."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1102.002",
   "technique_ja": "双方向通信",
   "technique_en": "Bidirectional Communication",
   "analytic_id": "AN0101",
   "detection_strategy_id": "DET0035",
   "analytic_name": "Analytic 0101",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "UploadDirectionality | HostnameRegexList | ScriptParentName",
   "detection_logic_en": "Non-interactive system processes making encrypted HTTPS connections to well-known web services followed by high outbound traffic volume or scripted upload patterns."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1102.002",
   "technique_ja": "双方向通信",
   "technique_en": "Bidirectional Communication",
   "analytic_id": "AN0102",
   "detection_strategy_id": "DET0035",
   "analytic_name": "Analytic 0102",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Connection Creation (NSM:Connections)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワーク接続確立 (NSM:Connections)",
   "tuning": "ScriptEngineList | SocialMediaDomainPatterns | BurstConnectionRate",
   "detection_logic_en": "Scripting engines (e.g., osascript, Python) initiating HTTPS requests to social media or content-sharing platforms, paired with automated response handling indicative of two-way communication."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1102.003",
   "technique_ja": "一方向通信",
   "technique_en": "One-Way Communication",
   "analytic_id": "AN1599",
   "detection_strategy_id": "DET0581",
   "analytic_name": "Analytic 1599",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Content (etw:Microsoft-Windows-WinINet)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (etw:Microsoft-Windows-WinINet)",
   "tuning": "DestinationDomain | TimeWindow | ProcessName",
   "detection_logic_en": "Suspicious process initiating outbound connections to web services without corresponding response or return traffic, indicative of one-way command channels."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1102.003",
   "technique_ja": "一方向通信",
   "technique_en": "One-Way Communication",
   "analytic_id": "AN1600",
   "detection_strategy_id": "DET0581",
   "analytic_name": "Analytic 1600",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Flow (iptables:LOG)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィックフロー (iptables:LOG)",
   "tuning": "ParentProcess | CommandLineArgs",
   "detection_logic_en": "Curl, wget, or custom HTTP clients initiated by uncommon user accounts or cron jobs to popular web services, with no observed response parsing logic."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1102.003",
   "technique_ja": "一方向通信",
   "technique_en": "One-Way Communication",
   "analytic_id": "AN1601",
   "detection_strategy_id": "DET0581",
   "analytic_name": "Analytic 1601",
   "platforms": "macOS",
   "log_sources": "Network Traffic Content (macos:unifiedlog) | Process Creation (macos:endpointsecurity)",
   "log_sources_ja": "ネットワークトラフィック内容 (macos:unifiedlog) | プロセス生成 (macos:endpointsecurity)",
   "tuning": "UserContext | EntropyScore",
   "detection_logic_en": "Process using URLSession or similar API to fetch from web services without any response handling, indicative of one-way C2 channels."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1102.003",
   "technique_ja": "一方向通信",
   "technique_en": "One-Way Communication",
   "analytic_id": "AN1602",
   "detection_strategy_id": "DET0581",
   "analytic_name": "Analytic 1602",
   "platforms": "ESXi",
   "log_sources": "Network Traffic Flow (esxi:hostd)",
   "log_sources_ja": "ネットワークトラフィックフロー (esxi:hostd)",
   "tuning": "ScheduledTaskName | DestinationIP",
   "detection_logic_en": "ESXi shell or scheduled tasks initiating outbound HTTPS to known public services without inbound return or loggable response, used to fetch instructions."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1104",
   "technique_ja": "多段チャネル",
   "technique_en": "Multi-Stage Channels",
   "analytic_id": "AN0637",
   "detection_strategy_id": "DET0228",
   "analytic_name": "Analytic 0637",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | ParentProcess | DestinationHostname",
   "detection_logic_en": "Initial process initiates outbound connection to first-stage C2, receives payloads or commands, then spawns or injects into a second process that establishes a new outbound connection to an unrelated destination (second-stage C2)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1104",
   "technique_ja": "多段チャネル",
   "technique_en": "Multi-Stage Channels",
   "analytic_id": "AN0638",
   "detection_strategy_id": "DET0228",
   "analytic_name": "Analytic 0638",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Flow (iptables:LOG)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィックフロー (iptables:LOG)",
   "tuning": "BinaryPath | IPDistance",
   "detection_logic_en": "Shell script or binary initiates curl/wget request to staging domain, writes output to disk or memory, and shortly afterward launches another process that establishes new outbound connection to a different IP or hostname."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1104",
   "technique_ja": "多段チャネル",
   "technique_en": "Multi-Stage Channels",
   "analytic_id": "AN0639",
   "detection_strategy_id": "DET0228",
   "analytic_name": "Analytic 0639",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:endpointsecurity) | Network Traffic Flow (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:endpointsecurity) | ネットワークトラフィックフロー (macos:unifiedlog)",
   "tuning": "UserContext | EntropyScore",
   "detection_logic_en": "Initial process using NSURLSession or similar APIs reaches out to known staging domains, followed by creation of a reverse shell or RAT connecting to a second unrelated server."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1104",
   "technique_ja": "多段チャネル",
   "technique_en": "Multi-Stage Channels",
   "analytic_id": "AN0640",
   "detection_strategy_id": "DET0228",
   "analytic_name": "Analytic 0640",
   "platforms": "ESXi",
   "log_sources": "Network Traffic Flow (esxi:hostd) | Process Creation (esxi:cron)",
   "log_sources_ja": "ネットワークトラフィックフロー (esxi:hostd) | プロセス生成 (esxi:cron)",
   "tuning": "ScheduledTaskName | DestinationIP",
   "detection_logic_en": "CLI-based or API-based network call from the hypervisor to external staging host, shortly followed by a connection to a second external IP by a spawned process or scheduled task."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1105",
   "technique_ja": "ツールの送り込み",
   "technique_en": "Ingress Tool Transfer",
   "analytic_id": "AN0165",
   "detection_strategy_id": "DET0060",
   "analytic_name": "Analytic 0165",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "ParentProcessName | DestinationIPCategory | FilePathRegex",
   "detection_logic_en": "Unusual or uncommon processes initiate network connections to external destinations followed by file creation (tools downloaded)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1105",
   "technique_ja": "ツールの送り込み",
   "technique_en": "Ingress Tool Transfer",
   "analytic_id": "AN0166",
   "detection_strategy_id": "DET0060",
   "analytic_name": "Analytic 0166",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | File Creation (auditd:SYSCALL) | Network Traffic Flow (iptables:LOG)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ファイル作成 (auditd:SYSCALL) | ネットワークトラフィックフロー (iptables:LOG)",
   "tuning": "ToolName | DownloadExtension",
   "detection_logic_en": "Shell-based tools (curl, wget, scp) initiate connections to external domains followed by creation of executable files on disk."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1105",
   "technique_ja": "ツールの送り込み",
   "technique_en": "Ingress Tool Transfer",
   "analytic_id": "AN0167",
   "detection_strategy_id": "DET0060",
   "analytic_name": "Analytic 0167",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:endpointsecurity) | File Creation (macos:unifiedlog) | Network Connection Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:endpointsecurity) | ファイル作成 (macos:unifiedlog) | ネットワーク接続確立 (macos:unifiedlog)",
   "tuning": "DirectoryTargeted | ProcessPath",
   "detection_logic_en": "Process execution of curl or wget followed by a network connection and a file created in temporary or user-specific directories."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1105",
   "technique_ja": "ツールの送り込み",
   "technique_en": "Ingress Tool Transfer",
   "analytic_id": "AN0168",
   "detection_strategy_id": "DET0060",
   "analytic_name": "Analytic 0168",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:hostd) | File Creation (esxi:vmkernel)",
   "log_sources_ja": "コマンド実行 (esxi:hostd) | ファイル作成 (esxi:vmkernel)",
   "tuning": "ToolName | DatastorePath",
   "detection_logic_en": "Command line interface or vCLI triggers remote transfer using wget or curl, writing files into datastore paths or local tmp directories."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1105",
   "technique_ja": "ツールの送り込み",
   "technique_en": "Ingress Tool Transfer",
   "analytic_id": "AN0169",
   "detection_strategy_id": "DET0060",
   "analytic_name": "Analytic 0169",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Flow (NSM:Flow) | File Creation (snmp:syslog)",
   "log_sources_ja": "ネットワークトラフィックフロー (NSM:Flow) | ファイル作成 (snmp:syslog)",
   "tuning": "PayloadVolumeThreshold | ProtocolUsed",
   "detection_logic_en": "Network device logs show anomalous inbound file transfers or uncharacteristic flows with high payload volume to network devices with storage or automation hooks."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1132",
   "technique_ja": "データエンコーディング",
   "technique_en": "Data Encoding",
   "analytic_id": "AN0302",
   "detection_strategy_id": "DET0108",
   "analytic_name": "Analytic 0302",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "PayloadEntropyThreshold | ProcessAllowlist | AnomalyScoreThreshold",
   "detection_logic_en": "Atypical processes (e.g., powershell.exe, regsvr32.exe) encode large outbound traffic using Base64 or other character encodings; this traffic is sent over uncommon ports or embedded in protocol fields (e.g., HTTP cookies or headers)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1132",
   "technique_ja": "データエンコーディング",
   "technique_en": "Data Encoding",
   "analytic_id": "AN0303",
   "detection_strategy_id": "DET0108",
   "analytic_name": "Analytic 0303",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow) | Command Execution (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow) | コマンド実行 (linux:syslog)",
   "tuning": "TimeWindow | UserContext",
   "detection_logic_en": "Custom scripts or processes encode outbound traffic using gzip, Base64, or hex prior to exfiltration via curl, wget, or custom sockets. Encoding typically occurs before or during outbound connections from non-network daemons."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1132",
   "technique_ja": "データエンコーディング",
   "technique_en": "Data Encoding",
   "analytic_id": "AN0304",
   "detection_strategy_id": "DET0108",
   "analytic_name": "Analytic 0304",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Network Traffic Content (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ネットワークトラフィック内容 (macos:unifiedlog)",
   "tuning": "EncodedCommandLengthThreshold | SuspiciousProcessChainDepth",
   "detection_logic_en": "Processes use built-in encoding utilities (e.g., `base64`, `xxd`, or `plutil`) to encode file contents followed by HTTP/HTTPS transfer via curl or custom applications."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1132",
   "technique_ja": "データエンコーディング",
   "technique_en": "Data Encoding",
   "analytic_id": "AN0305",
   "detection_strategy_id": "DET0108",
   "analytic_name": "Analytic 0305",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:shell) | Network Traffic Content (esxi:vmkernel) | User Account Authentication (ESXiLogs:authlog)",
   "log_sources_ja": "コマンド実行 (esxi:shell) | ネットワークトラフィック内容 (esxi:vmkernel) | ユーザーアカウント認証 (ESXiLogs:authlog)",
   "tuning": "AuthSourceTrustLevel | ExfilBurstThreshold",
   "detection_logic_en": "ESXi daemons (e.g., hostd, vpxa) are wrapped or impersonated to send large outbound traffic using gzip/Base64 encoding over SSH or HTTP. These actions follow suspicious logins or shell access."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1132.001",
   "technique_ja": "標準エンコーディング",
   "technique_en": "Standard Encoding",
   "analytic_id": "AN0345",
   "detection_strategy_id": "DET0124",
   "analytic_name": "Analytic 0345",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | Script Execution (WinEventLog:PowerShell) | Network Traffic Flow (M365Defender:DeviceNetworkEvents)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | スクリプト実行 (WinEventLog:PowerShell) | ネットワークトラフィックフロー (M365Defender:DeviceNetworkEvents)",
   "tuning": "PayloadEntropyThreshold | B64LengthThreshold | TimeWindow | KnownAdminTools | BytesOutToInRatio",
   "detection_logic_en": "Process invokes a standard encoder (e.g., PowerShell -enc, certutil -encode, base64 via .NET/Invoke-Expression) or emits long Base64/hex literals → shortly followed by outbound network egress with high bytes_out:bytes_in ratio or HTTP headers/payloads containing Base64/MIME blocks."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1132.001",
   "technique_ja": "標準エンコーディング",
   "technique_en": "Standard Encoding",
   "analytic_id": "AN0346",
   "detection_strategy_id": "DET0124",
   "analytic_name": "Analytic 0346",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "EncodingToolsAllowList | EntropyThreshold | TimeWindow | OutInRatio",
   "detection_logic_en": "Shell/utility (base64, xxd -p, od, openssl enc -base64, python/perl base64 libraries) encodes data → subsequent outbound connections (curl/wget/bash TCP, socat, python requests) with high asymmetry or Base64/MIME blobs in HTTP/DNS payloads."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1132.001",
   "technique_ja": "標準エンコーディング",
   "technique_en": "Standard Encoding",
   "analytic_id": "AN0347",
   "detection_strategy_id": "DET0124",
   "analytic_name": "Analytic 0347",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Flow (PF:Logs) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィックフロー (PF:Logs) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "AllowedDeveloperIDs | EntropyThreshold | TimeWindow",
   "detection_logic_en": "Processes use base64/xxd/openssl/python Objective‑C APIs to encode data (seen in EndpointSecurity exec events or Unified Logs) → quick outbound connections with large bytes_out or HTTP POSTs carrying Base64/MIME bodies."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1132.001",
   "technique_ja": "標準エンコーディング",
   "technique_en": "Standard Encoding",
   "analytic_id": "AN0348",
   "detection_strategy_id": "DET0124",
   "analytic_name": "Analytic 0348",
   "platforms": "ESXi",
   "log_sources": "Process Creation (esxi:shell) | Application Log Content (esxi:hostd) | Network Traffic Flow (NSX:FlowLogs) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (esxi:shell) | アプリケーションログ内容 (esxi:hostd) | ネットワークトラフィックフロー (NSX:FlowLogs) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "MgmtCIDRs | BytesRatio | TimeWindow",
   "detection_logic_en": "ESXi shell (BusyBox) or VMware utilities (openssl, python if present) used to Base64/hex encode data from datastore or config files → followed by abnormal egress from the host (NSX/flow logs) with asymmetric bytes_out or HTTPS posts to non-management endpoints."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1132.002",
   "technique_ja": "非標準エンコーディング",
   "technique_en": "Non-Standard Encoding",
   "analytic_id": "AN0927",
   "detection_strategy_id": "DET0326",
   "analytic_name": "Analytic 0927",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | Script Execution (WinEventLog:PowerShell) | Network Traffic Flow (m365:defender)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | スクリプト実行 (WinEventLog:PowerShell) | ネットワークトラフィックフロー (m365:defender)",
   "tuning": "EntropyThreshold | TokenLengthThreshold | BytesOutToInRatio | FixedPacketStdDevThreshold | TimeWindow | KnownLegitEncoders",
   "detection_logic_en": "A process/script constructs or references a custom/alphabet translation table (e.g., 64/85/32+ arbitrary chars, XOR/base-N loops) or emits long high-entropy strings that do NOT validate as standard Base64/Hex → shortly after, the same process (or its child) generates outbound traffic with asymmetric bytes_out:bytes_in, fixed-size beacons, or protocol/header mismatches (e.g., Content-Type says JSON but body fails JSON parse / contains non-standard alphabet)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1132.002",
   "technique_ja": "非標準エンコーディング",
   "technique_en": "Non-Standard Encoding",
   "analytic_id": "AN0928",
   "detection_strategy_id": "DET0326",
   "analytic_name": "Analytic 0928",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "EntropyThreshold | TokenLengthThreshold | BytesOutToInRatio | TimeWindow | KnownEncoders",
   "detection_logic_en": "Shell scripts or binaries implement custom mapping tables (tr/sed/awk/golang/rust/python encode loops), or emit long high-entropy tokens that fail Base64/Hex validation → correlated with egress showing asymmetric flow, protocol-mismatch payloads, or DNS/HTTP bodies containing low-diversity-but-long custom alphabets."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1132.002",
   "technique_ja": "非標準エンコーディング",
   "technique_en": "Non-Standard Encoding",
   "analytic_id": "AN0929",
   "detection_strategy_id": "DET0326",
   "analytic_name": "Analytic 0929",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:endpointsecurity) | Network Traffic Flow (PF:Logs) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (macos:endpointsecurity) | ネットワークトラフィックフロー (PF:Logs) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "EntropyThreshold | TokenLengthThreshold | BytesOutToInRatio | TimeWindow | AllowedSignedBinaries",
   "detection_logic_en": "EndpointSecurity/Unified Logs show processes generating custom alphabets or long high-entropy, non-standard tokens → network logs (PF/Zeek/EDR) show asymmetric beacons, protocol mismatches, or periodic fixed-size posts."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1132.002",
   "technique_ja": "非標準エンコーディング",
   "technique_en": "Non-Standard Encoding",
   "analytic_id": "AN0930",
   "detection_strategy_id": "DET0326",
   "analytic_name": "Analytic 0930",
   "platforms": "ESXi",
   "log_sources": "Process Creation (esxi:shell) | Application Log Content (esxi:hostd) | Network Traffic Flow (NSM:Flow) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (esxi:shell) | アプリケーションログ内容 (esxi:hostd) | ネットワークトラフィックフロー (NSM:Flow) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "MgmtCIDRs | BytesOutToInRatio | TokenLengthThreshold | TimeWindow",
   "detection_logic_en": "ESXi shell or scripts produce long, high-entropy tokens (non-standard alphabets) in shell.log/hostd, followed by outbound flows (NSX/Zeek) with asymmetric ratios or protocol mismatches to non-management endpoints."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1205",
   "technique_ja": "トラフィックシグナリング",
   "technique_en": "Traffic Signaling",
   "analytic_id": "AN1448",
   "detection_strategy_id": "DET0524",
   "analytic_name": "Analytic 1448",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Flow (WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall) | Command Execution (WinEventLog:PowerShell)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィックフロー (WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall) | コマンド実行 (WinEventLog:PowerShell)",
   "tuning": "TimeWindowKnock | PortSequenceMinLen | SuspiciousProcesses | AllowedFirewallChangers | WoLAllowedWindows",
   "detection_logic_en": "A remote host sends a short sequence of failed connection attempts (RST/ICMP unreachable) to a set of closed ports. Within a brief window the endpoint (a) adds/enables a firewall rule or (b) a sniffer-backed process begins listening or opens a new socket, after which a successful connection occurs. Also detects Wake-on-LAN magic packets seen on local segment."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1205",
   "technique_ja": "トラフィックシグナリング",
   "technique_en": "Traffic Signaling",
   "analytic_id": "AN1449",
   "detection_strategy_id": "DET0524",
   "analytic_name": "Analytic 1449",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ServicePort | KnockResetRatio | ProcessAllowList",
   "detection_logic_en": "Closed-port knock sequence from a remote IP followed by on-host firewall change (iptables/nftables) or daemon starts listening (socket open) and a successful TCP/UDP connect. Optional detection of libpcap/raw-socket sniffers spawning to watch for secret values."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1205",
   "technique_ja": "トラフィックシグナリング",
   "technique_en": "Traffic Signaling",
   "analytic_id": "AN1450",
   "detection_strategy_id": "DET0524",
   "analytic_name": "Analytic 1450",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Flow (macos:unifiedlog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィックフロー (macos:unifiedlog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "PFAnchorPaths | DeveloperMode",
   "detection_logic_en": "Remote knock sequence followed by PF/socketfilterfw rule update or a background process listening on a new port; then a successful TCP session. Also flags WoL magic packets on local segment."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1205",
   "technique_ja": "トラフィックシグナリング",
   "technique_en": "Traffic Signaling",
   "analytic_id": "AN1451",
   "detection_strategy_id": "DET0524",
   "analytic_name": "Analytic 1451",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Flow (networkdevice:syslog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィックフロー (networkdevice:syslog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "MgmtPortSet | DeviceRole",
   "detection_logic_en": "Crafted ‘synful knock’ patterns toward routers/switches (same src hits interface/broadcast/network address on same port in short order) followed by ACL/telnet/SSH enablement or module change. Detect device image/ACL updates then a new mgmt session."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1205.001",
   "technique_ja": "ポートノッキング",
   "technique_en": "Port Knocking",
   "analytic_id": "AN0842",
   "detection_strategy_id": "DET0302",
   "analytic_name": "Analytic 0842",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Flow (WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィックフロー (WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall)",
   "tuning": "TimeWindow | MinSequenceLen | RuleChangeAllowList | WatchedPorts",
   "detection_logic_en": "A remote source rapidly touches a short sequence of closed ports (SYN→RST/S0) on a Windows host. Within a short window the host changes firewall state (WFP rule added/modified or service starts listening) and then the same source completes the first successful handshake to the newly opened port."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1205.001",
   "technique_ja": "ポートノッキング",
   "technique_en": "Port Knocking",
   "analytic_id": "AN0843",
   "detection_strategy_id": "DET0302",
   "analytic_name": "Analytic 0843",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "ServicePort | KnockTolerance | MgmtAllowList",
   "detection_logic_en": "A source performs a short closed-port sequence; the host then modifies iptables/nftables/ufw rules or starts a daemon binding a new socket, followed by a successful connection from the same source."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1205.001",
   "technique_ja": "ポートノッキング",
   "technique_en": "Port Knocking",
   "analytic_id": "AN0844",
   "detection_strategy_id": "DET0302",
   "analytic_name": "Analytic 0844",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Flow (macos:unifiedlog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィックフロー (macos:unifiedlog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "PFAnchorPaths | DevMode",
   "detection_logic_en": "A source performs a closed-port sequence; the endpoint enables a PF/socketfilterfw rule or a background process binds a port; then a successful connection completes from the same source."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1205.001",
   "technique_ja": "ポートノッキング",
   "technique_en": "Port Knocking",
   "analytic_id": "AN0845",
   "detection_strategy_id": "DET0302",
   "analytic_name": "Analytic 0845",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Flow (networkdevice:syslog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィックフロー (networkdevice:syslog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "MgmtPortSet | DeviceRole",
   "detection_logic_en": "Router/switch receives a knock pattern (same src touches device unicast, broadcast, and network-address on same or stepped ports) followed by ACL/line-vty/service enable and the first mgmt session success."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1205.002",
   "technique_ja": "ソケットフィルタ",
   "technique_en": "Socket Filters",
   "analytic_id": "AN0462",
   "detection_strategy_id": "DET0162",
   "analytic_name": "Analytic 0462",
   "platforms": "Windows",
   "log_sources": "Service Creation (WinEventLog:System) | Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Driver Load (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "サービス作成 (WinEventLog:System) | プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ドライバ読み込み (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TimeWindow | CaptureLibIndicators | AllowedInstallers | ReversePorts",
   "detection_logic_en": "Adversary installs/uses packet-capture or raw-socket capability (WinPcap/Npcap, wpcap/packet DLLs or raw socket attach) and sets a filter. A crafted inbound packet is observed; within a short window the host process that loaded capture libraries initiates an outbound connection (e.g., reverse shell) to the packet origin."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1205.002",
   "technique_ja": "ソケットフィルタ",
   "technique_en": "Socket Filters",
   "analytic_id": "AN0463",
   "detection_strategy_id": "DET0162",
   "analytic_name": "Analytic 0463",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (linux:osquery) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (linux:osquery) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "UserContext | MinPayloadEntropy | AFPacketAllowList",
   "detection_logic_en": "Process creates a raw/packet socket and attaches a (e)BPF filter (setsockopt SO_ATTACH_FILTER/ATTACH_BPF or bpf(BPF_PROG_LOAD)). Immediately after a matching inbound packet, the same process binds/connects outward to a remote host (reverse shell or beacon)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1205.002",
   "technique_ja": "ソケットフィルタ",
   "technique_en": "Socket Filters",
   "analytic_id": "AN0464",
   "detection_strategy_id": "DET0162",
   "analytic_name": "Analytic 0464",
   "platforms": "macOS",
   "log_sources": "Process Creation (OpenBSM:AuditTrail) | Network Connection Creation (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (OpenBSM:AuditTrail) | ネットワーク接続確立 (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "BPFDevicePath | DeveloperMode",
   "detection_logic_en": "Process opens /dev/bpf* (libpcap) or loads NetworkExtension filter, then after a crafted inbound packet the same process initiates an outbound connection to the trigger origin."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1219",
   "technique_ja": "リモートアクセスツール",
   "technique_en": "Remote Access Tools",
   "analytic_id": "AN1366",
   "detection_strategy_id": "DET0496",
   "analytic_name": "Analytic 1366",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Service Creation (WinEventLog:System) | Windows Registry Key Creation (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | サービス作成 (WinEventLog:System) | Windowsレジストリキー作成 (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | UserContext | ProcessAllowlist | InstallPathRegex | ExternalIPAllowlist | ShellSpawnRegex | EgressHeuristics",
   "detection_logic_en": "Chain of remote access tool behavior: (1) initial execution of remote-control/assist agent or GUI under user context; (2) persistence via service or autorun; (3) long-lived outbound connection/tunnel to external infrastructure; (4) interactive control signals such as shell or file-manager child processes spawned by the RAT parent."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1219",
   "technique_ja": "リモートアクセスツール",
   "technique_en": "Remote Access Tools",
   "analytic_id": "AN1367",
   "detection_strategy_id": "DET0496",
   "analytic_name": "Analytic 1367",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Creation (auditd:PATH) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル作成 (auditd:PATH) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | DaemonAllowlist | SuspiciousChildProcesses | EgressHeuristics",
   "detection_logic_en": "Sequence of RAT agent execution, systemd persistence, and long-lived external egress; optional interactive shells spawned from the agent."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1219",
   "technique_ja": "リモートアクセスツール",
   "technique_en": "Remote Access Tools",
   "analytic_id": "AN1368",
   "detection_strategy_id": "DET0496",
   "analytic_name": "Analytic 1368",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (macos:osquery) | Network Connection Creation (macos:osquery)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:osquery) | ネットワーク接続確立 (macos:osquery)",
   "tuning": "AllowedAppBundlePaths | LaunchdAllowlist | TimeWindow | EgressHeuristics",
   "detection_logic_en": "Electron/GUI or headless RAT execution followed by LaunchAgent/Daemon persistence and persistent external connections; interactive children (osascript/sh/curl) spawned by parent."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1219.001",
   "technique_ja": "IDEトンネリング",
   "technique_en": "IDE Tunneling",
   "analytic_id": "AN0375",
   "detection_strategy_id": "DET0133",
   "analytic_name": "Analytic 0375",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "TimeWindow | TunnelDomainPatterns | AuthorizedUserList",
   "detection_logic_en": "Detection of the creation of VSCode or JetBrains CLI tunneling profiles followed by persistent remote access via IDE-integrated tunnels, potentially authenticated via GitHub or JetBrains accounts."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1219.001",
   "technique_ja": "IDEトンネリング",
   "technique_en": "IDE Tunneling",
   "analytic_id": "AN0376",
   "detection_strategy_id": "DET0133",
   "analytic_name": "Analytic 0376",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Creation (auditd:SYSCALL) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル作成 (auditd:SYSCALL) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "PathRegex | TunnelCLIFlags | Username | TunnelArtifactPath | CommandLineFlags",
   "detection_logic_en": "Creation of VSCode tunnel configuration file combined with interactive remote session via code CLI or ssh with JetBrains gateway."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1219.001",
   "technique_ja": "IDEトンネリング",
   "technique_en": "IDE Tunneling",
   "analytic_id": "AN0377",
   "detection_strategy_id": "DET0133",
   "analytic_name": "Analytic 0377",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (macos:unifiedlog) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:unifiedlog) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "ParentProcessName | RemoteTunnelPersistence | RemoteFlag | LaunchAgentPath | TunnelReconnectInterval",
   "detection_logic_en": "Detection of JetBrains or VSCode tunnel profile creation followed by unusual persistent SSH or IDE-based tunnel communications to devtunnel APIs."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1219.002",
   "technique_ja": "リモートデスクトップソフトウェア",
   "technique_en": "Remote Desktop Software",
   "analytic_id": "AN0714",
   "detection_strategy_id": "DET0259",
   "analytic_name": "Analytic 0714",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Firewall Rule Modification (WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ファイアウォールルール変更 (WinEventLog:Microsoft-Windows-Windows Firewall With Advanced Security/Firewall)",
   "tuning": "Image | DestinationPort | ParentImage | TimeWindow",
   "detection_logic_en": "Adversary installation or use of RMM software (e.g., TeamViewer, AnyDesk, ScreenConnect) followed by outbound beaconing or remote session establishment"
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1219.002",
   "technique_ja": "リモートデスクトップソフトウェア",
   "technique_en": "Remote Desktop Software",
   "analytic_id": "AN0715",
   "detection_strategy_id": "DET0259",
   "analytic_name": "Analytic 0715",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "binary_name | OutboundIPRange",
   "detection_logic_en": "Execution of known or custom VNC/remote desktop daemons or tunneling agents that initiate external communication after launch"
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1219.002",
   "technique_ja": "リモートデスクトップソフトウェア",
   "technique_en": "Remote Desktop Software",
   "analytic_id": "AN0716",
   "detection_strategy_id": "DET0259",
   "analytic_name": "Analytic 0716",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Connection Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワーク接続確立 (macos:unifiedlog)",
   "tuning": "process_signature | sandbox_exception",
   "detection_logic_en": "Initiation of remote desktop sessions via AnyDesk, TeamViewer, or Chrome Remote Desktop accompanied by unexpected user logins or system modifications"
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1219.003",
   "technique_ja": "リモートアクセスハードウェア",
   "technique_en": "Remote Access Hardware",
   "analytic_id": "AN0446",
   "detection_strategy_id": "DET0159",
   "analytic_name": "Analytic 0446",
   "platforms": "Windows",
   "log_sources": "Drive Creation (WinEventLog:System)",
   "log_sources_ja": "ドライブ作成 (WinEventLog:System)",
   "tuning": "VendorID | SerialNumber | TimeWindow",
   "detection_logic_en": "Detection of USB-based remote access hardware (e.g., TinyPilot, PiKVM) attached to the host via drive or peripheral enumeration, triggering vendor identifiers or unusual EDID announcements."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1219.003",
   "technique_ja": "リモートアクセスハードウェア",
   "technique_en": "Remote Access Hardware",
   "analytic_id": "AN0447",
   "detection_strategy_id": "DET0159",
   "analytic_name": "Analytic 0447",
   "platforms": "Linux",
   "log_sources": "Drive Creation (auditd:SYSCALL)",
   "log_sources_ja": "ドライブ作成 (auditd:SYSCALL)",
   "tuning": "FriendlyName | MountPath",
   "detection_logic_en": "Insertion of USB-based hardware proxies (e.g., PiKVM) which register under predictable names (e.g., tinypilot) or mount under known paths (e.g., /opt/tinypilot-privileged)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1219.003",
   "technique_ja": "リモートアクセスハードウェア",
   "technique_en": "Remote Access Hardware",
   "analytic_id": "AN0448",
   "detection_strategy_id": "DET0159",
   "analytic_name": "Analytic 0448",
   "platforms": "macOS",
   "log_sources": "Drive Creation (macos:unifiedlog)",
   "log_sources_ja": "ドライブ作成 (macos:unifiedlog)",
   "tuning": "DeviceClass | SerialCorrelationDepth",
   "detection_logic_en": "Attachment of hardware-backed USB KVM devices (e.g., TinyPilot) that enumerate new HID or serial communication interfaces with identifiable metadata."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1568",
   "technique_ja": "動的解決",
   "technique_en": "Dynamic Resolution",
   "analytic_id": "AN0109",
   "detection_strategy_id": "DET0039",
   "analytic_name": "Analytic 0109",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "EntropyThreshold | TimeWindow",
   "detection_logic_en": "Correlate high-frequency or anomalous DNS query activity with processes that do not normally generate network requests (e.g., Office apps, system utilities). Detect pseudo-random or high-entropy domain lookups indicative of domain generation algorithms (DGAs)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1568",
   "technique_ja": "動的解決",
   "technique_en": "Dynamic Resolution",
   "analytic_id": "AN0110",
   "detection_strategy_id": "DET0039",
   "analytic_name": "Analytic 0110",
   "platforms": "Linux",
   "log_sources": "Network Traffic Flow (auditd:SYSCALL) | Network Traffic Content (linux:syslog)",
   "log_sources_ja": "ネットワークトラフィックフロー (auditd:SYSCALL) | ネットワークトラフィック内容 (linux:syslog)",
   "tuning": "DomainReputationFeed | ProcessWhitelist",
   "detection_logic_en": "Monitor /var/log/audit/audit.log and DNS resolver logs for repeated failed lookups or connections to high-entropy domain names. Correlate suspicious DNS queries with process lineage (e.g., Python, bash, or unusual system daemons)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1568",
   "technique_ja": "動的解決",
   "technique_en": "Dynamic Resolution",
   "analytic_id": "AN0111",
   "detection_strategy_id": "DET0039",
   "analytic_name": "Analytic 0111",
   "platforms": "macOS",
   "log_sources": "Network Traffic Content (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ネットワークトラフィック内容 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "NewDomainThreshold | DNSQueryVolume",
   "detection_logic_en": "Inspect unified logs for anomalous DNS resolutions triggered by non-network applications. Flag repeated connections to newly registered or algorithmically generated domains. Correlate with endpoint process telemetry."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1568",
   "technique_ja": "動的解決",
   "technique_en": "Dynamic Resolution",
   "analytic_id": "AN0112",
   "detection_strategy_id": "DET0039",
   "analytic_name": "Analytic 0112",
   "platforms": "ESXi",
   "log_sources": "Network Traffic Flow (esxi:syslog)",
   "log_sources_ja": "ネットワークトラフィックフロー (esxi:syslog)",
   "tuning": "ResolverConfigPaths | ExternalDomainWhitelist",
   "detection_logic_en": "Monitor esxcli and syslog records for DNS resolver changes or repeated queries to unusual external domains by management agents. Detect unauthorized changes to VM or host network settings that redirect DNS lookups."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1568.001",
   "technique_ja": "Fast Flux DNS",
   "technique_en": "Fast Flux DNS",
   "analytic_id": "AN1331",
   "detection_strategy_id": "DET0485",
   "analytic_name": "Analytic 1331",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Security)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Security)",
   "tuning": "DNSQueryBurstThreshold | TimeWindow",
   "detection_logic_en": "Identify repeated DNS resolutions where the same domain name returns multiple IPs in short succession, combined with low TTL values and high query volume from unusual processes. Correlate with process lineage (e.g., Office apps spawning abnormal DNS lookups)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1568.001",
   "technique_ja": "Fast Flux DNS",
   "technique_en": "Fast Flux DNS",
   "analytic_id": "AN1332",
   "detection_strategy_id": "DET0485",
   "analytic_name": "Analytic 1332",
   "platforms": "Linux",
   "log_sources": "Network Traffic Flow (auditd:SYSCALL)",
   "log_sources_ja": "ネットワークトラフィックフロー (auditd:SYSCALL)",
   "tuning": "TTLThreshold | DomainReputationFeed",
   "detection_logic_en": "Monitor resolver logs and auditd events for domains resolving to a rotating set of IPs within very short TTL intervals. Correlate high query rates from non-browser applications (e.g., python, curl)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1568.001",
   "technique_ja": "Fast Flux DNS",
   "technique_en": "Fast Flux DNS",
   "analytic_id": "AN1333",
   "detection_strategy_id": "DET0485",
   "analytic_name": "Analytic 1333",
   "platforms": "macOS",
   "log_sources": "Network Traffic Flow (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ネットワークトラフィックフロー (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "DNSRotationRate | NewDomainThreshold",
   "detection_logic_en": "Use unified logs to identify processes issuing repeated DNS queries where the resolved IP addresses change frequently within very short TTL values. Correlate with outbound network traffic to validate C2-like patterns."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1568.001",
   "technique_ja": "Fast Flux DNS",
   "technique_en": "Fast Flux DNS",
   "analytic_id": "AN1334",
   "detection_strategy_id": "DET0485",
   "analytic_name": "Analytic 1334",
   "platforms": "ESXi",
   "log_sources": "Network Traffic Flow (esxi:syslog)",
   "log_sources_ja": "ネットワークトラフィックフロー (esxi:syslog)",
   "tuning": "ResolverConfigPaths | ExternalDomainWhitelist",
   "detection_logic_en": "Monitor ESXi syslog and esxcli outputs for abnormal DNS resolver behavior, such as frequent domain-to-IP changes or unauthorized modifications of DNS settings used by management agents. Correlate domain lookups with short TTL values."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1568.002",
   "technique_ja": "ドメイン生成アルゴリズム（DGA）",
   "technique_en": "Domain Generation Algorithms",
   "analytic_id": "AN1178",
   "detection_strategy_id": "DET0419",
   "analytic_name": "Analytic 1178",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Security)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Security)",
   "tuning": "EntropyThreshold | QueryFailureRate | TimeWindow",
   "detection_logic_en": "Correlate DNS queries that generate domains with high entropy or gibberish patterns, combined with short-lived connections from unusual processes. Monitor Sysmon DNS events and Windows Security logs for abnormal query rates and failed lookups."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1568.002",
   "technique_ja": "ドメイン生成アルゴリズム（DGA）",
   "technique_en": "Domain Generation Algorithms",
   "analytic_id": "AN1179",
   "detection_strategy_id": "DET0419",
   "analytic_name": "Analytic 1179",
   "platforms": "Linux",
   "log_sources": "Network Traffic Flow (auditd:SYSCALL) | Network Traffic Content (linux:syslog)",
   "log_sources_ja": "ネットワークトラフィックフロー (auditd:SYSCALL) | ネットワークトラフィック内容 (linux:syslog)",
   "tuning": "NXDOMAINThreshold | DomainAge",
   "detection_logic_en": "Identify processes issuing repeated DNS queries to random-looking domains with abnormal entropy or word concatenations. Correlate resolver logs with high NXDOMAIN rates and auditd socket connections."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1568.002",
   "technique_ja": "ドメイン生成アルゴリズム（DGA）",
   "technique_en": "Domain Generation Algorithms",
   "analytic_id": "AN1180",
   "detection_strategy_id": "DET0419",
   "analytic_name": "Analytic 1180",
   "platforms": "macOS",
   "log_sources": "Network Traffic Flow (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ネットワークトラフィックフロー (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "ReputationFeedWhitelist | LexicalScoreThreshold",
   "detection_logic_en": "Monitor unified DNS logs for abnormal domain queries with low lexical similarity to known domains, repeated failed lookups, and random string structures. Cross-check with process logs to confirm unusual origins (non-browser apps)."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1568.002",
   "technique_ja": "ドメイン生成アルゴリズム（DGA）",
   "technique_en": "Domain Generation Algorithms",
   "analytic_id": "AN1181",
   "detection_strategy_id": "DET0419",
   "analytic_name": "Analytic 1181",
   "platforms": "ESXi",
   "log_sources": "Network Traffic Flow (esxi:syslog)",
   "log_sources_ja": "ネットワークトラフィックフロー (esxi:syslog)",
   "tuning": "ResolverConfigPaths | DomainWhitelist",
   "detection_logic_en": "Use ESXi syslogs to track abnormal DNS query patterns from management agents or VMs. Identify high-frequency, low-TTL, or unresolvable domains as suspicious. Correlate with unusual management plane process activity."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1568.003",
   "technique_ja": "DNS計算",
   "technique_en": "DNS Calculation",
   "analytic_id": "AN0728",
   "detection_strategy_id": "DET0262",
   "analytic_name": "Analytic 0728",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "PortDeviationThreshold | TimeWindow",
   "detection_logic_en": "Monitor DNS query results where subsequent connections use derived or unusual port numbers not explicitly resolved, especially when tied to suspicious processes. Correlate Sysmon DNS logs (Event ID 22) with process creation and socket activity."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1568.003",
   "technique_ja": "DNS計算",
   "technique_en": "DNS Calculation",
   "analytic_id": "AN0729",
   "detection_strategy_id": "DET0262",
   "analytic_name": "Analytic 0729",
   "platforms": "Linux",
   "log_sources": "Network Connection Creation (auditd:SYSCALL) | Network Traffic Content (linux:syslog)",
   "log_sources_ja": "ネットワーク接続確立 (auditd:SYSCALL) | ネットワークトラフィック内容 (linux:syslog)",
   "tuning": "EphemeralPortRange | ResolverWhitelist",
   "detection_logic_en": "Inspect resolver and audit logs for processes initiating outbound connections to ports calculated from DNS response IPs. Abnormal ephemeral port usage shortly after DNS queries can indicate DNS calculation behavior."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1568.003",
   "technique_ja": "DNS計算",
   "technique_en": "DNS Calculation",
   "analytic_id": "AN0730",
   "detection_strategy_id": "DET0262",
   "analytic_name": "Analytic 0730",
   "platforms": "macOS",
   "log_sources": "Network Traffic Content (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ネットワークトラフィック内容 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "ProcessAllowlist | ConnectionVolumeThreshold",
   "detection_logic_en": "Use unified logs to detect unusual DNS responses correlated with subsequent connections to calculated or non-standard ports. Monitor non-browser apps making repeated outbound connections that deviate from expected patterns."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1568.003",
   "technique_ja": "DNS計算",
   "technique_en": "DNS Calculation",
   "analytic_id": "AN0731",
   "detection_strategy_id": "DET0262",
   "analytic_name": "Analytic 0731",
   "platforms": "ESXi",
   "log_sources": "Network Traffic Flow (esxi:syslog)",
   "log_sources_ja": "ネットワークトラフィックフロー (esxi:syslog)",
   "tuning": "ManagementPlaneIPs | DomainReputationFeed",
   "detection_logic_en": "Analyze ESXi syslogs for management agents or VMs making outbound connections to dynamically calculated ports derived from DNS responses. Cross-check with VM traffic baselines to identify anomalies."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1571",
   "technique_ja": "非標準ポート",
   "technique_en": "Non-Standard Port",
   "analytic_id": "AN0633",
   "detection_strategy_id": "DET0227",
   "analytic_name": "Analytic 0633",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "PortThresholds | ProcessAllowList | TimeWindow",
   "detection_logic_en": "Processes initiating outbound connections on uncommon ports or using protocols inconsistent with the assigned port. Correlating process creation with subsequent network connections reveals anomalies such as svchost.exe or Office applications using high, atypical ports."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1571",
   "technique_ja": "非標準ポート",
   "technique_en": "Non-Standard Port",
   "analytic_id": "AN0634",
   "detection_strategy_id": "DET0227",
   "analytic_name": "Analytic 0634",
   "platforms": "Linux",
   "log_sources": "Network Traffic Flow (auditd:SYSCALL) | Application Log Content (linux:syslog) | Process Creation (linux:osquery)",
   "log_sources_ja": "ネットワークトラフィックフロー (auditd:SYSCALL) | アプリケーションログ内容 (linux:syslog) | プロセス生成 (linux:osquery)",
   "tuning": "AllowedServices | PayloadEntropyThreshold",
   "detection_logic_en": "Unusual daemons or user processes binding/listening on ports outside of standard ranges, or initiating client connections using mismatched protocol/port pairings."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1571",
   "technique_ja": "非標準ポート",
   "technique_en": "Non-Standard Port",
   "analytic_id": "AN0635",
   "detection_strategy_id": "DET0227",
   "analytic_name": "Analytic 0635",
   "platforms": "macOS",
   "log_sources": "Network Traffic Flow (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ネットワークトラフィックフロー (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "BaselinePortProfiles",
   "detection_logic_en": "Applications making outbound connections on non-standard ports or launchd services bound to ports inconsistent with system baselines."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1571",
   "technique_ja": "非標準ポート",
   "technique_en": "Non-Standard Port",
   "analytic_id": "AN0636",
   "detection_strategy_id": "DET0227",
   "analytic_name": "Analytic 0636",
   "platforms": "ESXi",
   "log_sources": "Network Traffic Flow (esxi:vpxd) | Network Traffic Content (esxcli:network)",
   "log_sources_ja": "ネットワークトラフィックフロー (esxi:vpxd) | ネットワークトラフィック内容 (esxcli:network)",
   "tuning": "ESXiAllowedPorts",
   "detection_logic_en": "VM services or management daemons communicating on ports not defined by VMware defaults, such as vpxa or hostd processes initiating traffic over high-numbered or unexpected ports."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1572",
   "technique_ja": "プロトコルトンネリング",
   "technique_en": "Protocol Tunneling",
   "analytic_id": "AN1483",
   "detection_strategy_id": "DET0538",
   "analytic_name": "Analytic 1483",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "AllowedTools | DataAsymmetryThreshold | TimeWindow",
   "detection_logic_en": "Processes such as plink.exe, ssh.exe, or netsh.exe establishing outbound network connections where traffic patterns show encapsulated protocols (e.g., RDP over SSH). Defender observations include anomalous process-to-network relationships, large asymmetric data flows, and port usage mismatches."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1572",
   "technique_ja": "プロトコルトンネリング",
   "technique_en": "Protocol Tunneling",
   "analytic_id": "AN1484",
   "detection_strategy_id": "DET0538",
   "analytic_name": "Analytic 1484",
   "platforms": "Linux",
   "log_sources": "Network Connection Creation (auditd:SYSCALL) | Application Log Content (linux:syslog) | Process Creation (linux:osquery)",
   "log_sources_ja": "ネットワーク接続確立 (auditd:SYSCALL) | アプリケーションログ内容 (linux:syslog) | プロセス生成 (linux:osquery)",
   "tuning": "ForwardingFlags | ProtocolBaseline",
   "detection_logic_en": "sshd, socat, or custom binaries initiating port forwarding or encapsulating traffic (e.g., RDP, SMB) through SSH or HTTP. Defender sees abnormal connect/bind syscalls, encrypted traffic on ports typically used for non-encrypted services, and outlier traffic volume patterns."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1572",
   "technique_ja": "プロトコルトンネリング",
   "technique_en": "Protocol Tunneling",
   "analytic_id": "AN1485",
   "detection_strategy_id": "DET0538",
   "analytic_name": "Analytic 1485",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Content (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィック内容 (macos:unifiedlog)",
   "tuning": "ExpectedDoHResolvers | PayloadEntropyThreshold",
   "detection_logic_en": "launchd or user-invoked processes (ssh, socat) encapsulating traffic via SSH tunnels, VPN-style tooling, or DNS-over-HTTPS clients. Defender sees outbound TLS traffic with embedded DNS or RDP payloads."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1572",
   "technique_ja": "プロトコルトンネリング",
   "technique_en": "Protocol Tunneling",
   "analytic_id": "AN1486",
   "detection_strategy_id": "DET0538",
   "analytic_name": "Analytic 1486",
   "platforms": "ESXi",
   "log_sources": "Network Traffic Flow (esxi:vpxd) | Network Traffic Content (esxcli:network)",
   "log_sources_ja": "ネットワークトラフィックフロー (esxi:vpxd) | ネットワークトラフィック内容 (esxcli:network)",
   "tuning": "ESXiServiceProfiles",
   "detection_logic_en": "VMware daemons or user processes encapsulating traffic (e.g., guest VMs tunneling via hostd). Defender sees network services inside ESXi creating flows inconsistent with management plane traffic, such as SSH forwarding or DNS-over-HTTPS from management interfaces."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1573",
   "technique_ja": "暗号化チャネル",
   "technique_en": "Encrypted Channel",
   "analytic_id": "AN0759",
   "detection_strategy_id": "DET0273",
   "analytic_name": "Analytic 0759",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Module Load (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | モジュール読み込み (WinEventLog:Sysmon)",
   "tuning": "AllowedEncryptedProcesses | EntropyThreshold | TimeWindow",
   "detection_logic_en": "Processes that normally do not initiate network connections establishing outbound encrypted TLS/SSL sessions, especially with asymmetric traffic volumes (client sending more than receiving) or non-standard certificate chains. Defender observations correlate process creation with unexpected network encryption libraries being loaded."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1573",
   "technique_ja": "暗号化チャネル",
   "technique_en": "Encrypted Channel",
   "analytic_id": "AN0760",
   "detection_strategy_id": "DET0273",
   "analytic_name": "Analytic 0760",
   "platforms": "Linux",
   "log_sources": "Network Connection Creation (auditd:SYSCALL) | Application Log Content (linux:syslog) | Process Creation (linux:osquery)",
   "log_sources_ja": "ネットワーク接続確立 (auditd:SYSCALL) | アプリケーションログ内容 (linux:syslog) | プロセス生成 (linux:osquery)",
   "tuning": "WhitelistedDaemons | CertificateAuthorities",
   "detection_logic_en": "Processes like curl, wget, python, socat, or custom binaries initiating TLS/SSL sessions to non-standard destinations. Defender sees abnormal syscalls for connect(), loading of libssl libraries, and persistent outbound encrypted traffic from daemons not normally communicating externally."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1573",
   "technique_ja": "暗号化チャネル",
   "technique_en": "Encrypted Channel",
   "analytic_id": "AN0761",
   "detection_strategy_id": "DET0273",
   "analytic_name": "Analytic 0761",
   "platforms": "macOS",
   "log_sources": "Network Traffic Content (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ネットワークトラフィック内容 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "DoHResolvers | PayloadEntropyThreshold",
   "detection_logic_en": "Applications or launchd jobs initiating encrypted TLS traffic to rare external hosts. Defender observes unified logs showing ssl/TLS API calls by processes not baseline-approved, and payload entropy suggesting encrypted C2 sessions."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1573",
   "technique_ja": "暗号化チャネル",
   "technique_en": "Encrypted Channel",
   "analytic_id": "AN0762",
   "detection_strategy_id": "DET0273",
   "analytic_name": "Analytic 0762",
   "platforms": "ESXi",
   "log_sources": "Network Traffic Flow (esxi:vpxd) | Network Traffic Content (esxi:vmkernel)",
   "log_sources_ja": "ネットワークトラフィックフロー (esxi:vpxd) | ネットワークトラフィック内容 (esxi:vmkernel)",
   "tuning": "AllowedMgmtHosts",
   "detection_logic_en": "VMware management daemons or guest processes initiating encrypted connections outside expected vCenter, update servers, or internal comms. Defender identifies hostd or vpxa initiating outbound TLS flows with uncommon destinations."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1573",
   "technique_ja": "暗号化チャネル",
   "technique_en": "Encrypted Channel",
   "analytic_id": "AN0763",
   "detection_strategy_id": "DET0273",
   "analytic_name": "Analytic 0763",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Flow (NSM:Flow) | Network Traffic Content (NSM:Connections)",
   "log_sources_ja": "ネットワークトラフィックフロー (NSM:Flow) | ネットワークトラフィック内容 (NSM:Connections)",
   "tuning": "PortProfiles | TrafficAsymmetryRatio",
   "detection_logic_en": "Unusual TLS tunnels through ports not normally encrypted (e.g., TLS on port 8080, 53). Defender sees NetFlow/IPFIX or packet inspection indicating high-entropy traffic volumes and asymmetric client/server exchange ratios."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1573.001",
   "technique_ja": "対称暗号",
   "technique_en": "Symmetric Cryptography",
   "analytic_id": "AN0400",
   "detection_strategy_id": "DET0143",
   "analytic_name": "Analytic 0400",
   "platforms": "Windows",
   "log_sources": "Module Load (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "モジュール読み込み (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "AllowedCryptoProcesses | EntropyThreshold | TimeWindow",
   "detection_logic_en": "Processes that typically do not perform cryptographic operations loading symmetric encryption libraries (e.g., bcryptprimitives.dll, aes.dll), then initiating outbound connections with high-entropy payloads. Defender correlates process creation, DLL load, and anomalous encrypted traffic patterns."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1573.001",
   "technique_ja": "対称暗号",
   "technique_en": "Symmetric Cryptography",
   "analytic_id": "AN0401",
   "detection_strategy_id": "DET0143",
   "analytic_name": "Analytic 0401",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Application Log Content (linux:syslog) | Module Load (linux:osquery)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | アプリケーションログ内容 (linux:syslog) | モジュール読み込み (linux:osquery)",
   "tuning": "TrustedCryptoLibs | TrafficAsymmetryRatio",
   "detection_logic_en": "Unexpected processes (e.g., bash, python, custom binaries) dynamically loading libcrypto or performing AES/RC4 encryption operations, then initiating outbound sessions with abnormal byte entropy or asymmetric traffic patterns."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1573.001",
   "technique_ja": "対称暗号",
   "technique_en": "Symmetric Cryptography",
   "analytic_id": "AN0402",
   "detection_strategy_id": "DET0143",
   "analytic_name": "Analytic 0402",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Content (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィック内容 (macos:unifiedlog)",
   "tuning": "DoHResolvers | PayloadEntropyThreshold",
   "detection_logic_en": "Launchd jobs or user processes invoking symmetric crypto APIs from the Security framework and generating outbound connections carrying randomized payloads inconsistent with normal TLS patterns."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1573.001",
   "technique_ja": "対称暗号",
   "technique_en": "Symmetric Cryptography",
   "analytic_id": "AN0403",
   "detection_strategy_id": "DET0143",
   "analytic_name": "Analytic 0403",
   "platforms": "ESXi",
   "log_sources": "Application Log Content (esxi:vpxd) | Network Traffic Content (esxcli:network)",
   "log_sources_ja": "アプリケーションログ内容 (esxi:vpxd) | ネットワークトラフィック内容 (esxcli:network)",
   "tuning": "AllowedMgmtHosts",
   "detection_logic_en": "ESXi daemons (hostd, vpxa) unexpectedly using symmetric encryption routines for external connections. Defender identifies logs of service traffic with encrypted payloads inconsistent with VMware management baselines."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1573.001",
   "technique_ja": "対称暗号",
   "technique_en": "Symmetric Cryptography",
   "analytic_id": "AN0404",
   "detection_strategy_id": "DET0143",
   "analytic_name": "Analytic 0404",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Flow (NSM:Flow) | Network Traffic Content (NSM:Connections)",
   "log_sources_ja": "ネットワークトラフィックフロー (NSM:Flow) | ネットワークトラフィック内容 (NSM:Connections)",
   "tuning": "PortProfiles | TrafficVolumeThreshold",
   "detection_logic_en": "Flows showing encrypted payloads with high entropy not matching TLS handshake patterns, particularly when occurring on non-standard ports. Defender observes NetFlow/IPFIX byte distribution anomalies or IDS/IPS detecting symmetric encryption patterns without associated key exchange."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1573.002",
   "technique_ja": "非対称暗号",
   "technique_en": "Asymmetric Cryptography",
   "analytic_id": "AN1496",
   "detection_strategy_id": "DET0543",
   "analytic_name": "Analytic 1496",
   "platforms": "Windows",
   "log_sources": "Module Load (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "モジュール読み込み (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "AllowedCryptoProcesses | CertificateAuthorityList | HandshakeTimeout",
   "detection_logic_en": "Processes not typically associated with encryption loading asymmetric crypto libraries (e.g., rsaenh.dll, crypt32.dll) and subsequently initiating outbound TLS/SSL connections with abnormal certificate chains or handshakes. Defender correlates process creation, module load, and unusual encrypted sessions."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1573.002",
   "technique_ja": "非対称暗号",
   "technique_en": "Asymmetric Cryptography",
   "analytic_id": "AN1497",
   "detection_strategy_id": "DET0543",
   "analytic_name": "Analytic 1497",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Application Log Content (linux:syslog) | Module Load (linux:osquery)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | アプリケーションログ内容 (linux:syslog) | モジュール読み込み (linux:osquery)",
   "tuning": "ExpectedCryptoLibs | TrafficAsymmetryRatio",
   "detection_logic_en": "Processes (e.g., bash, python, custom binaries) dynamically linking libcrypto/libssl for RSA key exchange, then creating external connections with abnormal certificate validation or handshake anomalies. Defender observes syscall traces and outbound asymmetric key exchanges from non-SSL-native processes."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1573.002",
   "technique_ja": "非対称暗号",
   "technique_en": "Asymmetric Cryptography",
   "analytic_id": "AN1498",
   "detection_strategy_id": "DET0543",
   "analytic_name": "Analytic 1498",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Content (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィック内容 (macos:unifiedlog)",
   "tuning": "TrustedDoHEndpoints | PayloadEntropyThreshold",
   "detection_logic_en": "Applications or launchd services invoking RSA or public-key routines from the Security framework, followed by outbound SSL/TLS sessions with unrecognized certs or anomalous handshakes. Defender observes unified logs of API calls and suspicious network entropy."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1573.002",
   "technique_ja": "非対称暗号",
   "technique_en": "Asymmetric Cryptography",
   "analytic_id": "AN1499",
   "detection_strategy_id": "DET0543",
   "analytic_name": "Analytic 1499",
   "platforms": "ESXi",
   "log_sources": "Application Log Content (esxi:vpxd) | Network Traffic Content (esxcli:network)",
   "log_sources_ja": "アプリケーションログ内容 (esxi:vpxd) | ネットワークトラフィック内容 (esxcli:network)",
   "tuning": "BaselineMgmtHosts",
   "detection_logic_en": "VMware services (hostd, vpxa) unexpectedly negotiating asymmetric crypto sessions to external endpoints outside vCenter or update servers. Defender sees encrypted handshakes in logs inconsistent with baseline ESXi communication patterns."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1573.002",
   "technique_ja": "非対称暗号",
   "technique_en": "Asymmetric Cryptography",
   "analytic_id": "AN1500",
   "detection_strategy_id": "DET0543",
   "analytic_name": "Analytic 1500",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Flow (NSM:Flow) | Network Traffic Content (IDS:TLSInspection)",
   "log_sources_ja": "ネットワークトラフィックフロー (NSM:Flow) | ネットワークトラフィック内容 (IDS:TLSInspection)",
   "tuning": "PortProfiles | CertValidationPolicy",
   "detection_logic_en": "Encrypted sessions detected with asymmetric key exchange anomalies on non-standard ports or with invalid/malformed certs. Defender correlates NetFlow/IPFIX with IDS/IPS detecting RSA exchanges outside expected TLS flows."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1659",
   "technique_ja": "コンテンツインジェクション",
   "technique_en": "Content Injection",
   "analytic_id": "AN0992",
   "detection_strategy_id": "DET0349",
   "analytic_name": "Analytic 0992",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "MonitoredExtensions | SuspiciousParentProcesses | RedirectList",
   "detection_logic_en": "Detect suspicious file creations and process executions triggered by browser activity (e.g., injected payloads written to %AppData% or Temp directories, then executed). Correlate network anomalies with subsequent local process creation or script execution."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1659",
   "technique_ja": "コンテンツインジェクション",
   "technique_en": "Content Injection",
   "analytic_id": "AN0993",
   "detection_strategy_id": "DET0349",
   "analytic_name": "Analytic 0993",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | File Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ファイル作成 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TempDirectories",
   "detection_logic_en": "Detect curl/wget commands saving executable/script payloads to /tmp or /var/tmp followed by execution. Monitor packet captures or IDS/IPS alerts for injected responses or mismatched content types."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1659",
   "technique_ja": "コンテンツインジェクション",
   "technique_en": "Content Injection",
   "analytic_id": "AN0994",
   "detection_strategy_id": "DET0349",
   "analytic_name": "Analytic 0994",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Creation (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル作成 (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "MonitoredDirectories",
   "detection_logic_en": "Monitor unified logs for processes spawned from Safari or other browsers that immediately load scripts or executables. Detect file drops in ~/Library/Caches or ~/Downloads that execute shortly after being written."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1665",
   "technique_ja": "インフラの隠蔽",
   "technique_en": "Hide Infrastructure",
   "analytic_id": "AN1148",
   "detection_strategy_id": "DET0411",
   "analytic_name": "Analytic 1148",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Security) | Domain Registration (dns:query)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Security) | ドメイン登録 (dns:query)",
   "tuning": "SuspiciousDomains | ResponderIPs",
   "detection_logic_en": "Monitor DNS queries, proxy logs, and user-agent strings for anomalous patterns associated with adversary attempts to hide infrastructure. Defenders may observe DNS resolutions to short-lived domains, abnormal WHOIS registration data, or filtering of known defensive/responder IP addresses."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1665",
   "technique_ja": "インフラの隠蔽",
   "technique_en": "Hide Infrastructure",
   "analytic_id": "AN1149",
   "detection_strategy_id": "DET0411",
   "analytic_name": "Analytic 1149",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Response Metadata (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | 応答メタデータ (NSM:Flow)",
   "tuning": "BlockedAgents",
   "detection_logic_en": "Detect adversaries filtering traffic or modifying server responses to evade scanning. Monitor iptables, nftables, or proxy configurations that deny or redirect requests from known scanning agents or defensive tools."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1665",
   "technique_ja": "インフラの隠蔽",
   "technique_en": "Hide Infrastructure",
   "analytic_id": "AN1150",
   "detection_strategy_id": "DET0411",
   "analytic_name": "Analytic 1150",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Response Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | 応答内容 (NSM:Flow)",
   "tuning": "TrustedHostingProviders",
   "detection_logic_en": "Monitor unified logs for manipulation of proxy configurations, DNS resolution, or filtering rules. Adversaries may redirect responses or use trusted domains that later resolve to malicious C2 infrastructure."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1665",
   "technique_ja": "インフラの隠蔽",
   "technique_en": "Hide Infrastructure",
   "analytic_id": "AN1151",
   "detection_strategy_id": "DET0411",
   "analytic_name": "Analytic 1151",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "GeoIPRanges",
   "detection_logic_en": "Inspect network telemetry for adversary attempts to blend malicious traffic with legitimate flows using VPNs, proxies, or geolocation spoofing. Defensive teams may observe anomalous tunnels, encrypted sessions to suspicious domains, or geo-mismatched IP activity."
  },
  {
   "tactic_id": "TA0011",
   "tactic_ja": "コマンド＆コントロール",
   "technique_id": "T1665",
   "technique_ja": "インフラの隠蔽",
   "technique_en": "Hide Infrastructure",
   "analytic_id": "AN1152",
   "detection_strategy_id": "DET0411",
   "analytic_name": "Analytic 1152",
   "platforms": "ESXi",
   "log_sources": "Domain Registration (esxi:vmkernel) | Network Traffic Content (esxi:vmkernel)",
   "log_sources_ja": "ドメイン登録 (esxi:vmkernel) | ネットワークトラフィック内容 (esxi:vmkernel)",
   "tuning": "MonitoredVMs",
   "detection_logic_en": "Monitor VM-level DNS and network traffic logs for adversary-controlled domains or selective response behavior (e.g., dropped requests from security scanners)."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1011",
   "technique_ja": "他のネットワーク媒体経由の持ち出し",
   "technique_en": "Exfiltration Over Other Network Medium",
   "analytic_id": "AN0212",
   "detection_strategy_id": "DET0077",
   "analytic_name": "Analytic 0212",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Content (WinEventLog:System) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (WinEventLog:System) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "InterfaceType | FileSizeThreshold | TimeWindow",
   "detection_logic_en": "Execution of file transfer or network access activity through non-primary interfaces (e.g., WiFi, Bluetooth, cellular) by processes not typically associated with such behavior (e.g., rundll32, powershell, regsvr32)."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1011",
   "technique_ja": "他のネットワーク媒体経由の持ち出し",
   "technique_en": "Exfiltration Over Other Network Medium",
   "analytic_id": "AN0213",
   "detection_strategy_id": "DET0077",
   "analytic_name": "Analytic 0213",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "CommandPattern | NetworkDevice",
   "detection_logic_en": "Use of `rfkill`, `nmcli`, or low-level tools (e.g., `iw`, `hcitool`, `pppd`) to enable alternate interfaces followed by data transfer via non-primary NICs."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1011",
   "technique_ja": "他のネットワーク媒体経由の持ち出し",
   "technique_en": "Exfiltration Over Other Network Medium",
   "analytic_id": "AN0214",
   "detection_strategy_id": "DET0077",
   "analytic_name": "Analytic 0214",
   "platforms": "macOS",
   "log_sources": "Network Traffic Content (macos:unifiedlog) | Process Creation (macos:osquery) | Host Status (macos:osquery)",
   "log_sources_ja": "ネットワークトラフィック内容 (macos:unifiedlog) | プロセス生成 (macos:osquery) | ホスト状態 (macos:osquery)",
   "tuning": "Protocol | InterfaceActivityWindow",
   "detection_logic_en": "AppleScript or system calls to activate WiFi/Bluetooth interfaces (`networksetup`, `blueutil`), followed by exfiltration via AirDrop, cloud sync, or network socket."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1011.001",
   "technique_ja": "Bluetooth経由の持ち出し",
   "technique_en": "Exfiltration Over Bluetooth",
   "analytic_id": "AN1531",
   "detection_strategy_id": "DET0554",
   "analytic_name": "Analytic 1531",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:System) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:System) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | InterfaceType | FileSizeThreshold",
   "detection_logic_en": "Detection of non-interactive or suspicious processes accessing Bluetooth interfaces and transmitting outbound traffic following file access or staging activity."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1011.001",
   "technique_ja": "Bluetooth経由の持ち出し",
   "technique_en": "Exfiltration Over Bluetooth",
   "analytic_id": "AN1532",
   "detection_strategy_id": "DET0554",
   "analytic_name": "Analytic 1532",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | Network Connection Creation (linux:syslog) | File Access (linux:osquery)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ネットワーク接続確立 (linux:syslog) | ファイルアクセス (linux:osquery)",
   "tuning": "BluetoothUtility | SessionWindow",
   "detection_logic_en": "Use of hcitool, bluetoothctl, or rfcomm to initialize Bluetooth connection paired with recent file reads by the same user or session."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1011.001",
   "technique_ja": "Bluetooth経由の持ち出し",
   "technique_en": "Exfiltration Over Bluetooth",
   "analytic_id": "AN1533",
   "detection_strategy_id": "DET0554",
   "analytic_name": "Analytic 1533",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Network Connection Creation (macos:osquery) | File Access (macos:osquery)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ネットワーク接続確立 (macos:osquery) | ファイルアクセス (macos:osquery)",
   "tuning": "ProcessContext | PayloadType",
   "detection_logic_en": "Observation of `blueutil`/`networksetup` commands or low-level APIs toggling Bluetooth or initiating transfers, especially if paired with recent large file read activity by non-GUI processes."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1020",
   "technique_ja": "自動持ち出し",
   "technique_en": "Automated Exfiltration",
   "analytic_id": "AN1113",
   "detection_strategy_id": "DET0397",
   "analytic_name": "Analytic 1113",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | DestinationIP",
   "detection_logic_en": "Detection of automated tools or scripts periodically transmitting data to external destinations using scheduled tasks or background processes."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1020",
   "technique_ja": "自動持ち出し",
   "technique_en": "Automated Exfiltration",
   "analytic_id": "AN1114",
   "detection_strategy_id": "DET0397",
   "analytic_name": "Analytic 1114",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "CronJobInterval | UserContext",
   "detection_logic_en": "Background scripts (e.g., via cron) or daemons transmitting data repeatedly to remote IPs or URLs."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1020",
   "technique_ja": "自動持ち出し",
   "technique_en": "Automated Exfiltration",
   "analytic_id": "AN1115",
   "detection_strategy_id": "DET0397",
   "analytic_name": "Analytic 1115",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Connection Creation (macos:unifiedlog) | Scheduled Job Creation (macos:cron)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワーク接続確立 (macos:unifiedlog) | スケジュールジョブ作成 (macos:cron)",
   "tuning": "LaunchInterval | DestinationPort",
   "detection_logic_en": "Observation of LaunchAgents or LaunchDaemons establishing periodic external connections indicative of automated data transfer."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1020.001",
   "technique_ja": "トラフィックの複製",
   "technique_en": "Traffic Duplication",
   "analytic_id": "AN1131",
   "detection_strategy_id": "DET0403",
   "analytic_name": "Analytic 1131",
   "platforms": "IaaS",
   "log_sources": "Network Traffic Flow (AWS:CloudTrail) | Network Connection Creation (AWS:VPCFlowLogs)",
   "log_sources_ja": "ネットワークトラフィックフロー (AWS:CloudTrail) | ネットワーク接続確立 (AWS:VPCFlowLogs)",
   "tuning": "TimeWindow | MirrorDestinationCIDR | UserIdentity",
   "detection_logic_en": "Configuration changes to virtual TAP/mirror policies that forward traffic to unapproved destinations. Detection correlates management plane API calls with mirrored traffic observation."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1020.001",
   "technique_ja": "トラフィックの複製",
   "technique_en": "Traffic Duplication",
   "analytic_id": "AN1132",
   "detection_strategy_id": "DET0403",
   "analytic_name": "Analytic 1132",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Flow (networkdevice:syslog) | Network Connection Creation (networkdevice:Flow)",
   "log_sources_ja": "ネットワークトラフィックフロー (networkdevice:syslog) | ネットワーク接続確立 (networkdevice:Flow)",
   "tuning": "ConfigChangeType | MirrorDestinationPort | DeviceRole",
   "detection_logic_en": "Unauthorized mirroring sessions initiated on routers/switches (e.g., via `monitor session`, `mirror port`) coupled with outbound traffic from mirrored interface to unexpected destinations."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1029",
   "technique_ja": "スケジュールされた転送",
   "technique_en": "Scheduled Transfer",
   "analytic_id": "AN1118",
   "detection_strategy_id": "DET0399",
   "analytic_name": "Analytic 1118",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Scheduled Job Metadata (WinEventLog:System)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | スケジュールジョブメタデータ (WinEventLog:System)",
   "tuning": "TimeWindow | DestIPAllowlist | ParentProcessBaseline",
   "detection_logic_en": "Recurring network exfiltration initiated by scheduled or script-based processes exhibiting time-based regularity and consistent external destinations."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1029",
   "technique_ja": "スケジュールされた転送",
   "technique_en": "Scheduled Transfer",
   "analytic_id": "AN1119",
   "detection_strategy_id": "DET0399",
   "analytic_name": "Analytic 1119",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Scheduled Job Metadata (linux:cron) | Network Connection Creation (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | スケジュールジョブメタデータ (linux:cron) | ネットワーク接続確立 (NSM:Flow)",
   "tuning": "ScriptPathRegex | CronIntervalThreshold | ExfilUserContext",
   "detection_logic_en": "Detection of cron-based or script-based recurring transfers where the same script, user, or destination reappears at predictable intervals."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1029",
   "technique_ja": "スケジュールされた転送",
   "technique_en": "Scheduled Transfer",
   "analytic_id": "AN1120",
   "detection_strategy_id": "DET0399",
   "analytic_name": "Analytic 1120",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:endpointsecurity) | Scheduled Job Metadata (macos:launchd) | Network Traffic Flow (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:endpointsecurity) | スケジュールジョブメタデータ (macos:launchd) | ネットワークトラフィックフロー (macos:unifiedlog)",
   "tuning": "AgentPathPatterns | RepeatIntervalDelta | UserHomeJobs",
   "detection_logic_en": "LaunchAgent or launchd recurring jobs initiating data transfer to consistent external IPs or domains with repeat timing signatures."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1030",
   "technique_ja": "データ転送サイズ制限",
   "technique_en": "Data Transfer Size Limits",
   "analytic_id": "AN0596",
   "detection_strategy_id": "DET0213",
   "analytic_name": "Analytic 0596",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "PacketSizeThreshold | IntervalRepeatWindow | KnownServicePorts",
   "detection_logic_en": "Adversary uses a process to establish outbound connections that transmit uniform packet sizes at a consistent interval, avoiding threshold-based network alerts."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1030",
   "technique_ja": "データ転送サイズ制限",
   "technique_en": "Data Transfer Size Limits",
   "analytic_id": "AN0597",
   "detection_strategy_id": "DET0213",
   "analytic_name": "Analytic 0597",
   "platforms": "Linux",
   "log_sources": "Network Connection Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "ProcessNetworkBaseline | PayloadLengthVariance | RepeatFrequencyThreshold",
   "detection_logic_en": "Outbound connections from non-network-facing processes repeatedly send similarly sized payloads within uniform time intervals."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1030",
   "technique_ja": "データ転送サイズ制限",
   "technique_en": "Data Transfer Size Limits",
   "analytic_id": "AN0598",
   "detection_strategy_id": "DET0213",
   "analytic_name": "Analytic 0598",
   "platforms": "macOS",
   "log_sources": "Network Traffic Flow (macos:unifiedlog) | Network Connection Creation (macos:endpointsecurity)",
   "log_sources_ja": "ネットワークトラフィックフロー (macos:unifiedlog) | ネットワーク接続確立 (macos:endpointsecurity)",
   "tuning": "LaunchdJobContext | TransferSizeMedian | TransferProtocolOutlier",
   "detection_logic_en": "Processes on macOS initiate external connections that consistently transmit data in fixed sizes using LaunchAgents or unexpected users."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1041",
   "technique_ja": "C2チャネル経由の持ち出し",
   "technique_en": "Exfiltration Over C2 Channel",
   "analytic_id": "AN0988",
   "detection_strategy_id": "DET0348",
   "analytic_name": "Analytic 0988",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Network Traffic Content (NSM:Flow) | File Access (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ネットワークトラフィック内容 (NSM:Flow) | ファイルアクセス (WinEventLog:Security)",
   "tuning": "DataVolumeThreshold | KnownBenignProcesses",
   "detection_logic_en": "Identifies suspicious outbound traffic volume mismatches from processes that typically do not generate network activity, particularly over C2 protocols like HTTPS, DNS, or custom TCP/UDP ports, following file or data access."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1041",
   "technique_ja": "C2チャネル経由の持ち出し",
   "technique_en": "Exfiltration Over C2 Channel",
   "analytic_id": "AN0989",
   "detection_strategy_id": "DET0348",
   "analytic_name": "Analytic 0989",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "OutboundEntropyScore | ConnectionDuration",
   "detection_logic_en": "Monitors for processes reading sensitive files then immediately initiating unusual outbound connections or bulk transfer sessions over persistent sockets, particularly with encrypted or binary payloads."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1041",
   "technique_ja": "C2チャネル経由の持ち出し",
   "technique_en": "Exfiltration Over C2 Channel",
   "analytic_id": "AN0990",
   "detection_strategy_id": "DET0348",
   "analytic_name": "Analytic 0990",
   "platforms": "macOS",
   "log_sources": "Network Traffic Content (macos:unifiedlog) | Network Traffic Flow (macos:osquery) | Process Creation (macos:osquery)",
   "log_sources_ja": "ネットワークトラフィック内容 (macos:unifiedlog) | ネットワークトラフィックフロー (macos:osquery) | プロセス生成 (macos:osquery)",
   "tuning": "ParentProcessAncestry | ProtocolList",
   "detection_logic_en": "Detects unauthorized applications or scripts accessing sensitive data followed by establishing encrypted outbound communication to rare external destinations or with abnormal byte ratios."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1041",
   "technique_ja": "C2チャネル経由の持ち出し",
   "technique_en": "Exfiltration Over C2 Channel",
   "analytic_id": "AN0991",
   "detection_strategy_id": "DET0348",
   "analytic_name": "Analytic 0991",
   "platforms": "ESXi",
   "log_sources": "Network Traffic Flow (esxi:vpxa) | Network Traffic Content (esxi:vmkernel) | File Access (esxi:syslog)",
   "log_sources_ja": "ネットワークトラフィックフロー (esxi:vpxa) | ネットワークトラフィック内容 (esxi:vmkernel) | ファイルアクセス (esxi:syslog)",
   "tuning": "GuestOSAllowList | TransferSizeThresholdMB | ProtocolAllowList",
   "detection_logic_en": "Detects VMs sending outbound traffic through non-standard services or to unknown destinations. Exfiltration over reverse shells tunneled via VMkernel or custom payloads routed via hostd/vpxa."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1048",
   "technique_ja": "代替プロトコル経由の持ち出し",
   "technique_en": "Exfiltration Over Alternative Protocol",
   "analytic_id": "AN0367",
   "detection_strategy_id": "DET0131",
   "analytic_name": "Analytic 0367",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Security)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Security)",
   "tuning": "DataVolumeThresholdMB | ProtocolAllowList | TimeWindow | ParentProcessAnomaly",
   "detection_logic_en": "Detects unusual outbound file transfer behavior using protocols like FTP, SMB, SMTP, or DNS, involving non-standard processes, off-hour activity, or uncommonly high volume."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1048",
   "technique_ja": "代替プロトコル経由の持ち出し",
   "technique_en": "Exfiltration Over Alternative Protocol",
   "analytic_id": "AN0368",
   "detection_strategy_id": "DET0131",
   "analytic_name": "Analytic 0368",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (auditd:SYSCALL) | File Access (auditd:SYSCALL) | File Modification (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (auditd:SYSCALL) | ファイルアクセス (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "ProtocolType | UserContext | FileExtensionSensitivity",
   "detection_logic_en": "Detects file exfiltration using tools like curl, scp, or custom binaries over protocols such as FTP, HTTP/S, or DNS tunneling, especially outside baseline user behavior."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1048",
   "technique_ja": "代替プロトコル経由の持ち出し",
   "technique_en": "Exfiltration Over Alternative Protocol",
   "analytic_id": "AN0369",
   "detection_strategy_id": "DET0131",
   "analytic_name": "Analytic 0369",
   "platforms": "macOS",
   "log_sources": "Network Traffic Content (macos:unifiedlog) | Process Creation (macos:osquery) | File Creation (macos:osquery)",
   "log_sources_ja": "ネットワークトラフィック内容 (macos:unifiedlog) | プロセス生成 (macos:osquery) | ファイル作成 (macos:osquery)",
   "tuning": "ProtocolUnusualnessScore | ExecutableBaselining",
   "detection_logic_en": "Detects non-native file transfer via curl, Python scripts, or AppleScript using uncommon protocols like FTP, SMTP, or DNS exfiltration through mDNSResponder abuse."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1048",
   "technique_ja": "代替プロトコル経由の持ち出し",
   "technique_en": "Exfiltration Over Alternative Protocol",
   "analytic_id": "AN0370",
   "detection_strategy_id": "DET0131",
   "analytic_name": "Analytic 0370",
   "platforms": "IaaS",
   "log_sources": "Cloud Storage Access (AWS:CloudTrail) | Network Traffic Flow (AWS:VPCFlowLogs)",
   "log_sources_ja": "クラウドストレージアクセス (AWS:CloudTrail) | ネットワークトラフィックフロー (AWS:VPCFlowLogs)",
   "tuning": "IAMRoleContext | GeoDestinationThreshold",
   "detection_logic_en": "Detects access to cloud APIs or CLI tools to move or sync files from sensitive buckets to external endpoints using protocols like HTTPS or S3 APIs."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1048",
   "technique_ja": "代替プロトコル経由の持ち出し",
   "technique_en": "Exfiltration Over Alternative Protocol",
   "analytic_id": "AN0371",
   "detection_strategy_id": "DET0131",
   "analytic_name": "Analytic 0371",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:hostd) | Network Connection Creation (esxi:vmkernel)",
   "log_sources_ja": "コマンド実行 (esxi:hostd) | ネットワーク接続確立 (esxi:vmkernel)",
   "tuning": "GuestTrafficBaseline | ServiceAccountProfile",
   "detection_logic_en": "Detects outbound traffic from hostd/vpxa or guest VM interfaces using unauthorized protocols such as FTP, HTTP POST bursts, or long-lived DNS tunnels."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1048.001",
   "technique_ja": "対称暗号化された非C2プロトコル経由の持ち出し",
   "technique_en": "Exfiltration Over Symmetric Encrypted Non-C2 Protocol",
   "analytic_id": "AN1389",
   "detection_strategy_id": "DET0503",
   "analytic_name": "Analytic 1389",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "PayloadEntropyThreshold | TimeWindow | ExecutableAllowlist",
   "detection_logic_en": "Detects the execution of non-browser processes establishing outbound encrypted network connections using uncommon symmetric encryption protocols (e.g., AES via PowerShell or custom scripts) to alternate external destinations."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1048.001",
   "technique_ja": "対称暗号化された非C2プロトコル経由の持ち出し",
   "technique_en": "Exfiltration Over Symmetric Encrypted Non-C2 Protocol",
   "analytic_id": "AN1390",
   "detection_strategy_id": "DET0503",
   "analytic_name": "Analytic 1390",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "FileTransferIndicator | LibraryCallTracking",
   "detection_logic_en": "Detects command-line utilities or scripts using encryption libraries or symmetric algorithms (e.g., OpenSSL AES, GPG, Python + PyCrypto) in conjunction with outbound file transfers or traffic to external destinations."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1048.001",
   "technique_ja": "対称暗号化された非C2プロトコル経由の持ち出し",
   "technique_en": "Exfiltration Over Symmetric Encrypted Non-C2 Protocol",
   "analytic_id": "AN1391",
   "detection_strategy_id": "DET0503",
   "analytic_name": "Analytic 1391",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Flow (macos:osquery) | Network Connection Creation (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィックフロー (macos:osquery) | ネットワーク接続確立 (macos:unifiedlog)",
   "tuning": "ApplicationProfileBaseline | EncryptionRoutinePattern",
   "detection_logic_en": "Detects symmetric key-based encryption operations (e.g., AES via Python, AppleScript, or OpenSSL) followed by unusual outbound connections from non-browser applications or scripted tools."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1048.001",
   "technique_ja": "対称暗号化された非C2プロトコル経由の持ち出し",
   "technique_en": "Exfiltration Over Symmetric Encrypted Non-C2 Protocol",
   "analytic_id": "AN1392",
   "detection_strategy_id": "DET0503",
   "analytic_name": "Analytic 1392",
   "platforms": "ESXi",
   "log_sources": "Network Traffic Flow (esxi:vmkernel) | Command Execution (esxi:hostd) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィックフロー (esxi:vmkernel) | コマンド実行 (esxi:hostd) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "GuestVMExfilWatchlist | ServiceEgressProfile",
   "detection_logic_en": "Detects unexpected encrypted egress traffic from management services (e.g., hostd) or guest VMs utilizing symmetric encryption without traditional protocols (e.g., FTP with embedded AES ciphertext)."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1048.002",
   "technique_ja": "非対称暗号化された非C2プロトコル経由の持ち出し",
   "technique_en": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol",
   "analytic_id": "AN1413",
   "detection_strategy_id": "DET0512",
   "analytic_name": "Analytic 1413",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | File Access (WinEventLog:Security) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Security) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "TimeWindow | CertificateIssuerDenylist | BinaryAllowlist",
   "detection_logic_en": "Detects non-browser processes that establish encrypted outbound connections (e.g., TLS/SSL) to unfamiliar or atypical destinations for the host/user, following a data staging or compression event."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1048.002",
   "technique_ja": "非対称暗号化された非C2プロトコル経由の持ち出し",
   "technique_en": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol",
   "analytic_id": "AN1414",
   "detection_strategy_id": "DET0512",
   "analytic_name": "Analytic 1414",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow) | File Access (auditd:SYSCALL)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow) | ファイルアクセス (auditd:SYSCALL)",
   "tuning": "ConnectionDestinationScope | FileAccessExtensionList | SSLClientProcessBaseline",
   "detection_logic_en": "Detects staged file access (e.g., archive or obfuscation), followed by an encrypted outbound connection (TLS/HTTPS) from unusual processes such as curl/wget, Python scripts, or custom binaries."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1048.002",
   "technique_ja": "非対称暗号化された非C2プロトコル経由の持ち出し",
   "technique_en": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol",
   "analytic_id": "AN1415",
   "detection_strategy_id": "DET0512",
   "analytic_name": "Analytic 1415",
   "platforms": "macOS",
   "log_sources": "Network Traffic Flow (macos:osquery) | Process Creation (macos:osquery) | File Access (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィックフロー (macos:osquery) | プロセス生成 (macos:osquery) | ファイルアクセス (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "OutboundTrafficVolumeThreshold | FileSensitivityContext",
   "detection_logic_en": "Detects abnormal encrypted network connections (via TLS/HTTPS) initiated by non-browser binaries, particularly after sensitive file access or compression events."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1048.002",
   "technique_ja": "非対称暗号化された非C2プロトコル経由の持ち出し",
   "technique_en": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol",
   "analytic_id": "AN1416",
   "detection_strategy_id": "DET0512",
   "analytic_name": "Analytic 1416",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:hostd) | Network Traffic Flow (esxi:vmkernel)",
   "log_sources_ja": "コマンド実行 (esxi:hostd) | ネットワークトラフィックフロー (esxi:vmkernel)",
   "tuning": "VMToEgressPathWatchlist | TLSClientAppIdentifier",
   "detection_logic_en": "Detects unexpected encrypted outbound connections from management components or guest VMs using TLS, particularly after data volume spikes or script-based orchestration from within guest environments."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1048.003",
   "technique_ja": "非暗号化の非C2プロトコル経由の持ち出し",
   "technique_en": "Exfiltration Over Unencrypted Non-C2 Protocol",
   "analytic_id": "AN0423",
   "detection_strategy_id": "DET0149",
   "analytic_name": "Analytic 0423",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon) | File Access (WinEventLog:Security) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Security) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "UnencryptedProtocolList | DataTransferSizeThreshold | ParentProcessDenylist",
   "detection_logic_en": "Detects data access or staging events followed by outbound data flows using unencrypted protocols (e.g., FTP, HTTP) initiated by unexpected processes or to rare destinations."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1048.003",
   "technique_ja": "非暗号化の非C2プロトコル経由の持ち出し",
   "technique_en": "Exfiltration Over Unencrypted Non-C2 Protocol",
   "analytic_id": "AN0424",
   "detection_strategy_id": "DET0149",
   "analytic_name": "Analytic 0424",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Connection Creation (auditd:SYSCALL) | Network Traffic Content (NSM:Flow) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワーク接続確立 (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "SensitiveDirectoryWatchlist | ProcessBaseline | TimeWindow",
   "detection_logic_en": "Detects file access or compression utilities followed by outbound connections using curl, wget, ftp, or custom binaries communicating over unencrypted protocols."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1048.003",
   "technique_ja": "非暗号化の非C2プロトコル経由の持ち出し",
   "technique_en": "Exfiltration Over Unencrypted Non-C2 Protocol",
   "analytic_id": "AN0425",
   "detection_strategy_id": "DET0149",
   "analytic_name": "Analytic 0425",
   "platforms": "macOS",
   "log_sources": "Network Traffic Flow (macos:osquery) | Process Creation (macos:osquery) | File Access (macos:unifiedlog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ネットワークトラフィックフロー (macos:osquery) | プロセス生成 (macos:osquery) | ファイルアクセス (macos:unifiedlog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ScriptedClientAllowlist | PayloadInspectionKeywordList",
   "detection_logic_en": "Detects abnormal outbound HTTP/FTP connections by local scripts or binaries outside of standard browser activity, following access to local documents or user data."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1048.003",
   "technique_ja": "非暗号化の非C2プロトコル経由の持ち出し",
   "technique_en": "Exfiltration Over Unencrypted Non-C2 Protocol",
   "analytic_id": "AN0426",
   "detection_strategy_id": "DET0149",
   "analytic_name": "Analytic 0426",
   "platforms": "ESXi",
   "log_sources": "Command Execution (esxi:hostd) | Network Traffic Flow (NSM:Flow) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (esxi:hostd) | ネットワークトラフィックフロー (NSM:Flow) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "VMConfigAccessPathWatchlist | OutboundProtocolProfile",
   "detection_logic_en": "Detects shell-based scripts accessing configuration files or snapshots and transmitting them over unencrypted protocols such as FTP or HTTP to non-management IPs."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1048.003",
   "technique_ja": "非暗号化の非C2プロトコル経由の持ち出し",
   "technique_en": "Exfiltration Over Unencrypted Non-C2 Protocol",
   "analytic_id": "AN0427",
   "detection_strategy_id": "DET0149",
   "analytic_name": "Analytic 0427",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:cli) | Network Traffic Flow (networkdevice:syslog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (networkdevice:cli) | ネットワークトラフィックフロー (networkdevice:syslog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "ProtocolCommandWatchlist | DestinationIPBlocklist",
   "detection_logic_en": "Detects use of unencrypted protocols (e.g., TFTP, FTP, HTTP) to transfer configuration files, routing tables, or logs to untrusted IP addresses, especially using administrative commands like `copy run ftp:`."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1052",
   "technique_ja": "物理媒体経由の持ち出し",
   "technique_en": "Exfiltration Over Physical Medium",
   "analytic_id": "AN0342",
   "detection_strategy_id": "DET0123",
   "analytic_name": "Analytic 0342",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | File Access (WinEventLog:Security) | Drive Creation (WinEventLog:System)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Security) | ドライブ作成 (WinEventLog:System)",
   "tuning": "DriveTypeFilter | ProcessNameExclusionList | TimeWindow",
   "detection_logic_en": "Detects removable drive insertion followed by unusual file access, compression, or staging activity by unauthorized users or unexpected processes."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1052",
   "technique_ja": "物理媒体経由の持ち出し",
   "technique_en": "Exfiltration Over Physical Medium",
   "analytic_id": "AN0343",
   "detection_strategy_id": "DET0123",
   "analytic_name": "Analytic 0343",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Drive Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | ドライブ作成 (auditd:SYSCALL)",
   "tuning": "MountPointPattern | UserGroupScope | AccessVolumeThreshold",
   "detection_logic_en": "Detects mounted external devices (via /media or /mnt) followed by large file read or copy operations by shell scripts, unauthorized users, or staging tools (e.g., tar, rsync)."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1052",
   "technique_ja": "物理媒体経由の持ち出し",
   "technique_en": "Exfiltration Over Physical Medium",
   "analytic_id": "AN0344",
   "detection_strategy_id": "DET0123",
   "analytic_name": "Analytic 0344",
   "platforms": "macOS",
   "log_sources": "Drive Creation (macos:unifiedlog) | File Access (macos:osquery) | Command Execution (fs:fsusage)",
   "log_sources_ja": "ドライブ作成 (macos:unifiedlog) | ファイルアクセス (macos:osquery) | コマンド実行 (fs:fsusage)",
   "tuning": "VolumeNamePattern | ProcessOrigin | UserSessionCheck",
   "detection_logic_en": "Detects mounting of external volumes followed by high-volume or sensitive file access via Finder, terminal, or third-party apps (e.g., rsync, zip)."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1052.001",
   "technique_ja": "USB経由の持ち出し",
   "technique_en": "Exfiltration over USB",
   "analytic_id": "AN0616",
   "detection_strategy_id": "DET0220",
   "analytic_name": "Analytic 0616",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | File Access (WinEventLog:Security) | Drive Creation (WinEventLog:System)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Security) | ドライブ作成 (WinEventLog:System)",
   "tuning": "SensitiveFilePathRegex | UserContext | TimeWindow",
   "detection_logic_en": "Detects USB device insertion followed by high-volume or sensitive file access and staging activity by suspicious processes or accounts."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1052.001",
   "technique_ja": "USB経由の持ち出し",
   "technique_en": "Exfiltration over USB",
   "analytic_id": "AN0617",
   "detection_strategy_id": "DET0220",
   "analytic_name": "Analytic 0617",
   "platforms": "Linux",
   "log_sources": "File Access (auditd:SYSCALL) | Drive Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイルアクセス (auditd:SYSCALL) | ドライブ作成 (auditd:SYSCALL)",
   "tuning": "MountPath | CopyCommandSignature | AccessRateThreshold",
   "detection_logic_en": "Detects USB block device mount followed by file access in sensitive directories or high-volume copy operations by user-controlled processes."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1052.001",
   "technique_ja": "USB経由の持ち出し",
   "technique_en": "Exfiltration over USB",
   "analytic_id": "AN0618",
   "detection_strategy_id": "DET0220",
   "analytic_name": "Analytic 0618",
   "platforms": "macOS",
   "log_sources": "Drive Creation (macos:unifiedlog) | File Access (fs:fsusage) | Process Creation (macos:osquery)",
   "log_sources_ja": "ドライブ作成 (macos:unifiedlog) | ファイルアクセス (fs:fsusage) | プロセス生成 (macos:osquery)",
   "tuning": "DriveLabelFilter | ScriptExecutionContext | VolumeMountFrequency",
   "detection_logic_en": "Detects external volume mount with Finder, Terminal, or script-initiated file copy from user profiles, sensitive folders, or cloud storage sync directories to USB."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1537",
   "technique_ja": "クラウドアカウントへのデータ転送",
   "technique_en": "Transfer Data to Cloud Account",
   "analytic_id": "AN1580",
   "detection_strategy_id": "DET0573",
   "analytic_name": "Analytic 1580",
   "platforms": "IaaS",
   "log_sources": "Snapshot Modification (AWS:CloudTrail) | Cloud Storage Modification (AWS:CloudTrail) | Snapshot Creation (AWS:CloudTrail) | Snapshot Metadata (AWS:CloudTrail) | Network Traffic Content (AWS:VPCFlowLogs)",
   "log_sources_ja": "スナップショット変更 (AWS:CloudTrail) | クラウドストレージ変更 (AWS:CloudTrail) | スナップショット作成 (AWS:CloudTrail) | スナップショットメタデータ (AWS:CloudTrail) | ネットワークトラフィック内容 (AWS:VPCFlowLogs)",
   "tuning": "CrossAccountIDList | Region | VolumeSizeThresholdGB | TimeWindow",
   "detection_logic_en": "Detects snapshot sharing, backup exports, or data object transfers from victim-owned cloud accounts to other cloud identities within the same provider (e.g., AWS, Azure) using snapshot sharing, S3 bucket policy updates, or SAS URI generation."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1537",
   "technique_ja": "クラウドアカウントへのデータ転送",
   "technique_en": "Transfer Data to Cloud Account",
   "analytic_id": "AN1581",
   "detection_strategy_id": "DET0573",
   "analytic_name": "Analytic 1581",
   "platforms": "Office Suite",
   "log_sources": "Cloud Storage Modification (m365:unified) | Cloud Storage Metadata (m365:unified) | Application Log Content (m365:unified)",
   "log_sources_ja": "クラウドストレージ変更 (m365:unified) | クラウドストレージメタデータ (m365:unified) | アプリケーションログ内容 (m365:unified)",
   "tuning": "ExternalDomainList | TimeWindow | SharingMethod",
   "detection_logic_en": "Detects user activity that shares or syncs files with external domains via link generation, OneDrive external sharing, or file transfer actions involving non-whitelisted partner tenants."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1537",
   "technique_ja": "クラウドアカウントへのデータ転送",
   "technique_en": "Transfer Data to Cloud Account",
   "analytic_id": "AN1582",
   "detection_strategy_id": "DET0573",
   "analytic_name": "Analytic 1582",
   "platforms": "SaaS",
   "log_sources": "Cloud Storage Modification (saas:googledrive) | Cloud Storage Metadata (saas:box)",
   "log_sources_ja": "クラウドストレージ変更 (saas:googledrive) | クラウドストレージメタデータ (saas:box)",
   "tuning": "UserContext | DomainReputationList | PayloadVolumeThreshold",
   "detection_logic_en": "Detects use of built-in SaaS sharing mechanisms to transfer ownership or share access of critical data to external tenants or untrusted users through API calls or link generation features."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567",
   "technique_ja": "Webサービス経由の持ち出し",
   "technique_en": "Exfiltration Over Web Service",
   "analytic_id": "AN1511",
   "detection_strategy_id": "DET0548",
   "analytic_name": "Analytic 1511",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "MonitoredServices | ExfilVolumeThreshold | TimeWindow",
   "detection_logic_en": "Processes that normally do not initiate network communications suddenly making outbound HTTPS connections with high outbound-to-inbound data ratios. Defender view: correlation between process creation logs (e.g., Word, Excel, PowerShell) and subsequent anomalous network traffic volumes toward common web services (Dropbox, Google Drive, OneDrive)."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567",
   "technique_ja": "Webサービス経由の持ち出し",
   "technique_en": "Exfiltration Over Web Service",
   "analytic_id": "AN1512",
   "detection_strategy_id": "DET0548",
   "analytic_name": "Analytic 1512",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:EXECVE) | File Access (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (auditd:EXECVE) | ファイルアクセス (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "MonitoredTools | DataVolumeThreshold",
   "detection_logic_en": "Processes (tar, curl, python scripts) accessing large file sets and initiating outbound HTTPS POST requests with payload sizes inconsistent with baseline activity. Defender perspective: detect abnormal sequence of file archival followed by encrypted uploads to external web services."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567",
   "technique_ja": "Webサービス経由の持ち出し",
   "technique_en": "Exfiltration Over Web Service",
   "analytic_id": "AN1513",
   "detection_strategy_id": "DET0548",
   "analytic_name": "Analytic 1513",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Access (macos:unifiedlog) | Network Traffic Content (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイルアクセス (macos:unifiedlog) | ネットワークトラフィック内容 (macos:unifiedlog)",
   "tuning": "WatchedApplications",
   "detection_logic_en": "Office apps or scripts writing files followed by xattr manipulation (to evade quarantine) and subsequent HTTPS uploads. Defender perspective: anomalous file modification + outbound TLS traffic originating from non-networking apps (Word, Excel, Preview)."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567",
   "technique_ja": "Webサービス経由の持ち出し",
   "technique_en": "Exfiltration Over Web Service",
   "analytic_id": "AN1514",
   "detection_strategy_id": "DET0548",
   "analytic_name": "Analytic 1514",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (m365:unified) | Network Traffic Content (saas:box)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | ネットワークトラフィック内容 (saas:box)",
   "tuning": "APICallThreshold | UserBaselineProfiles",
   "detection_logic_en": "Abnormal API calls from user accounts invoking file upload endpoints outside normal baselines (M365, Google Drive, Box). Defender perspective: monitor unified audit logs for elevated frequency of Upload, Create, or Copy operations from compromised accounts."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567",
   "technique_ja": "Webサービス経由の持ち出し",
   "technique_en": "Exfiltration Over Web Service",
   "analytic_id": "AN1515",
   "detection_strategy_id": "DET0548",
   "analytic_name": "Analytic 1515",
   "platforms": "ESXi",
   "log_sources": "Network Connection Creation (esxi:vmkernel) | File Access (esxi:hostd)",
   "log_sources_ja": "ネットワーク接続確立 (esxi:vmkernel) | ファイルアクセス (esxi:hostd)",
   "tuning": "DatastoreTransferThreshold",
   "detection_logic_en": "ESXi guest OS or management interface processes establishing unexpected external HTTPS connections. Defender perspective: monitor vmx or hostd processes making outbound web requests with significant data transfer."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567.001",
   "technique_ja": "コードリポジトリへの持ち出し",
   "technique_en": "Exfiltration to Code Repository",
   "analytic_id": "AN0895",
   "detection_strategy_id": "DET0318",
   "analytic_name": "Analytic 0895",
   "platforms": "Windows",
   "log_sources": "File Access (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイルアクセス (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "MonitoredDomains | ExfilVolumeThreshold",
   "detection_logic_en": "Processes such as PowerShell, Git, or curl initiating outbound HTTPS POST requests to known code repository APIs (e.g., github.com, gitlab.com) immediately following large file reads. Defender view: correlation between file access of sensitive directories (e.g., Documents, Finance) and abnormal data uploads to repository domains."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567.001",
   "technique_ja": "コードリポジトリへの持ち出し",
   "technique_en": "Exfiltration to Code Repository",
   "analytic_id": "AN0896",
   "detection_strategy_id": "DET0318",
   "analytic_name": "Analytic 0896",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:EXECVE) | File Access (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (auditd:EXECVE) | ファイルアクセス (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "WorkHours | RepoDomainList",
   "detection_logic_en": "Processes like git, curl, or python scripts executing commands that package files (tar, gzip) followed by HTTPS uploads to code repository endpoints. Defender view: detect unusual git push activity or scripted HTTPS requests outside normal developer work hours."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567.001",
   "technique_ja": "コードリポジトリへの持ち出し",
   "technique_en": "Exfiltration to Code Repository",
   "analytic_id": "AN0897",
   "detection_strategy_id": "DET0318",
   "analytic_name": "Analytic 0897",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Access (macos:unifiedlog) | Network Traffic Content (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイルアクセス (macos:unifiedlog) | ネットワークトラフィック内容 (macos:unifiedlog)",
   "tuning": "MonitoredApplications",
   "detection_logic_en": "Office or scripting applications initiating unusual HTTPS traffic to code repository APIs with high outbound-to-inbound ratios. Defender perspective: monitor for sensitive file access in combination with network connections to github.com, gitlab.com, or bitbucket.org."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567.001",
   "technique_ja": "コードリポジトリへの持ち出し",
   "technique_en": "Exfiltration to Code Repository",
   "analytic_id": "AN0898",
   "detection_strategy_id": "DET0318",
   "analytic_name": "Analytic 0898",
   "platforms": "ESXi",
   "log_sources": "File Access (esxi:hostd) | Network Traffic Flow (esxi:vmkernel)",
   "log_sources_ja": "ファイルアクセス (esxi:hostd) | ネットワークトラフィックフロー (esxi:vmkernel)",
   "tuning": "DatastoreTransferThreshold",
   "detection_logic_en": "ESXi host processes (vmx, hostd) initiating HTTPS sessions toward external code repositories. Defender perspective: detect datastore reads followed by outbound web traffic inconsistent with administrative baselines."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567.002",
   "technique_ja": "クラウドストレージへの持ち出し",
   "technique_en": "Exfiltration to Cloud Storage",
   "analytic_id": "AN1571",
   "detection_strategy_id": "DET0570",
   "analytic_name": "Analytic 1571",
   "platforms": "Windows",
   "log_sources": "File Access (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイルアクセス (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "CloudStorageDomains | ExfilVolumeThreshold | UserContext",
   "detection_logic_en": "Unusual processes (e.g., powershell.exe, excel.exe) accessing large local files and subsequently initiating HTTPS POST requests to domains associated with cloud storage services (e.g., dropbox.com, drive.google.com, box.com). Defender perspective: correlation between file reads in sensitive directories and high outbound traffic volume to known storage APIs."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567.002",
   "technique_ja": "クラウドストレージへの持ち出し",
   "technique_en": "Exfiltration to Cloud Storage",
   "analytic_id": "AN1572",
   "detection_strategy_id": "DET0570",
   "analytic_name": "Analytic 1572",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:EXECVE) | File Access (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (auditd:EXECVE) | ファイルアクセス (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "AllowedTools | WorkHours",
   "detection_logic_en": "Processes such as curl, wget, rclone, or custom scripts executing uploads to cloud storage endpoints. Defender perspective: detect chained events where tar/gzip is executed to compress files followed by HTTPS PUT/POST requests to known storage services."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567.002",
   "technique_ja": "クラウドストレージへの持ち出し",
   "technique_en": "Exfiltration to Cloud Storage",
   "analytic_id": "AN1573",
   "detection_strategy_id": "DET0570",
   "analytic_name": "Analytic 1573",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Access (macos:unifiedlog) | Network Traffic Content (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイルアクセス (macos:unifiedlog) | ネットワークトラフィック内容 (macos:unifiedlog)",
   "tuning": "WatchedApps | EntropyThreshold",
   "detection_logic_en": "Applications or scripts invoking cloud storage APIs (Dropbox sync, iCloud, Google Drive client) in unexpected contexts. Defender perspective: detect sensitive file reads by non-standard applications followed by unusual encrypted uploads to external cloud storage domains."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567.002",
   "technique_ja": "クラウドストレージへの持ち出し",
   "technique_en": "Exfiltration to Cloud Storage",
   "analytic_id": "AN1574",
   "detection_strategy_id": "DET0570",
   "analytic_name": "Analytic 1574",
   "platforms": "ESXi",
   "log_sources": "File Access (esxi:hostd) | Network Traffic Flow (esxi:vmkernel)",
   "log_sources_ja": "ファイルアクセス (esxi:hostd) | ネットワークトラフィックフロー (esxi:vmkernel)",
   "tuning": "DatastoreTransferThreshold | ApprovedStorageServices",
   "detection_logic_en": "Unusual ESXi processes (vmx, hostd) reading datastore files and generating outbound HTTPS traffic toward external cloud storage endpoints. Defender perspective: anomalous datastore activity followed by network transfers to Dropbox, AWS S3, or other storage services."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567.003",
   "technique_ja": "テキスト保存サイトへの持ち出し",
   "technique_en": "Exfiltration to Text Storage Sites",
   "analytic_id": "AN0787",
   "detection_strategy_id": "DET0284",
   "analytic_name": "Analytic 0787",
   "platforms": "Windows",
   "log_sources": "File Access (WinEventLog:Security) | Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイルアクセス (WinEventLog:Security) | ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TextStorageDomains | UploadSizeThreshold | UserContext",
   "detection_logic_en": "Unexpected processes (e.g., powershell.exe, wscript.exe, office apps) initiating HTTP POST/PUT requests to text storage domains like pastebin.com or hastebin.com, particularly when preceded by file access in sensitive directories. Defender perspective: correlation of process lineage, large clipboard/file read operations, and outbound uploads to text storage services."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567.003",
   "technique_ja": "テキスト保存サイトへの持ち出し",
   "technique_en": "Exfiltration to Text Storage Sites",
   "analytic_id": "AN0788",
   "detection_strategy_id": "DET0284",
   "analytic_name": "Analytic 0788",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:EXECVE) | File Access (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (auditd:EXECVE) | ファイルアクセス (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "AllowedTools | WorkHours",
   "detection_logic_en": "Use of curl, wget, or custom scripts to POST data to pastebin-like services. Defender perspective: identify chained behavior where files are compressed/read followed by HTTPS POST requests to text-sharing endpoints."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567.003",
   "technique_ja": "テキスト保存サイトへの持ち出し",
   "technique_en": "Exfiltration to Text Storage Sites",
   "analytic_id": "AN0789",
   "detection_strategy_id": "DET0284",
   "analytic_name": "Analytic 0789",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Access (macos:unifiedlog) | Network Traffic Flow (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイルアクセス (macos:unifiedlog) | ネットワークトラフィックフロー (macos:unifiedlog)",
   "tuning": "WatchedApps | EntropyThreshold",
   "detection_logic_en": "Processes such as osascript, curl, or office applications sending data to text storage APIs/domains. Defender perspective: anomalous clipboard or file reads by unexpected applications immediately followed by outbound HTTPS requests to pastebin-like services."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567.003",
   "technique_ja": "テキスト保存サイトへの持ち出し",
   "technique_en": "Exfiltration to Text Storage Sites",
   "analytic_id": "AN0790",
   "detection_strategy_id": "DET0284",
   "analytic_name": "Analytic 0790",
   "platforms": "ESXi",
   "log_sources": "File Access (esxi:hostd) | Network Traffic Content (esxi:vmkernel)",
   "log_sources_ja": "ファイルアクセス (esxi:hostd) | ネットワークトラフィック内容 (esxi:vmkernel)",
   "tuning": "DatastoreExfilThreshold | ApprovedDestinations",
   "detection_logic_en": "ESXi services (vmx, hostd) generating outbound HTTPS POST requests to text storage sites. Defender perspective: anomalous datastore or log reads chained with traffic to pastebin-like destinations."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567.004",
   "technique_ja": "Webhook経由の持ち出し",
   "technique_en": "Exfiltration Over Webhook",
   "analytic_id": "AN0436",
   "detection_strategy_id": "DET0153",
   "analytic_name": "Analytic 0436",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | File Access (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Security)",
   "tuning": "WebhookDomains | UploadSizeThreshold | ApprovedApps",
   "detection_logic_en": "Unusual processes (e.g., powershell.exe, wscript.exe, mshta.exe) posting data to webhook endpoints (Discord, Slack, webhook.site) using HTTP POST/PUT requests. Defender perspective: suspicious process lineage followed by outbound HTTPS traffic to webhook domains."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567.004",
   "technique_ja": "Webhook経由の持ち出し",
   "technique_en": "Exfiltration Over Webhook",
   "analytic_id": "AN0437",
   "detection_strategy_id": "DET0153",
   "analytic_name": "Analytic 0437",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:EXECVE) | File Access (auditd:SYSCALL) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "コマンド実行 (auditd:EXECVE) | ファイルアクセス (auditd:SYSCALL) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "AllowedTools | TimeWindow",
   "detection_logic_en": "Processes such as curl, wget, or custom scripts initiating POST requests to webhook endpoints with encoded or bulk data. Defender perspective: abnormal chaining of file compression or access followed by outbound data to webhook URLs."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567.004",
   "technique_ja": "Webhook経由の持ち出し",
   "technique_en": "Exfiltration Over Webhook",
   "analytic_id": "AN0438",
   "detection_strategy_id": "DET0153",
   "analytic_name": "Analytic 0438",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Access (macos:unifiedlog) | Network Traffic Flow (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイルアクセス (macos:unifiedlog) | ネットワークトラフィックフロー (macos:unifiedlog)",
   "tuning": "WebhookEndpoints | EntropyThreshold",
   "detection_logic_en": "Unexpected apps or scripts (osascript, curl, Automator workflows) exfiltrating data via webhooks. Defender perspective: correlation of clipboard/file read operations followed by HTTPS POST traffic to webhook services."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567.004",
   "technique_ja": "Webhook経由の持ち出し",
   "technique_en": "Exfiltration Over Webhook",
   "analytic_id": "AN0439",
   "detection_strategy_id": "DET0153",
   "analytic_name": "Analytic 0439",
   "platforms": "ESXi",
   "log_sources": "File Access (esxi:hostd) | Network Traffic Content (esxi:vmkernel)",
   "log_sources_ja": "ファイルアクセス (esxi:hostd) | ネットワークトラフィック内容 (esxi:vmkernel)",
   "tuning": "DatastoreExfilThreshold | ApprovedIntegrations",
   "detection_logic_en": "VMware services or management daemons generating HTTP POST requests to webhook endpoints, chained with unusual datastore or log access. Defender perspective: exfiltration from VM logs or disk images over webhook URLs."
  },
  {
   "tactic_id": "TA0010",
   "tactic_ja": "持ち出し",
   "technique_id": "T1567.004",
   "technique_ja": "Webhook経由の持ち出し",
   "technique_en": "Exfiltration Over Webhook",
   "analytic_id": "AN0440",
   "detection_strategy_id": "DET0153",
   "analytic_name": "Analytic 0440",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (m365:unified) | Network Traffic Flow (saas:api)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | ネットワークトラフィックフロー (saas:api)",
   "tuning": "WebhookRegistrations | ExternalDomains",
   "detection_logic_en": "Suspicious SaaS tenant activity involving webhook configurations pointing to external or untrusted domains. Defender perspective: repeated automated exports or suspicious webhook endpoint registrations."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1485",
   "technique_ja": "データ破壊",
   "technique_en": "Data Destruction",
   "analytic_id": "AN0411",
   "detection_strategy_id": "DET0146",
   "analytic_name": "Analytic 0411",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | File Deletion (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ファイル削除 (WinEventLog:Sysmon)",
   "tuning": "TargetFilename | ProcessCommandLine | VolumeThreshold | TimeWindow",
   "detection_logic_en": "Adversary spawns command-line tools (e.g., del, cipher /w, SDelete) or scripts to recursively delete or overwrite user/system files. This may be correlated with abnormal file IO activity, registry writes, or tampering in critical system directories."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1485",
   "technique_ja": "データ破壊",
   "technique_en": "Data Destruction",
   "analytic_id": "AN0412",
   "detection_strategy_id": "DET0146",
   "analytic_name": "Analytic 0412",
   "platforms": "Linux",
   "log_sources": "File Deletion (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイル削除 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "ExecutablePath | DeletedPathPattern | SyscallBurstRate",
   "detection_logic_en": "Massive recursive deletions or overwrites via `rm -rf`, `shred`, `dd`, or wiper binaries. May include unlink syscalls, deletion of known config/data paths, or sequential overwrite patterns."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1485",
   "technique_ja": "データ破壊",
   "technique_en": "Data Destruction",
   "analytic_id": "AN0413",
   "detection_strategy_id": "DET0146",
   "analytic_name": "Analytic 0413",
   "platforms": "macOS",
   "log_sources": "File Deletion (macos:unifiedlog) | Process Termination (macos:unifiedlog)",
   "log_sources_ja": "ファイル削除 (macos:unifiedlog) | プロセス終了 (macos:unifiedlog)",
   "tuning": "CommandPattern | EntropyChangeRate",
   "detection_logic_en": "Destruction via `rm -rf`, overwrite with `dd` or `srm`, often executed by script in /tmp or /private/tmp, may also involve file overwrite to political or decoy image data."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1485",
   "technique_ja": "データ破壊",
   "technique_en": "Data Destruction",
   "analytic_id": "AN0414",
   "detection_strategy_id": "DET0146",
   "analytic_name": "Analytic 0414",
   "platforms": "IaaS",
   "log_sources": "Cloud Storage Deletion (AWS:CloudTrail)",
   "log_sources_ja": "クラウドストレージ削除 (AWS:CloudTrail)",
   "tuning": "OperationType | UserAgent | RegionScope",
   "detection_logic_en": "Adversary deletes critical infrastructure: EC2 instances, S3 buckets, snapshots, or volumes using elevated IAM credentials. Frequently includes batch API calls with `Delete*` or `TerminateInstances`."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1485",
   "technique_ja": "データ破壊",
   "technique_en": "Data Destruction",
   "analytic_id": "AN0415",
   "detection_strategy_id": "DET0146",
   "analytic_name": "Analytic 0415",
   "platforms": "ESXi",
   "log_sources": "Volume Deletion (esxi:vmkernel)",
   "log_sources_ja": "ボリューム削除 (esxi:vmkernel)",
   "tuning": "DatastorePath | InitiatingUser",
   "detection_logic_en": "Adversary destroys virtual disks (VMDK), images, or VMs by invoking `vim-cmd`, deleting datastore contents, or purging snapshots."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1485",
   "technique_ja": "データ破壊",
   "technique_en": "Data Destruction",
   "analytic_id": "AN0416",
   "detection_strategy_id": "DET0146",
   "analytic_name": "Analytic 0416",
   "platforms": "Containers",
   "log_sources": "File Deletion (auditd:SYSCALL) | Command Execution (docker:events)",
   "log_sources_ja": "ファイル削除 (auditd:SYSCALL) | コマンド実行 (docker:events)",
   "tuning": "MountPoint | ContainerImage",
   "detection_logic_en": "Container process executes destructive file operations inside volume mounts or host paths. Includes `rm -rf /mnt/volumes/`, container breakout followed by host deletion attempts."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1485.001",
   "technique_ja": "ライフサイクルトリガー削除",
   "technique_en": "Lifecycle-Triggered Deletion",
   "analytic_id": "AN0117",
   "detection_strategy_id": "DET0041",
   "analytic_name": "Analytic 0117",
   "platforms": "IaaS",
   "log_sources": "Cloud Storage Modification (AWS:CloudTrail)",
   "log_sources_ja": "クラウドストレージ変更 (AWS:CloudTrail)",
   "tuning": "LifecycleExpirationDays | TargetBucket | Principal | TimeWindow",
   "detection_logic_en": "Adversary with write access to storage modifies lifecycle policies (e.g., via PutBucketLifecycle) to schedule rapid object deletion across one or more storage buckets. This is often used to trigger impact (destruction), remove logs (defense evasion), or force extortion (ransomware)."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1486",
   "technique_ja": "影響目的のデータ暗号化",
   "technique_en": "Data Encrypted for Impact",
   "analytic_id": "AN0602",
   "detection_strategy_id": "DET0215",
   "analytic_name": "Analytic 0602",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Creation (WinEventLog:Sysmon) | File Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル作成 (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Sysmon)",
   "tuning": "FileExtension | TargetFolder | TimeWindow | CommandLine",
   "detection_logic_en": "High-frequency file write operations using uncommon extensions, followed by ransom note creation, registry tampering, or shadow copy deletion. Often uses CLI tools like vssadmin, wbadmin, cipher, or PowerShell."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1486",
   "technique_ja": "影響目的のデータ暗号化",
   "technique_en": "Data Encrypted for Impact",
   "analytic_id": "AN0603",
   "detection_strategy_id": "DET0215",
   "analytic_name": "Analytic 0603",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "FilenamePattern | SyscallBurstRate | DirectoryTargeted",
   "detection_logic_en": "Encryption via custom or open-source tools (e.g., openssl, gpg, aescrypt) recursively targeting user or system directories. Also includes overwrite of existing data and ransom note drops."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1486",
   "technique_ja": "影響目的のデータ暗号化",
   "technique_en": "Data Encrypted for Impact",
   "analytic_id": "AN0604",
   "detection_strategy_id": "DET0215",
   "analytic_name": "Analytic 0604",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "ExtensionPattern | VolumeTargeted",
   "detection_logic_en": "Userland or kernel-level ransomware encrypting user files (Documents, Desktop) using `srm`, `gpg`, or compiled payloads. Often correlated with ransom note creation in multiple directories."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1486",
   "technique_ja": "影響目的のデータ暗号化",
   "technique_en": "Data Encrypted for Impact",
   "analytic_id": "AN0605",
   "detection_strategy_id": "DET0215",
   "analytic_name": "Analytic 0605",
   "platforms": "ESXi",
   "log_sources": "File Modification (esxi:vmkernel) | Command Execution (esxi:shell)",
   "log_sources_ja": "ファイル変更 (esxi:vmkernel) | コマンド実行 (esxi:shell)",
   "tuning": "FileType | UserContext",
   "detection_logic_en": "Ransomware encrypts .vmdk, .vmx, .log, or VM config files in VMFS datastores. May rename to .locked or delete/overwrite with encrypted versions. Often correlates with shell commands run through `dcui`, SSH, or vSphere."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1486",
   "technique_ja": "影響目的のデータ暗号化",
   "technique_en": "Data Encrypted for Impact",
   "analytic_id": "AN0606",
   "detection_strategy_id": "DET0215",
   "analytic_name": "Analytic 0606",
   "platforms": "IaaS",
   "log_sources": "Cloud Storage Modification (AWS:CloudTrail)",
   "log_sources_ja": "クラウドストレージ変更 (AWS:CloudTrail)",
   "tuning": "SSEHeader | AffectedBucket | UserAgent",
   "detection_logic_en": "Encryption of cloud storage objects (e.g., S3 buckets) via Server-Side Encryption (SSE-C) or by replacing objects with encrypted variants. May include API patterns like PutObject with SSE-C headers."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1489",
   "technique_ja": "サービス停止",
   "technique_en": "Service Stop",
   "analytic_id": "AN0061",
   "detection_strategy_id": "DET0021",
   "analytic_name": "Analytic 0061",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Logon Session Metadata (WinEventLog:Security) | Service Creation (WinEventLog:System) | Service Metadata (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ログオンセッションメタデータ (WinEventLog:Security) | サービス作成 (WinEventLog:System) | サービスメタデータ (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | ServiceName | ParentProcess",
   "detection_logic_en": "Adversary disables or stops critical services (e.g., Exchange, SQL, AV, endpoint monitoring) using native utilities or API calls, often preceding destructive actions (T1485, T1486). Behavioral chain: Elevated execution context + stop-service or sc.exe or ChangeServiceConfigW + terminated or disabled service + possible follow-up file manipulation."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1489",
   "technique_ja": "サービス停止",
   "technique_en": "Service Stop",
   "analytic_id": "AN0062",
   "detection_strategy_id": "DET0021",
   "analytic_name": "Analytic 0062",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | File Deletion (auditd:SYSCALL) | Service Metadata (linux:syslog)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ファイル削除 (auditd:SYSCALL) | サービスメタデータ (linux:syslog)",
   "tuning": "TimeWindow | ExecUser",
   "detection_logic_en": "Adversary executes systemctl or service stop targeting high-value services (e.g., mysql, sshd), possibly followed by rm or shred against data stores. Behavioral chain: sudo/su usage + stop command + /var/log/messages or syslog entries + file access/delete."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1489",
   "technique_ja": "サービス停止",
   "technique_en": "Service Stop",
   "analytic_id": "AN0063",
   "detection_strategy_id": "DET0021",
   "analytic_name": "Analytic 0063",
   "platforms": "macOS",
   "log_sources": "Service Metadata (macos:unifiedlog) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "サービスメタデータ (macos:unifiedlog) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "ServiceLabel | LaunchType",
   "detection_logic_en": "Use of launchctl to stop services or kill critical background processes (e.g., securityd, com.apple.*), typically followed by command-line tools like rm or diskutil. Behavioral chain: Terminal or remote shell + launchctl bootout/disable + process termination + follow-on modification."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1489",
   "technique_ja": "サービス停止",
   "technique_en": "Service Stop",
   "analytic_id": "AN0064",
   "detection_strategy_id": "DET0021",
   "analytic_name": "Analytic 0064",
   "platforms": "ESXi",
   "log_sources": "Service Metadata (esxi:hostd) | Process Termination (esxi:hostd)",
   "log_sources_ja": "サービスメタデータ (esxi:hostd) | プロセス終了 (esxi:hostd)",
   "tuning": "VMName | InitiatorUser",
   "detection_logic_en": "Attacker disables VM-related services or stops VMs forcibly to target vmdk or logs. Behavioral chain: esxcli or vim-cmd stop + audit log showing user privilege use + datastore file manipulation."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1490",
   "technique_ja": "システム復旧の阻害",
   "technique_en": "Inhibit System Recovery",
   "analytic_id": "AN0933",
   "detection_strategy_id": "DET0329",
   "analytic_name": "Analytic 0933",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | File Deletion (WinEventLog:Microsoft-Windows-Backup) | Service Metadata (WinEventLog:System) | Windows Registry Key Modification (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ファイル削除 (WinEventLog:Microsoft-Windows-Backup) | サービスメタデータ (WinEventLog:System) | Windowsレジストリキー変更 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | CommandLinePattern | ParentProcessContext",
   "detection_logic_en": "Process chains that use native utilities (vssadmin, wbadmin, diskshadow, bcdedit, REAgentC, wmic) with arguments to delete shadow copies, disable recovery, or remove backup catalogs"
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1490",
   "technique_ja": "システム復旧の阻害",
   "technique_en": "Inhibit System Recovery",
   "analytic_id": "AN0934",
   "detection_strategy_id": "DET0329",
   "analytic_name": "Analytic 0934",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | File Deletion (auditd:CONFIG_CHANGE)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ファイル削除 (auditd:CONFIG_CHANGE)",
   "tuning": "WatchedFilePaths | ShellProcessUser",
   "detection_logic_en": "Shell utilities or scripts deleting `/etc/systemd/system/rescue.target`, `/etc/fstab` backups, or `/boot/efi` partitions; chattr used to block snapshot auto-recovery"
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1490",
   "technique_ja": "システム復旧の阻害",
   "technique_en": "Inhibit System Recovery",
   "analytic_id": "AN0935",
   "detection_strategy_id": "DET0329",
   "analytic_name": "Analytic 0935",
   "platforms": "ESXi",
   "log_sources": "Snapshot Deletion (esxi:hostd)",
   "log_sources_ja": "スナップショット削除 (esxi:hostd)",
   "tuning": "TargetVMNames",
   "detection_logic_en": "ESXi shell or vim-cmd execution that deletes all VM snapshots using vmsvc/snapshot.removeall or rm on snapshot paths"
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1490",
   "technique_ja": "システム復旧の阻害",
   "technique_en": "Inhibit System Recovery",
   "analytic_id": "AN0936",
   "detection_strategy_id": "DET0329",
   "analytic_name": "Analytic 0936",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:syslog)",
   "log_sources_ja": "コマンド実行 (networkdevice:syslog)",
   "tuning": "CommandSequenceWindow | UserPrivilegeLevel",
   "detection_logic_en": "Execution of `erase`, `format`, and `reload` in immediate sequence from a privileged AAA session"
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1490",
   "technique_ja": "システム復旧の阻害",
   "technique_en": "Inhibit System Recovery",
   "analytic_id": "AN0937",
   "detection_strategy_id": "DET0329",
   "analytic_name": "Analytic 0937",
   "platforms": "IaaS",
   "log_sources": "Snapshot Deletion (AWS:CloudTrail) | Cloud Storage Deletion (AWS:CloudTrail)",
   "log_sources_ja": "スナップショット削除 (AWS:CloudTrail) | クラウドストレージ削除 (AWS:CloudTrail)",
   "tuning": "UserAgent | ResourceType",
   "detection_logic_en": "Cloud API calls disabling snapshot scheduling, backup policies, versioning, followed by DeleteSnapshot/DeleteVolume operations"
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1491",
   "technique_ja": "改ざん（デフェイスメント）",
   "technique_en": "Defacement",
   "analytic_id": "AN0662",
   "detection_strategy_id": "DET0238",
   "analytic_name": "Analytic 0662",
   "platforms": "Windows",
   "log_sources": "File Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon) | Application Log Content (WinEventLog:Application)",
   "log_sources_ja": "ファイル変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon) | アプリケーションログ内容 (WinEventLog:Application)",
   "tuning": "target_filenames | TimeWindow",
   "detection_logic_en": "Adversary modifies website or application-hosted content via unauthorized file changes or script injections, often by exploiting web servers or CMS access."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1491",
   "technique_ja": "改ざん（デフェイスメント）",
   "technique_en": "Defacement",
   "analytic_id": "AN0663",
   "detection_strategy_id": "DET0238",
   "analytic_name": "Analytic 0663",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Network Traffic Content (apache:access_log) | Process Creation (linux:syslog)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | ネットワークトラフィック内容 (apache:access_log) | プロセス生成 (linux:syslog)",
   "tuning": "UploadPathRegex | FileExtensionScope",
   "detection_logic_en": "Adversary gains shell access or uploads a malicious script to deface hosted web content in Nginx, Apache, or other services."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1491",
   "technique_ja": "改ざん（デフェイスメント）",
   "technique_en": "Defacement",
   "analytic_id": "AN0664",
   "detection_strategy_id": "DET0238",
   "analytic_name": "Analytic 0664",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | File Modification (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファイル変更 (macos:unifiedlog)",
   "tuning": "TargetDirectoryPath",
   "detection_logic_en": "Adversary modifies internal or external site content through manipulated application bundles, hosted content, or web server configs."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1491",
   "technique_ja": "改ざん（デフェイスメント）",
   "technique_en": "Defacement",
   "analytic_id": "AN0665",
   "detection_strategy_id": "DET0238",
   "analytic_name": "Analytic 0665",
   "platforms": "ESXi",
   "log_sources": "File Modification (esxi:vmkernel)",
   "log_sources_ja": "ファイル変更 (esxi:vmkernel)",
   "tuning": "DatastoreVolumeName",
   "detection_logic_en": "Adversary defaces internal VM-hosted portals or web UIs by modifying static content on datastore-mounted paths."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1491",
   "technique_ja": "改ざん（デフェイスメント）",
   "technique_en": "Defacement",
   "analytic_id": "AN0666",
   "detection_strategy_id": "DET0238",
   "analytic_name": "Analytic 0666",
   "platforms": "IaaS",
   "log_sources": "File Creation (CloudTrail:PutObject) | Cloud Storage Access (AWS:CloudTrail)",
   "log_sources_ja": "ファイル作成 (CloudTrail:PutObject) | クラウドストレージアクセス (AWS:CloudTrail)",
   "tuning": "BucketNameRegex | IAMRoleContext",
   "detection_logic_en": "Adversary uses compromised instance credentials or web application access to deface content hosted in S3 buckets, Azure Blob Storage, or GCP Buckets."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1491.001",
   "technique_ja": "内部デフェイスメント",
   "technique_en": "Internal Defacement",
   "analytic_id": "AN0229",
   "detection_strategy_id": "DET0082",
   "analytic_name": "Analytic 0229",
   "platforms": "Windows",
   "log_sources": "File Access (WinEventLog:Security) | File Creation (WinEventLog:Sysmon) | File Modification (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイルアクセス (WinEventLog:Security) | ファイル作成 (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "FilePathPattern | TimeWindow | UserContext",
   "detection_logic_en": "Adversary modifies internal UI messages (e.g., login banners, desktop wallpapers) or hosted intranet web pages by creating or altering content files using scripts or unauthorized access. Often preceded by privilege escalation or web shell deployment."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1491.001",
   "technique_ja": "内部デフェイスメント",
   "technique_en": "Internal Defacement",
   "analytic_id": "AN0230",
   "detection_strategy_id": "DET0082",
   "analytic_name": "Analytic 0230",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL) | User Account Modification (linux:syslog)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL) | ユーザーアカウント変更 (linux:syslog)",
   "tuning": "TargetDirectories | UserContext | TimeWindow",
   "detection_logic_en": "Adversary leverages root or sudo access to alter system banners, web content directories (e.g., /var/www/html), or login configurations (/etc/issue). File creation or overwrites may coincide with suspicious script execution or cron job activity."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1491.001",
   "technique_ja": "内部デフェイスメント",
   "technique_en": "Internal Defacement",
   "analytic_id": "AN0231",
   "detection_strategy_id": "DET0082",
   "analytic_name": "Analytic 0231",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | Script Execution (macos:unifiedlog)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | スクリプト実行 (macos:unifiedlog)",
   "tuning": "ScriptNames | UserContext",
   "detection_logic_en": "Modification of user desktop backgrounds, login screen messages, or system banners by adversaries using admin privileges or script execution. May coincide with tampering in /Library/Desktop Pictures/ or use of AppleScript."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1491.001",
   "technique_ja": "内部デフェイスメント",
   "technique_en": "Internal Defacement",
   "analytic_id": "AN0232",
   "detection_strategy_id": "DET0082",
   "analytic_name": "Analytic 0232",
   "platforms": "ESXi",
   "log_sources": "File Modification (ESXiLogs:messages) | Command Execution (esxi:hostd)",
   "log_sources_ja": "ファイル変更 (ESXiLogs:messages) | コマンド実行 (esxi:hostd)",
   "tuning": "LoginBannerFilePath | AccessOrigin",
   "detection_logic_en": "Adversary modifies ESXi host login banner or MOTD file (/etc/motd), either through SSH or host console access. May involve configuration file overwrite or API calls from compromised vSphere clients."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1491.002",
   "technique_ja": "外部デフェイスメント",
   "technique_en": "External Defacement",
   "analytic_id": "AN1622",
   "detection_strategy_id": "DET0590",
   "analytic_name": "Analytic 1622",
   "platforms": "Windows",
   "log_sources": "File Modification (WinEventLog:Security) | Network Traffic Content (NSM:Connections) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ファイル変更 (WinEventLog:Security) | ネットワークトラフィック内容 (NSM:Connections) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "target_directory | UserContext | TimeWindow",
   "detection_logic_en": "Adversary modifies externally-facing web content by accessing and overwriting hosted HTML/JS/CSS files, typically following web shell deployment, credential abuse, or exploitation of web application vulnerabilities."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1491.002",
   "technique_ja": "外部デフェイスメント",
   "technique_en": "External Defacement",
   "analytic_id": "AN1623",
   "detection_strategy_id": "DET0590",
   "analytic_name": "Analytic 1623",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Logon Session Metadata (NSM:Connections) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | ログオンセッションメタデータ (NSM:Connections) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "web_root | payload_hash | UserContext",
   "detection_logic_en": "Adversary compromises a Linux-based web server and modifies hosted web files by exploiting upload vulnerabilities, remote code execution, or replacing index.html via SSH/webshell."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1491.002",
   "technique_ja": "外部デフェイスメント",
   "technique_en": "External Defacement",
   "analytic_id": "AN1624",
   "detection_strategy_id": "DET0590",
   "analytic_name": "Analytic 1624",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | Logon Session Metadata (macos:unifiedlog)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | ログオンセッションメタデータ (macos:unifiedlog)",
   "tuning": "web_root_dir | editor_name",
   "detection_logic_en": "Adversary modifies web-facing content on macOS via web development environments like MAMP or misconfigured Apache instances, typically with access to the hosting user account or via persistence tools."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1491.002",
   "technique_ja": "外部デフェイスメント",
   "technique_en": "External Defacement",
   "analytic_id": "AN1625",
   "detection_strategy_id": "DET0590",
   "analytic_name": "Analytic 1625",
   "platforms": "IaaS",
   "log_sources": "File Creation (AWS:CloudTrail) | Cloud Storage Enumeration (AWS:CloudTrail) | Cloud Storage Access (AWS:CloudTrail)",
   "log_sources_ja": "ファイル作成 (AWS:CloudTrail) | クラウドストレージ列挙 (AWS:CloudTrail) | クラウドストレージアクセス (AWS:CloudTrail)",
   "tuning": "bucket_name | region | IAMRole",
   "detection_logic_en": "Adversary modifies content in cloud-hosted websites (e.g., AWS S3-backed, Azure Blob-hosted sites) by gaining access to management consoles or APIs and uploading altered HTML/JS files."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1495",
   "technique_ja": "ファームウェア破壊",
   "technique_en": "Firmware Corruption",
   "analytic_id": "AN0474",
   "detection_strategy_id": "DET0167",
   "analytic_name": "Analytic 0474",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Security) | Driver Load (WinEventLog:Sysmon) | Firmware Modification (WinEventLog:Microsoft-Windows-Kernel-Boot)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Security) | ドライバ読み込み (WinEventLog:Sysmon) | ファームウェア変更 (WinEventLog:Microsoft-Windows-Kernel-Boot)",
   "tuning": "ParentImage | CommandLine",
   "detection_logic_en": "Firmware flash utility invoked with elevated privileges followed by raw access to firmware device path or changes to boot configuration."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1495",
   "technique_ja": "ファームウェア破壊",
   "technique_en": "Firmware Corruption",
   "analytic_id": "AN0475",
   "detection_strategy_id": "DET0167",
   "analytic_name": "Analytic 0475",
   "platforms": "Linux",
   "log_sources": "Firmware Modification (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ファームウェア変更 (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "ToolName",
   "detection_logic_en": "Direct write access to /dev/mem or /sys/firmware combined with usage of firmware flashing utilities (e.g., flashrom)."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1495",
   "technique_ja": "ファームウェア破壊",
   "technique_en": "Firmware Corruption",
   "analytic_id": "AN0476",
   "detection_strategy_id": "DET0167",
   "analytic_name": "Analytic 0476",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Firmware Modification (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ファームウェア変更 (macos:unifiedlog)",
   "tuning": "UpdateTimeWindow",
   "detection_logic_en": "EFI updates executed via system processes or binaries outside of expected patch windows or using unsigned firmware packages."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1495",
   "technique_ja": "ファームウェア破壊",
   "technique_en": "Firmware Corruption",
   "analytic_id": "AN0477",
   "detection_strategy_id": "DET0167",
   "analytic_name": "Analytic 0477",
   "platforms": "Network Devices",
   "log_sources": "Network Traffic Content (NSM:Flow) | Firmware Modification (networkdevice:firmware)",
   "log_sources_ja": "ネットワークトラフィック内容 (NSM:Flow) | ファームウェア変更 (networkdevice:firmware)",
   "tuning": "UploadSizeThreshold | RebootWindow",
   "detection_logic_en": "Firmware image uploaded via TFTP/SCP or web interface followed by reboot or unexpected loss of connectivity."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1496",
   "technique_ja": "リソース乗っ取り",
   "technique_en": "Resource Hijacking",
   "analytic_id": "AN0741",
   "detection_strategy_id": "DET0267",
   "analytic_name": "Analytic 0741",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Host Status (Windows:perfmon) | Network Connection Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ホスト状態 (Windows:perfmon) | ネットワーク接続確立 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | DestinationIPList | ExecutableNamePatterns",
   "detection_logic_en": "Persistent high CPU utilization combined with suspicious command-line execution (e.g., mining tools or obfuscated scripts) and outbound connections to mining/proxy networks."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1496",
   "technique_ja": "リソース乗っ取り",
   "technique_en": "Resource Hijacking",
   "analytic_id": "AN0742",
   "detection_strategy_id": "DET0267",
   "analytic_name": "Analytic 0742",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Host Status (linux:procfs) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ホスト状態 (linux:procfs) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "ProcessPath | CPUThreshold | KnownMiningDomains",
   "detection_logic_en": "Abnormal CPU/memory usage by unauthorized processes with outbound connections to known mining pools or using cron jobs/scripts to maintain persistence."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1496",
   "technique_ja": "リソース乗っ取り",
   "technique_en": "Resource Hijacking",
   "analytic_id": "AN0743",
   "detection_strategy_id": "DET0267",
   "analytic_name": "Analytic 0743",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Content (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィック内容 (macos:unifiedlog)",
   "tuning": "launchdLabel | TrafficVolumeThreshold",
   "detection_logic_en": "Background launch agents/daemons with high CPU use and network access to external mining services."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1496",
   "technique_ja": "リソース乗っ取り",
   "technique_en": "Resource Hijacking",
   "analytic_id": "AN0744",
   "detection_strategy_id": "DET0267",
   "analytic_name": "Analytic 0744",
   "platforms": "IaaS",
   "log_sources": "Instance Start (AWS:CloudTrail) | Host Status (AWS:CloudWatch) | Network Traffic Flow (AWS:VPCFlowLogs)",
   "log_sources_ja": "インスタンス起動 (AWS:CloudTrail) | ホスト状態 (AWS:CloudWatch) | ネットワークトラフィックフロー (AWS:VPCFlowLogs)",
   "tuning": "CPUUtilizationThreshold | UnusualRegionList",
   "detection_logic_en": "Sudden spikes in cloud VM CPU usage with outbound traffic to mining pools and unauthorized instance creation."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1496",
   "technique_ja": "リソース乗っ取り",
   "technique_en": "Resource Hijacking",
   "analytic_id": "AN0745",
   "detection_strategy_id": "DET0267",
   "analytic_name": "Analytic 0745",
   "platforms": "Containers",
   "log_sources": "Process Creation (containerd:events) | Host Status (prometheus:metrics) | Network Traffic Flow (container:cni)",
   "log_sources_ja": "プロセス生成 (containerd:events) | ホスト状態 (prometheus:metrics) | ネットワークトラフィックフロー (container:cni)",
   "tuning": "ImageName | CPUQuotaThreshold",
   "detection_logic_en": "High CPU usage by unauthorized containers running mining binaries or public proxy tools."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1496",
   "technique_ja": "リソース乗っ取り",
   "technique_en": "Resource Hijacking",
   "analytic_id": "AN0746",
   "detection_strategy_id": "DET0267",
   "analytic_name": "Analytic 0746",
   "platforms": "SaaS",
   "log_sources": "Cloud Service Modification (m365:unified) | Application Log Content (saas:application)",
   "log_sources_ja": "クラウドサービス変更 (m365:unified) | アプリケーションログ内容 (saas:application)",
   "tuning": "MessageRateThreshold | APIKeyList",
   "detection_logic_en": "Abuse of cloud messaging platforms to send mass spam or consume quota-based resources."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1496.001",
   "technique_ja": "計算リソース乗っ取り",
   "technique_en": "Compute Hijacking",
   "analytic_id": "AN1489",
   "detection_strategy_id": "DET0540",
   "analytic_name": "Analytic 1489",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Network Connection Creation (WinEventLog:Sysmon) | Scheduled Job Creation (WinEventLog:Security)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ネットワーク接続確立 (WinEventLog:Sysmon) | スケジュールジョブ作成 (WinEventLog:Security)",
   "tuning": "Image | DestinationIP | ParentProcessName",
   "detection_logic_en": "Sustained execution of resource-intensive processes (e.g., cryptocurrency miners), often launched via scheduled tasks, WMI, or PowerShell. These processes frequently establish persistent external connections and attempt to evade detection using masqueraded or renamed binaries."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1496.001",
   "technique_ja": "計算リソース乗っ取り",
   "technique_en": "Compute Hijacking",
   "analytic_id": "AN1490",
   "detection_strategy_id": "DET0540",
   "analytic_name": "Analytic 1490",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow) | Scheduled Job Creation (linux:cron)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow) | スケジュールジョブ作成 (linux:cron)",
   "tuning": "CommandLine | CPUThreshold",
   "detection_logic_en": "Unusual long-running processes consuming high CPU cycles (e.g., via 'top' or 'ps') initiated via cron, shell scripts, or Docker. Connections to known mining pools or DNS over HTTPS usage as evasion."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1496.001",
   "technique_ja": "計算リソース乗っ取り",
   "technique_en": "Compute Hijacking",
   "analytic_id": "AN1491",
   "detection_strategy_id": "DET0540",
   "analytic_name": "Analytic 1491",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Content (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィック内容 (macos:unifiedlog)",
   "tuning": "launchd.plist_label | DestinationDomain",
   "detection_logic_en": "Persistent or background daemons (e.g., plist or launchd jobs) spawning high-CPU processes like xmrig or cpuminer. Outbound encrypted traffic to IPs/domains commonly used by mining proxies."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1496.001",
   "technique_ja": "計算リソース乗っ取り",
   "technique_en": "Compute Hijacking",
   "analytic_id": "AN1492",
   "detection_strategy_id": "DET0540",
   "analytic_name": "Analytic 1492",
   "platforms": "Containers",
   "log_sources": "Container Creation (containerd:events) | Process Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "コンテナ作成 (containerd:events) | プロセス生成 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "ImageSource | Namespace",
   "detection_logic_en": "Ephemeral or unauthorized container instantiation using public images (e.g., from DockerHub) that initiate high CPU usage shortly after startup. Often scheduled via Kubernetes or Docker socket abuse."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1496.001",
   "technique_ja": "計算リソース乗っ取り",
   "technique_en": "Compute Hijacking",
   "analytic_id": "AN1493",
   "detection_strategy_id": "DET0540",
   "analytic_name": "Analytic 1493",
   "platforms": "IaaS",
   "log_sources": "Instance Start (AWS:CloudTrail) | Host Status (AWS:CloudWatch)",
   "log_sources_ja": "インスタンス起動 (AWS:CloudTrail) | ホスト状態 (AWS:CloudWatch)",
   "tuning": "Region | TagKey",
   "detection_logic_en": "Unauthorized instance creation in unmonitored or unused regions. Burst of compute-intensive jobs in spot instances or sudden spike in resource usage in legitimate VMs."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1496.002",
   "technique_ja": "帯域乗っ取り",
   "technique_en": "Bandwidth Hijacking",
   "analytic_id": "AN0080",
   "detection_strategy_id": "DET0028",
   "analytic_name": "Analytic 0080",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | DestinationCountry | ProcessName",
   "detection_logic_en": "Processes invoking network-intensive child processes or uploading large data volumes, often from non-standard user or system contexts, with evidence of long-duration TCP/UDP sessions to unusual destinations."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1496.002",
   "technique_ja": "帯域乗っ取り",
   "technique_en": "Bandwidth Hijacking",
   "analytic_id": "AN0081",
   "detection_strategy_id": "DET0028",
   "analytic_name": "Analytic 0081",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "ToolPattern | TrafficRateThreshold",
   "detection_logic_en": "User-initiated processes generating sustained outbound traffic over common or non-standard ports, often outside business hours, potentially linked to scanning or proxyjacking. Includes curl, wget, masscan, or proxy clients."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1496.002",
   "technique_ja": "帯域乗っ取り",
   "technique_en": "Bandwidth Hijacking",
   "analytic_id": "AN0082",
   "detection_strategy_id": "DET0028",
   "analytic_name": "Analytic 0082",
   "platforms": "macOS",
   "log_sources": "Network Traffic Content (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "ネットワークトラフィック内容 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "ProcessSignedStatus | DataRateThreshold",
   "detection_logic_en": "Suspicious long-lived or high-throughput connections by non-Apple signed apps or processes not commonly associated with network uploads. Detect background processes using open sockets for data egress."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1496.002",
   "technique_ja": "帯域乗っ取り",
   "technique_en": "Bandwidth Hijacking",
   "analytic_id": "AN0083",
   "detection_strategy_id": "DET0028",
   "analytic_name": "Analytic 0083",
   "platforms": "Containers",
   "log_sources": "Process Creation (containers:osquery) | Network Traffic Content (docker:stats)",
   "log_sources_ja": "プロセス生成 (containers:osquery) | ネットワークトラフィック内容 (docker:stats)",
   "tuning": "ContainerBaselineNetworkUsage | ImageName",
   "detection_logic_en": "Containerized apps or sidecar containers generating excessive outbound traffic or being leveraged for proxy networks. Includes sudden increases in network interface stats, especially in dormant or low-util apps."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1496.002",
   "technique_ja": "帯域乗っ取り",
   "technique_en": "Bandwidth Hijacking",
   "analytic_id": "AN0084",
   "detection_strategy_id": "DET0028",
   "analytic_name": "Analytic 0084",
   "platforms": "IaaS",
   "log_sources": "Instance Start (AWS:CloudTrail) | Network Traffic Flow (AWS:VPCFlowLogs)",
   "log_sources_ja": "インスタンス起動 (AWS:CloudTrail) | ネットワークトラフィックフロー (AWS:VPCFlowLogs)",
   "tuning": "InstanceType | TrafficEgressThreshold",
   "detection_logic_en": "Virtual instances or workloads generating sustained outbound data rates, often to TOR, VPN, or proxy endpoints. Often coincides with unusual IAM usage or deployed scripts (e.g., cron jobs using proxy clients)."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1496.003",
   "technique_ja": "SMSポンピング",
   "technique_en": "SMS Pumping",
   "analytic_id": "AN0443",
   "detection_strategy_id": "DET0156",
   "analytic_name": "Analytic 0443",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (saas:application) | User Account Authentication (saas:audit)",
   "log_sources_ja": "アプリケーションログ内容 (saas:application) | ユーザーアカウント認証 (saas:audit)",
   "tuning": "TimeWindow | SMSFrequencyThreshold | DestinationCountryCodeFilter | UserAgentAnomalyThreshold | IPGeoVarianceScore",
   "detection_logic_en": "Automated and repetitive triggering of SMS messages through OTP/account verification fields on SaaS platforms, leveraging background messaging APIs such as Twilio, AWS SNS, or Amazon Cognito to generate traffic toward attacker-controlled numbers."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1496.004",
   "technique_ja": "クラウドサービス乗っ取り",
   "technique_en": "Cloud Service Hijacking",
   "analytic_id": "AN0417",
   "detection_strategy_id": "DET0147",
   "analytic_name": "Analytic 0417",
   "platforms": "SaaS",
   "log_sources": "Cloud Service Modification (AWS:CloudTrail) | Application Log Content (AWS:CloudTrail) | User Account Metadata (AWS:CloudTrail)",
   "log_sources_ja": "クラウドサービス変更 (AWS:CloudTrail) | アプリケーションログ内容 (AWS:CloudTrail) | ユーザーアカウントメタデータ (AWS:CloudTrail)",
   "tuning": "TimeWindow | UserContext | RequestVolumeThreshold | GeoVelocityThreshold | ModelUsageQuotaSpike",
   "detection_logic_en": "Adversary gains access to cloud-hosted services such as AWS SES, SNS, or OpenAI API, enables or modifies usage policies, and initiates resource-intensive actions (e.g., mass email/SMS or LLM queries), often from unauthorized regions or under anomalous identity conditions."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1498",
   "technique_ja": "ネットワークDoS",
   "technique_en": "Network Denial of Service",
   "analytic_id": "AN1434",
   "detection_strategy_id": "DET0518",
   "analytic_name": "Analytic 1434",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "ThresholdEventVolume | DestinationDiversity",
   "detection_logic_en": "Executable or script generating large outbound network traffic targeting remote hosts or known amplification ports"
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1498",
   "technique_ja": "ネットワークDoS",
   "technique_en": "Network Denial of Service",
   "analytic_id": "AN1435",
   "detection_strategy_id": "DET0518",
   "analytic_name": "Analytic 1435",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow)",
   "tuning": "PacketRateThreshold",
   "detection_logic_en": "Flooding tools like hping3 or nping sending large volumes of packets across multiple ports or IPs"
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1498.001",
   "technique_ja": "直接ネットワークフラッド",
   "technique_en": "Direct Network Flood",
   "analytic_id": "AN0969",
   "detection_strategy_id": "DET0343",
   "analytic_name": "Analytic 0969",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Process Creation (WinEventLog:Security)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | プロセス生成 (WinEventLog:Security)",
   "tuning": "PacketRateThreshold | TimeWindow",
   "detection_logic_en": "High-volume packet generation by local processes (e.g., PowerShell, cmd, curl.exe) or network service processes resulting in excessive outbound traffic over short time window, correlated with abnormal resource usage or degraded host responsiveness."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1498.001",
   "technique_ja": "直接ネットワークフラッド",
   "technique_en": "Direct Network Flood",
   "analytic_id": "AN0970",
   "detection_strategy_id": "DET0343",
   "analytic_name": "Analytic 0970",
   "platforms": "Linux",
   "log_sources": "Network Traffic Flow (auditd:SYSCALL) | Process Creation (auditd:SYSCALL)",
   "log_sources_ja": "ネットワークトラフィックフロー (auditd:SYSCALL) | プロセス生成 (auditd:SYSCALL)",
   "tuning": "SyscallBurstCount | UserContext",
   "detection_logic_en": "Kernel or userland processes generating high-rate network traffic (ICMP, UDP, TCP SYN) beyond expected interface throughput or user behavior norms."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1498.001",
   "technique_ja": "直接ネットワークフラッド",
   "technique_en": "Direct Network Flood",
   "analytic_id": "AN0971",
   "detection_strategy_id": "DET0343",
   "analytic_name": "Analytic 0971",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Flow (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィックフロー (macos:unifiedlog)",
   "tuning": "BurstTimeWindow",
   "detection_logic_en": "Excessive outbound traffic via `ping`, `curl`, or custom scripts indicating flooding behavior, especially with no UI context or user interaction."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1498.001",
   "technique_ja": "直接ネットワークフラッド",
   "technique_en": "Direct Network Flood",
   "analytic_id": "AN0972",
   "detection_strategy_id": "DET0343",
   "analytic_name": "Analytic 0972",
   "platforms": "IaaS",
   "log_sources": "Network Traffic Flow (AWS:VPCFlowLogs) | Host Status (AWS:CloudWatch)",
   "log_sources_ja": "ネットワークトラフィックフロー (AWS:VPCFlowLogs) | ホスト状態 (AWS:CloudWatch)",
   "tuning": "InstanceTrafficThreshold | ProtocolType",
   "detection_logic_en": "VM or cloud instance generating anomalously high network egress targeting same destination IP or service, especially using stateless protocols."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1498.002",
   "technique_ja": "リフレクション増幅",
   "technique_en": "Reflection Amplification",
   "analytic_id": "AN1140",
   "detection_strategy_id": "DET0408",
   "analytic_name": "Analytic 1140",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | Host Status (Windows:perfmon)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | ホスト状態 (Windows:perfmon)",
   "tuning": "TimeWindow | AmplificationProtocolPorts | PacketToByteRatio",
   "detection_logic_en": "Outbound spoofed traffic to known amplification protocols (e.g., DNS, NTP, Memcached) combined with abnormal network traffic volume targeting remote reflectors, resulting in disproportionate traffic returned to a victim"
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1498.002",
   "technique_ja": "リフレクション増幅",
   "technique_en": "Reflection Amplification",
   "analytic_id": "AN1141",
   "detection_strategy_id": "DET0408",
   "analytic_name": "Analytic 1141",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow) | Host Status (sar:network)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow) | ホスト状態 (sar:network)",
   "tuning": "TimeWindow | AmplificationProtocolList | ExecutionToolList",
   "detection_logic_en": "Spoofed outbound packets sent to amplification services from command-line tools or scripts, combined with abnormal outbound packet volume on known reflector ports"
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1498.002",
   "technique_ja": "リフレクション増幅",
   "technique_en": "Reflection Amplification",
   "analytic_id": "AN1142",
   "detection_strategy_id": "DET0408",
   "analytic_name": "Analytic 1142",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Network Traffic Flow (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ネットワークトラフィックフロー (macos:unifiedlog)",
   "tuning": "ReflectionPorts | TrafficSpikeThreshold",
   "detection_logic_en": "Command-line initiated UDP traffic bursts to external reflection amplification ports using built-in scripting or binaries with network anomalies"
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1498.002",
   "technique_ja": "リフレクション増幅",
   "technique_en": "Reflection Amplification",
   "analytic_id": "AN1143",
   "detection_strategy_id": "DET0408",
   "analytic_name": "Analytic 1143",
   "platforms": "IaaS",
   "log_sources": "Firewall Rule Modification (AWS:CloudTrail) | Network Traffic Flow (AWS:VPCFlowLogs) | Host Status (AWS:CloudWatch)",
   "log_sources_ja": "ファイアウォールルール変更 (AWS:CloudTrail) | ネットワークトラフィックフロー (AWS:VPCFlowLogs) | ホスト状態 (AWS:CloudWatch)",
   "tuning": "EgressRulePorts | OutboundToInboundRatio | VMInstanceTagContext",
   "detection_logic_en": "Cloud-hosted VM or container generates spoofed UDP requests to third-party services on known amplifier ports, with high outbound-to-inbound traffic ratios in VPC Flow Logs"
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499",
   "technique_ja": "エンドポイントDoS",
   "technique_en": "Endpoint Denial of Service",
   "analytic_id": "AN0584",
   "detection_strategy_id": "DET0208",
   "analytic_name": "Analytic 0584",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Application Log Content (WinEventLog:Application) | Host Status (WinEventLog:System)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | アプリケーションログ内容 (WinEventLog:Application) | ホスト状態 (WinEventLog:System)",
   "tuning": "TimeWindow | ServiceTarget | CPUThresholdPercent",
   "detection_logic_en": "Excessive resource exhaustion or service crash induced by processes launched by users or scripts that rapidly consume CPU/memory or attempt malformed service interactions."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499",
   "technique_ja": "エンドポイントDoS",
   "technique_en": "Endpoint Denial of Service",
   "analytic_id": "AN0585",
   "detection_strategy_id": "DET0208",
   "analytic_name": "Analytic 0585",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Host Status (linux:syslog) | Application Log Content (journald:systemd)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ホスト状態 (linux:syslog) | アプリケーションログ内容 (journald:systemd)",
   "tuning": "ServiceName | RestartThreshold | OOMKillCount",
   "detection_logic_en": "Malicious script or binary causes repeated kernel panics, OOM kills, or systemd service restarts targeting services like nginx, httpd, sshd."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499",
   "technique_ja": "エンドポイントDoS",
   "technique_en": "Endpoint Denial of Service",
   "analytic_id": "AN0586",
   "detection_strategy_id": "DET0208",
   "analytic_name": "Analytic 0586",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | Host Status (macos:unifiedlog)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | ホスト状態 (macos:unifiedlog)",
   "tuning": "CrashCountThreshold | PayloadEntropyThreshold",
   "detection_logic_en": "Adversary launches high-entropy process or malformed app bundle causing repeated application crashes and system slowdowns."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499",
   "technique_ja": "エンドポイントDoS",
   "technique_en": "Endpoint Denial of Service",
   "analytic_id": "AN0587",
   "detection_strategy_id": "DET0208",
   "analytic_name": "Analytic 0587",
   "platforms": "IaaS",
   "log_sources": "Host Status (AWS:CloudWatch) | Instance Start (AWS:CloudTrail) | Network Traffic Flow (VPCFlowLogs:All)",
   "log_sources_ja": "ホスト状態 (AWS:CloudWatch) | インスタンス起動 (AWS:CloudTrail) | ネットワークトラフィックフロー (VPCFlowLogs:All)",
   "tuning": "InstanceType | FailureThreshold",
   "detection_logic_en": "Instance enters degraded/unhealthy state due to abnormal process load or memory exhaustion, often caused by automation or script-based attacks."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499",
   "technique_ja": "エンドポイントDoS",
   "technique_en": "Endpoint Denial of Service",
   "analytic_id": "AN0588",
   "detection_strategy_id": "DET0208",
   "analytic_name": "Analytic 0588",
   "platforms": "Containers",
   "log_sources": "Host Status (kubernetes:events) | Application Log Content (docker:events)",
   "log_sources_ja": "ホスト状態 (kubernetes:events) | アプリケーションログ内容 (docker:events)",
   "tuning": "RestartCountThreshold | ContainerImageEntropy",
   "detection_logic_en": "Container orchestrator logs show crashlooping pods, repeated resource exhaustion, or malicious binaries with infinite loops consuming systemd/cgroup limits."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499.001",
   "technique_ja": "OS枯渇フラッド",
   "technique_en": "OS Exhaustion Flood",
   "analytic_id": "AN1012",
   "detection_strategy_id": "DET0356",
   "analytic_name": "Analytic 1012",
   "platforms": "Windows",
   "log_sources": "Process Creation (WinEventLog:Sysmon) | Host Status (WinEventLog:Microsoft-Windows-TCPIP) | Network Traffic Content (NSM:Firewall)",
   "log_sources_ja": "プロセス生成 (WinEventLog:Sysmon) | ホスト状態 (WinEventLog:Microsoft-Windows-TCPIP) | ネットワークトラフィック内容 (NSM:Firewall)",
   "tuning": "TimeWindow | ConnectionRateThreshold | ProcessParentCheck",
   "detection_logic_en": "Burst of incomplete TCP handshakes (e.g., SYN floods) or uncorrelated ACK packets targeting the state table resulting in OS resource exhaustion."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499.001",
   "technique_ja": "OS枯渇フラッド",
   "technique_en": "OS Exhaustion Flood",
   "analytic_id": "AN1013",
   "detection_strategy_id": "DET0356",
   "analytic_name": "Analytic 1013",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow) | Host Status (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow) | ホスト状態 (NSM:Flow)",
   "tuning": "AmplificationThreshold | Interface",
   "detection_logic_en": "Flood of spoofed SYN or ACK packets causing exhaustion of OS TCP state table, potentially via user-space utilities or kernel-level DoS agents."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499.001",
   "technique_ja": "OS枯渇フラッド",
   "technique_en": "OS Exhaustion Flood",
   "analytic_id": "AN1014",
   "detection_strategy_id": "DET0356",
   "analytic_name": "Analytic 1014",
   "platforms": "macOS",
   "log_sources": "Host Status (macos:unifiedlog) | Process Creation (macos:osquery) | Network Traffic Content (NSM:Firewall)",
   "log_sources_ja": "ホスト状態 (macos:unifiedlog) | プロセス生成 (macos:osquery) | ネットワークトラフィック内容 (NSM:Firewall)",
   "tuning": "SystemLoadThreshold | ToolExecutionPath",
   "detection_logic_en": "Adversary tool/script issuing mass SYN/ACK floods that degrade OS responsiveness and interrupt service response on macOS endpoints."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499.002",
   "technique_ja": "サービス枯渇フラッド",
   "technique_en": "Service Exhaustion Flood",
   "analytic_id": "AN0489",
   "detection_strategy_id": "DET0173",
   "analytic_name": "Analytic 0489",
   "platforms": "Windows",
   "log_sources": "Application Log Content (WinEventLog:Application) | Network Connection Creation (WinEventLog:Sysmon) | Host Status (Windows:perfmon)",
   "log_sources_ja": "アプリケーションログ内容 (WinEventLog:Application) | ネットワーク接続確立 (WinEventLog:Sysmon) | ホスト状態 (Windows:perfmon)",
   "tuning": "TimeWindow | TargetServicePort | CPUThreshold",
   "detection_logic_en": "High-frequency, repetitive service requests (e.g., HTTP, TLS renegotiation) originating from a single or small set of source IPs targeting endpoint web services or application ports, leading to exhaustion of CPU or memory on targeted Windows services."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499.002",
   "technique_ja": "サービス枯渇フラッド",
   "technique_en": "Service Exhaustion Flood",
   "analytic_id": "AN0490",
   "detection_strategy_id": "DET0173",
   "analytic_name": "Analytic 0490",
   "platforms": "Linux",
   "log_sources": "Process Access (auditd:SYSCALL) | Network Traffic Flow (NSM:Flow) | Application Log Content (linux:syslog)",
   "log_sources_ja": "プロセスアクセス (auditd:SYSCALL) | ネットワークトラフィックフロー (NSM:Flow) | アプリケーションログ内容 (linux:syslog)",
   "tuning": "ErrorCodeWindow | ConnectionRateThreshold",
   "detection_logic_en": "Excessive inbound HTTP or TLS connections to services such as Apache or Nginx, causing worker thread exhaustion or segmentation faults."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499.002",
   "technique_ja": "サービス枯渇フラッド",
   "technique_en": "Service Exhaustion Flood",
   "analytic_id": "AN0491",
   "detection_strategy_id": "DET0173",
   "analytic_name": "Analytic 0491",
   "platforms": "macOS",
   "log_sources": "Host Status (macos:unifiedlog) | Network Traffic Content (macos:unifiedlog)",
   "log_sources_ja": "ホスト状態 (macos:unifiedlog) | ネットワークトラフィック内容 (macos:unifiedlog)",
   "tuning": "TLSHandshakeRate | ServiceCrashFrequency",
   "detection_logic_en": "Flood of incoming TLS or HTTP(S) connections to macOS-hosted services (e.g., MAMP, Apache), causing high CPU usage and system unresponsiveness."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499.002",
   "technique_ja": "サービス枯渇フラッド",
   "technique_en": "Service Exhaustion Flood",
   "analytic_id": "AN0492",
   "detection_strategy_id": "DET0173",
   "analytic_name": "Analytic 0492",
   "platforms": "IaaS",
   "log_sources": "Firewall Rule Modification (AWS:CloudTrail) | Network Traffic Flow (AWS:VPCFlowLogs) | Host Status (AWS:CloudWatch)",
   "log_sources_ja": "ファイアウォールルール変更 (AWS:CloudTrail) | ネットワークトラフィックフロー (AWS:VPCFlowLogs) | ホスト状態 (AWS:CloudWatch)",
   "tuning": "VPCFlowBurstRate | EC2CPUThreshold",
   "detection_logic_en": "Automated or scripted HTTP/TLS flooding from one VM or cloud instance against another service, exploiting compute-based billing or exhaustion of service infrastructure."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499.003",
   "technique_ja": "アプリケーション枯渇フラッド",
   "technique_en": "Application Exhaustion Flood",
   "analytic_id": "AN1165",
   "detection_strategy_id": "DET0415",
   "analytic_name": "Analytic 1165",
   "platforms": "Windows",
   "log_sources": "Application Log Content (WinEventLog:Application) | Process Creation (WinEventLog:Sysmon) | Host Status (Windows:perfmon)",
   "log_sources_ja": "アプリケーションログ内容 (WinEventLog:Application) | プロセス生成 (WinEventLog:Sysmon) | ホスト状態 (Windows:perfmon)",
   "tuning": "CPUThreshold | MemoryConsumptionWindow | AppCrashFrequency",
   "detection_logic_en": "Repeated invocation of high-resource application endpoints or GUI components causing CPU and memory spikes, logged as elevated request volumes, prolonged handle locks, or frequent crash recoveries."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499.003",
   "technique_ja": "アプリケーション枯渇フラッド",
   "technique_en": "Application Exhaustion Flood",
   "analytic_id": "AN1166",
   "detection_strategy_id": "DET0415",
   "analytic_name": "Analytic 1166",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | Application Log Content (linux:syslog) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | アプリケーションログ内容 (linux:syslog) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "SyslogErrorRate | PortRequestSpikeThreshold | ProcessSpawnRate",
   "detection_logic_en": "Automated scripts or repeated CLI/API requests that trigger application backends to consume high CPU or memory (e.g., Apache/PHP, MySQL, mail servers), resulting in syslog errors and excessive process spawning."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499.003",
   "technique_ja": "アプリケーション枯渇フラッド",
   "technique_en": "Application Exhaustion Flood",
   "analytic_id": "AN1167",
   "detection_strategy_id": "DET0415",
   "analytic_name": "Analytic 1167",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | Process Creation (macos:osquery)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | プロセス生成 (macos:osquery)",
   "tuning": "SpinReportCount | HeavyAppReopenRate",
   "detection_logic_en": "Repetitive triggering of GUI or backend application workflows that cause increased CPU/memory usage, logged in unified logs as spin reports or crash dumps."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499.003",
   "technique_ja": "アプリケーション枯渇フラッド",
   "technique_en": "Application Exhaustion Flood",
   "analytic_id": "AN1168",
   "detection_strategy_id": "DET0415",
   "analytic_name": "Analytic 1168",
   "platforms": "IaaS",
   "log_sources": "Application Log Content (AWS:CloudWatch) | Cloud Service Metadata (AWS:CloudTrail) | Host Status (AWS:CloudMetrics)",
   "log_sources_ja": "アプリケーションログ内容 (AWS:CloudWatch) | クラウドサービスメタデータ (AWS:CloudTrail) | ホスト状態 (AWS:CloudMetrics)",
   "tuning": "HTTP5xxRateThreshold | FunctionInvocationRate | AutoscaleEventCount",
   "detection_logic_en": "Automated abuse of cloud-hosted applications (e.g., web apps, REST endpoints, internal APIs) causing compute exhaustion, high 5xx error rates, or frequent autoscaling triggers logged in app insights or cloudwatch."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499.004",
   "technique_ja": "アプリ/システムの脆弱性悪用",
   "technique_en": "Application or System Exploitation",
   "analytic_id": "AN0850",
   "detection_strategy_id": "DET0304",
   "analytic_name": "Analytic 0850",
   "platforms": "Windows",
   "log_sources": "Application Log Content (WinEventLog:Application) | Process Creation (WinEventLog:Sysmon) | Service Creation (WinEventLog:System)",
   "log_sources_ja": "アプリケーションログ内容 (WinEventLog:Application) | プロセス生成 (WinEventLog:Sysmon) | サービス作成 (WinEventLog:System)",
   "tuning": "TimeWindow | TargetApplication",
   "detection_logic_en": "Exploitation of system or application vulnerability (e.g., CVE-based exploit) followed by service crash, restart, or repeated failure within a short time frame, impacting application/system availability."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499.004",
   "technique_ja": "アプリ/システムの脆弱性悪用",
   "technique_en": "Application or System Exploitation",
   "analytic_id": "AN0851",
   "detection_strategy_id": "DET0304",
   "analytic_name": "Analytic 0851",
   "platforms": "Linux",
   "log_sources": "Process Termination (auditd:SYSCALL) | Application Log Content (journald:Application) | Network Traffic Content (NSM:Flow)",
   "log_sources_ja": "プロセス終了 (auditd:SYSCALL) | アプリケーションログ内容 (journald:Application) | ネットワークトラフィック内容 (NSM:Flow)",
   "tuning": "CrashPattern | ExploitSourceIP",
   "detection_logic_en": "User or remote input triggers application crash or segmentation fault (e.g., SIGSEGV) with service recovery attempts, observed via audit logs and systemd journaling."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499.004",
   "technique_ja": "アプリ/システムの脆弱性悪用",
   "technique_en": "Application or System Exploitation",
   "analytic_id": "AN0852",
   "detection_strategy_id": "DET0304",
   "analytic_name": "Analytic 0852",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | Process Creation (macos:unifiedlog)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | プロセス生成 (macos:unifiedlog)",
   "tuning": "CrashSignature | InputVector",
   "detection_logic_en": "Application crash or repeated restart cycle triggered by malformed input or exploit file, observed via unified logs and process crash monitoring."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1499.004",
   "technique_ja": "アプリ/システムの脆弱性悪用",
   "technique_en": "Application or System Exploitation",
   "analytic_id": "AN0853",
   "detection_strategy_id": "DET0304",
   "analytic_name": "Analytic 0853",
   "platforms": "IaaS",
   "log_sources": "Instance Stop (AWS:CloudTrail) | Application Log Content (AWS:CloudWatch) | Network Traffic Content (AWS:VPCFlowLogs)",
   "log_sources_ja": "インスタンス停止 (AWS:CloudTrail) | アプリケーションログ内容 (AWS:CloudWatch) | ネットワークトラフィック内容 (AWS:VPCFlowLogs)",
   "tuning": "CrashThreshold | ServiceID",
   "detection_logic_en": "Cloud workload exploitation leads to repeated container, service, or VM termination/restart, typically associated with CVE-based crash triggers or fuzzed payloads."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1529",
   "technique_ja": "システムのシャットダウン/再起動",
   "technique_en": "System Shutdown/Reboot",
   "analytic_id": "AN1538",
   "detection_strategy_id": "DET0559",
   "analytic_name": "Analytic 1538",
   "platforms": "Windows",
   "log_sources": "Host Status (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ホスト状態 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "UserContext | TimeWindow",
   "detection_logic_en": "Correlate process execution of shutdown/reboot commands (e.g., shutdown.exe, restart-computer) with host status change logs (Event IDs 1074, 6006) and absence of related administrative context (e.g., user not in Helpdesk group)."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1529",
   "technique_ja": "システムのシャットダウン/再起動",
   "technique_en": "System Shutdown/Reboot",
   "analytic_id": "AN1539",
   "detection_strategy_id": "DET0559",
   "analytic_name": "Analytic 1539",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | Host Status (linux:syslog)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | ホスト状態 (linux:syslog)",
   "tuning": "CommandLineMatch | UserContext",
   "detection_logic_en": "Detect 'shutdown', 'reboot', or 'systemctl poweroff' executions with auditd/syslog and absence of scheduled maintenance windows or approved user context."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1529",
   "technique_ja": "システムのシャットダウン/再起動",
   "technique_en": "System Shutdown/Reboot",
   "analytic_id": "AN1540",
   "detection_strategy_id": "DET0559",
   "analytic_name": "Analytic 1540",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Host Status (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | ホスト状態 (macos:unifiedlog)",
   "tuning": "LaunchMechanism | LogGranularity",
   "detection_logic_en": "Identify use of 'shutdown', 'reboot', or 'osascript' system shutdown invocations within unified logs and track unexpected shutdown sequences initiated by GUI or script. Cross-reference with user activity or absence thereof."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1529",
   "technique_ja": "システムのシャットダウン/再起動",
   "technique_en": "System Shutdown/Reboot",
   "analytic_id": "AN1541",
   "detection_strategy_id": "DET0559",
   "analytic_name": "Analytic 1541",
   "platforms": "ESXi",
   "log_sources": "Host Status (esxi:hostd) | Command Execution (esxi:shell)",
   "log_sources_ja": "ホスト状態 (esxi:hostd) | コマンド実行 (esxi:shell)",
   "tuning": "AccountRole | MaintenanceWindow",
   "detection_logic_en": "Detect commands such as 'esxcli system shutdown' or 'vim-cmd vmsvc/power.shutdown' executed outside of maintenance windows or via unusual users. Reboot logs in hostd.log and shell logs should be correlated."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1529",
   "technique_ja": "システムのシャットダウン/再起動",
   "technique_en": "System Shutdown/Reboot",
   "analytic_id": "AN1542",
   "detection_strategy_id": "DET0559",
   "analytic_name": "Analytic 1542",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:syslog) | Host Status (networkdevice:syslog)",
   "log_sources_ja": "コマンド実行 (networkdevice:syslog) | ホスト状態 (networkdevice:syslog)",
   "tuning": "PrivilegeLevel | ChangeTicketCorrelation",
   "detection_logic_en": "Monitor CLI 'reload' commands issued without scheduled maintenance, and correlate to TACACS+/AAA logs for privilege validation."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1531",
   "technique_ja": "アカウントアクセスの剥奪",
   "technique_en": "Account Access Removal",
   "analytic_id": "AN0334",
   "detection_strategy_id": "DET0120",
   "analytic_name": "Analytic 0334",
   "platforms": "Windows",
   "log_sources": "User Account Modification (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ユーザーアカウント変更 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "UserContext | TimeWindow | ParentProcessName",
   "detection_logic_en": "Correlated user account modification (reset, disable, deletion) events with anomalous process lineage (e.g., PowerShell or net.exe from an interactive session), especially outside of IT admin change windows or by non-admin users."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1531",
   "technique_ja": "アカウントアクセスの剥奪",
   "technique_en": "Account Access Removal",
   "analytic_id": "AN0335",
   "detection_strategy_id": "DET0120",
   "analytic_name": "Analytic 0335",
   "platforms": "Linux",
   "log_sources": "Process Creation (auditd:SYSCALL) | User Account Authentication (NSM:Connections)",
   "log_sources_ja": "プロセス生成 (auditd:SYSCALL) | ユーザーアカウント認証 (NSM:Connections)",
   "tuning": "ExecPath | NonRootUIDThreshold",
   "detection_logic_en": "Password changes or account deletions via 'passwd', 'userdel', or 'chage' preceded by interactive shell or remote command execution from non-privileged accounts."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1531",
   "technique_ja": "アカウントアクセスの剥奪",
   "technique_en": "Account Access Removal",
   "analytic_id": "AN0336",
   "detection_strategy_id": "DET0120",
   "analytic_name": "Analytic 0336",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | User Account Authentication (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ユーザーアカウント認証 (macos:unifiedlog)",
   "tuning": "CommandLinePattern | AnomalousUserFlag",
   "detection_logic_en": "Execution of dscl or sysadminctl commands to disable, delete, or modify users combined with anomalous process ancestry or terminal session launch."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1531",
   "technique_ja": "アカウントアクセスの剥奪",
   "technique_en": "Account Access Removal",
   "analytic_id": "AN0337",
   "detection_strategy_id": "DET0120",
   "analytic_name": "Analytic 0337",
   "platforms": "ESXi",
   "log_sources": "User Account Deletion (esxi:hostd) | User Account Authentication (esxi:vpxa)",
   "log_sources_ja": "ユーザーアカウント削除 (esxi:hostd) | ユーザーアカウント認証 (esxi:vpxa)",
   "tuning": "RemoteUserRole | ExpectedIPs",
   "detection_logic_en": "Invocation of esxcli 'system account remove' from vCLI, SSH, or vSphere API with anomalous user access or outside maintenance windows."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1531",
   "technique_ja": "アカウントアクセスの剥奪",
   "technique_en": "Account Access Removal",
   "analytic_id": "AN0338",
   "detection_strategy_id": "DET0120",
   "analytic_name": "Analytic 0338",
   "platforms": "Office Suite",
   "log_sources": "User Account Deletion (m365:unified) | User Account Authentication (m365:signinlogs)",
   "log_sources_ja": "ユーザーアカウント削除 (m365:unified) | ユーザーアカウント認証 (m365:signinlogs)",
   "tuning": "RoleAssignment | GeoThreshold",
   "detection_logic_en": "O365 UnifiedAuditLog entries for Remove-Mailbox or Set-Mailbox with account disable or delete actions correlated with suspicious login locations or MFA bypass."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1531",
   "technique_ja": "アカウントアクセスの剥奪",
   "technique_en": "Account Access Removal",
   "analytic_id": "AN0339",
   "detection_strategy_id": "DET0120",
   "analytic_name": "Analytic 0339",
   "platforms": "SaaS",
   "log_sources": "User Account Modification (saas:okta)",
   "log_sources_ja": "ユーザーアカウント変更 (saas:okta)",
   "tuning": "BulkActionThreshold | SessionDeviceType",
   "detection_logic_en": "Deletion or disablement of user accounts in platforms like Okta, Salesforce, or Zoom with anomalies in admin session attributes or mass actions within short duration."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1561",
   "technique_ja": "ディスクワイプ",
   "technique_en": "Disk Wipe",
   "analytic_id": "AN0384",
   "detection_strategy_id": "DET0137",
   "analytic_name": "Analytic 0384",
   "platforms": "Windows",
   "log_sources": "User Account Metadata (WinEventLog:Security) | Drive Modification (WinEventLog:Sysmon) | Driver Load (WinEventLog:Sysmon)",
   "log_sources_ja": "ユーザーアカウントメタデータ (WinEventLog:Security) | ドライブ変更 (WinEventLog:Sysmon) | ドライバ読み込み (WinEventLog:Sysmon)",
   "tuning": "ProcessWhitelist | TimeWindow",
   "detection_logic_en": "Unusual direct disk access attempts (e.g., use of \\\\.\\PhysicalDrive notation), abnormal writes to MBR/boot sectors, and installation of kernel drivers that grant raw disk access. Correlate anomalous process creation with disk modification attempts and driver loads."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1561",
   "technique_ja": "ディスクワイプ",
   "technique_en": "Disk Wipe",
   "analytic_id": "AN0385",
   "detection_strategy_id": "DET0137",
   "analytic_name": "Analytic 0385",
   "platforms": "Linux",
   "log_sources": "Drive Access (auditd:SYSCALL) | Process Creation (auditd:EXECVE)",
   "log_sources_ja": "ドライブアクセス (auditd:SYSCALL) | プロセス生成 (auditd:EXECVE)",
   "tuning": "TargetDevices | EntropyThreshold",
   "detection_logic_en": "Processes invoking destructive commands (dd, shred, wipe) with raw device targets (e.g., /dev/sda, /dev/nvme0n1). Detect direct writes to disk partitions and abnormal superblock or bootloader modifications. Correlate shell execution with subsequent block device I/O."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1561",
   "technique_ja": "ディスクワイプ",
   "technique_en": "Disk Wipe",
   "analytic_id": "AN0386",
   "detection_strategy_id": "DET0137",
   "analytic_name": "Analytic 0386",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Drive Modification (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ドライブ変更 (macos:unifiedlog)",
   "tuning": "AdminToolWhitelist",
   "detection_logic_en": "Abnormal invocation of diskutil, asr, or low-level APIs (IOKit) to erase/partition drives. Correlate process execution with unified log entries showing destructive disk operations."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1561",
   "technique_ja": "ディスクワイプ",
   "technique_en": "Disk Wipe",
   "analytic_id": "AN0387",
   "detection_strategy_id": "DET0137",
   "analytic_name": "Analytic 0387",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:cli) | User Account Authentication (networkdevice:syslog)",
   "log_sources_ja": "コマンド実行 (networkdevice:cli) | ユーザーアカウント認証 (networkdevice:syslog)",
   "tuning": "PrivilegedUsers | CommandPatterns",
   "detection_logic_en": "Execution of destructive CLI commands such as 'erase startup-config', 'erase flash:' or 'format disk' on routers/switches. Detect privilege level escalation preceding destructive commands."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1561.001",
   "technique_ja": "ディスク内容のワイプ",
   "technique_en": "Disk Content Wipe",
   "analytic_id": "AN0882",
   "detection_strategy_id": "DET0316",
   "analytic_name": "Analytic 0882",
   "platforms": "Windows",
   "log_sources": "User Account Metadata (WinEventLog:Security) | Drive Modification (WinEventLog:Sysmon) | Driver Load (WinEventLog:Sysmon)",
   "log_sources_ja": "ユーザーアカウントメタデータ (WinEventLog:Security) | ドライブ変更 (WinEventLog:Sysmon) | ドライバ読み込み (WinEventLog:Sysmon)",
   "tuning": "ProcessWhitelist | TimeWindow",
   "detection_logic_en": "Processes attempting raw disk access via \\\\.\\PhysicalDrive paths, abnormal file I/O to MBR/boot sectors, or loading of third-party drivers (e.g., RawDisk) that enable disk overwrite. Correlate process creation, privilege usage, and disk modification events within a short time window."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1561.001",
   "technique_ja": "ディスク内容のワイプ",
   "technique_en": "Disk Content Wipe",
   "analytic_id": "AN0883",
   "detection_strategy_id": "DET0316",
   "analytic_name": "Analytic 0883",
   "platforms": "Linux",
   "log_sources": "Drive Access (auditd:SYSCALL) | Process Creation (auditd:EXECVE)",
   "log_sources_ja": "ドライブアクセス (auditd:SYSCALL) | プロセス生成 (auditd:EXECVE)",
   "tuning": "TargetDevices | EntropyThreshold",
   "detection_logic_en": "Execution of destructive utilities (dd, shred, wipe) targeting block devices, or processes invoking syscalls to directly overwrite /dev/sd* or /dev/nvme* partitions. Correlate abnormal file write attempts with shell process execution and block device access."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1561.001",
   "technique_ja": "ディスク内容のワイプ",
   "technique_en": "Disk Content Wipe",
   "analytic_id": "AN0884",
   "detection_strategy_id": "DET0316",
   "analytic_name": "Analytic 0884",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Drive Modification (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ドライブ変更 (macos:unifiedlog)",
   "tuning": "AdminToolWhitelist",
   "detection_logic_en": "Abnormal invocation of diskutil or asr with destructive flags (eraseDisk, zeroDisk), or low-level IOKit calls that overwrite raw disk content. Detect correlation between elevated process execution and disk erase operations."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1561.001",
   "technique_ja": "ディスク内容のワイプ",
   "technique_en": "Disk Content Wipe",
   "analytic_id": "AN0885",
   "detection_strategy_id": "DET0316",
   "analytic_name": "Analytic 0885",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:cli) | User Account Authentication (networkdevice:syslog)",
   "log_sources_ja": "コマンド実行 (networkdevice:cli) | ユーザーアカウント認証 (networkdevice:syslog)",
   "tuning": "PrivilegedUsers | CommandPatterns",
   "detection_logic_en": "Execution of CLI commands erasing file systems or storage (erase flash:, format disk, erase nvram:). Detect authentication events followed by destructive commands within the same privileged session."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1561.002",
   "technique_ja": "ディスク構造のワイプ",
   "technique_en": "Disk Structure Wipe",
   "analytic_id": "AN0827",
   "detection_strategy_id": "DET0297",
   "analytic_name": "Analytic 0827",
   "platforms": "Windows",
   "log_sources": "User Account Metadata (WinEventLog:Security) | Drive Modification (WinEventLog:Sysmon) | Driver Load (WinEventLog:Sysmon)",
   "log_sources_ja": "ユーザーアカウントメタデータ (WinEventLog:Security) | ドライブ変更 (WinEventLog:Sysmon) | ドライバ読み込み (WinEventLog:Sysmon)",
   "tuning": "SectorRange | ProcessWhitelist",
   "detection_logic_en": "Processes attempting raw disk access to overwrite sensitive structures such as the MBR or partition table using \\\\.\\PhysicalDrive notation. Detection relies on correlating process creation, privilege escalation, and raw sector writes in Sysmon and Security logs."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1561.002",
   "technique_ja": "ディスク構造のワイプ",
   "technique_en": "Disk Structure Wipe",
   "analytic_id": "AN0828",
   "detection_strategy_id": "DET0297",
   "analytic_name": "Analytic 0828",
   "platforms": "Linux",
   "log_sources": "Drive Access (auditd:SYSCALL) | Process Creation (auditd:EXECVE)",
   "log_sources_ja": "ドライブアクセス (auditd:SYSCALL) | プロセス生成 (auditd:EXECVE)",
   "tuning": "TargetDevices | OffsetThreshold",
   "detection_logic_en": "Execution of utilities (dd, hdparm, sgdisk) or custom binaries attempting to overwrite disk boot structures (/dev/sda MBR sector or partition tables). Detection correlates shell execution with syscalls writing to sector 0 or disk metadata blocks."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1561.002",
   "technique_ja": "ディスク構造のワイプ",
   "technique_en": "Disk Structure Wipe",
   "analytic_id": "AN0829",
   "detection_strategy_id": "DET0297",
   "analytic_name": "Analytic 0829",
   "platforms": "macOS",
   "log_sources": "Command Execution (macos:unifiedlog) | Drive Modification (macos:unifiedlog)",
   "log_sources_ja": "コマンド実行 (macos:unifiedlog) | ドライブ変更 (macos:unifiedlog)",
   "tuning": "AdminToolWhitelist",
   "detection_logic_en": "Abnormal invocation of diskutil or asr that modifies partition tables or initializes raw devices. Monitor for IOKit system calls targeting disk headers or EFI boot sectors, correlated with elevated privileges."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1561.002",
   "technique_ja": "ディスク構造のワイプ",
   "technique_en": "Disk Structure Wipe",
   "analytic_id": "AN0830",
   "detection_strategy_id": "DET0297",
   "analytic_name": "Analytic 0830",
   "platforms": "Network Devices",
   "log_sources": "Command Execution (networkdevice:cli) | User Account Authentication (networkdevice:syslog)",
   "log_sources_ja": "コマンド実行 (networkdevice:cli) | ユーザーアカウント認証 (networkdevice:syslog)",
   "tuning": "CommandPatterns | PrivilegedUsers",
   "detection_logic_en": "Execution of destructive CLI commands such as format flash:, format disk, or equivalent vendor-specific commands that erase filesystem structures. Detection correlates AAA logs showing privileged access with immediate format/erase commands."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1565",
   "technique_ja": "データ操作",
   "technique_en": "Data Manipulation",
   "analytic_id": "AN0162",
   "detection_strategy_id": "DET0059",
   "analytic_name": "Analytic 0162",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Modification (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon) | File Access (WinEventLog:Security)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon) | ファイルアクセス (WinEventLog:Security)",
   "tuning": "MonitoredFilePaths | TimeWindow | AuthorizedProcesses",
   "detection_logic_en": "Correlate unauthorized or anomalous file modifications, deletions, or metadata changes with suspicious process execution or API calls. Detect abnormal changes to structured data (e.g., database files, logs, financial records) outside expected business process activity."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1565",
   "technique_ja": "データ操作",
   "technique_en": "Data Manipulation",
   "analytic_id": "AN0163",
   "detection_strategy_id": "DET0059",
   "analytic_name": "Analytic 0163",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | Network Traffic Content (linux:syslog)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | ネットワークトラフィック内容 (linux:syslog)",
   "tuning": "WatchedDirectories | CommandExclusions",
   "detection_logic_en": "Detect unauthorized manipulation of log files, database entries, or system configuration files through auditd and syslog. Correlate shell commands that alter HISTFILE or data-related processes with abnormal file access patterns."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1565",
   "technique_ja": "データ操作",
   "technique_en": "Data Manipulation",
   "analytic_id": "AN0164",
   "detection_strategy_id": "DET0059",
   "analytic_name": "Analytic 0164",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | OS API Execution (macos:osquery)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | OS API実行 (macos:osquery)",
   "tuning": "AllowedPlistEditors | FileIntegrityBaseline",
   "detection_logic_en": "Detect manipulation of system or application files in `/Library`, `/System`, or user data directories using FSEvents and Unified Logs. Identify anomalous process execution modifying plist files, structured data, or logs outside expected update cycles."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1565.001",
   "technique_ja": "保存データの操作",
   "technique_en": "Stored Data Manipulation",
   "analytic_id": "AN0555",
   "detection_strategy_id": "DET0193",
   "analytic_name": "Analytic 0555",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Deletion (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon) | File Modification (WinEventLog:Security)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイル削除 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon) | ファイル変更 (WinEventLog:Security)",
   "tuning": "MonitoredDirectories | AuthorizedProcesses | TimeWindow",
   "detection_logic_en": "Identify unauthorized creation, deletion, or modification of business-critical stored data such as Office documents, database files, and log archives. Detect anomalous processes modifying stored data outside of expected workflows (e.g., non-database processes modifying database files)."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1565.001",
   "technique_ja": "保存データの操作",
   "technique_en": "Stored Data Manipulation",
   "analytic_id": "AN0556",
   "detection_strategy_id": "DET0193",
   "analytic_name": "Analytic 0556",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:SYSCALL) | File Modification (auditd:SYSCALL)",
   "log_sources_ja": "ファイル作成 (auditd:SYSCALL) | ファイル変更 (auditd:SYSCALL)",
   "tuning": "WatchedPaths | CommandExclusions",
   "detection_logic_en": "Detect suspicious file creation, modification, or deletion in stored data directories (e.g., `/var/lib/mysql/`, `/var/log/`, mail spools). Identify shell commands interacting directly with structured data files instead of legitimate database utilities."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1565.001",
   "technique_ja": "保存データの操作",
   "technique_en": "Stored Data Manipulation",
   "analytic_id": "AN0557",
   "detection_strategy_id": "DET0193",
   "analytic_name": "Analytic 0557",
   "platforms": "macOS",
   "log_sources": "File Modification (macos:unifiedlog) | File Deletion (macos:osquery)",
   "log_sources_ja": "ファイル変更 (macos:unifiedlog) | ファイル削除 (macos:osquery)",
   "tuning": "FileIntegrityBaseline | AllowedEditors",
   "detection_logic_en": "Monitor sensitive data files such as plist-based storage, mail archives, or Office files for unexpected modifications. Detect anomalous processes modifying stored data outside expected update cycles using FSEvents and Unified Logs."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1565.002",
   "technique_ja": "転送データの操作",
   "technique_en": "Transmitted Data Manipulation",
   "analytic_id": "AN0702",
   "detection_strategy_id": "DET0254",
   "analytic_name": "Analytic 0702",
   "platforms": "Windows",
   "log_sources": "Network Connection Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon)",
   "log_sources_ja": "ネットワーク接続確立 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon)",
   "tuning": "IntegrityBaseline | MonitoredPorts",
   "detection_logic_en": "Monitor for anomalies in transmitted data streams, including mismatched file integrity checks, API interception, or man-in-the-middle modifications. Detect unexpected use of APIs that handle network I/O where transmitted data integrity could be manipulated."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1565.002",
   "technique_ja": "転送データの操作",
   "technique_en": "Transmitted Data Manipulation",
   "analytic_id": "AN0703",
   "detection_strategy_id": "DET0254",
   "analytic_name": "Analytic 0703",
   "platforms": "Linux",
   "log_sources": "OS API Execution (auditd:SYSCALL) | Network Traffic Content (linux:syslog)",
   "log_sources_ja": "OS API実行 (auditd:SYSCALL) | ネットワークトラフィック内容 (linux:syslog)",
   "tuning": "WatchedProcesses | HashCheckInterval",
   "detection_logic_en": "Detect alterations of transmitted data via monitoring syscalls (`send`, `recv`, `write`) or middleware interception. Identify mismatched file hashes when compared at origin vs. destination. Watch for anomalous activity from processes interacting with secure transmission services (e.g., OpenSSL, scp)."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1565.002",
   "technique_ja": "転送データの操作",
   "technique_en": "Transmitted Data Manipulation",
   "analytic_id": "AN0704",
   "detection_strategy_id": "DET0254",
   "analytic_name": "Analytic 0704",
   "platforms": "macOS",
   "log_sources": "Network Traffic Flow (macos:unifiedlog) | OS API Execution (macos:osquery)",
   "log_sources_ja": "ネットワークトラフィックフロー (macos:unifiedlog) | OS API実行 (macos:osquery)",
   "tuning": "TLSValidationRules | AllowedApps",
   "detection_logic_en": "Monitor system APIs such as CFNetwork and SecureTransport for anomalies in transmitted data streams. Detect mismatches in file hashes or SSL/TLS downgrade attempts that enable manipulation of transmitted data."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1565.003",
   "technique_ja": "実行時データの操作",
   "technique_en": "Runtime Data Manipulation",
   "analytic_id": "AN1097",
   "detection_strategy_id": "DET0391",
   "analytic_name": "Analytic 1097",
   "platforms": "Windows",
   "log_sources": "File Creation (WinEventLog:Sysmon) | File Metadata (WinEventLog:Sysmon) | Windows Registry Key Modification (WinEventLog:Security)",
   "log_sources_ja": "ファイル作成 (WinEventLog:Sysmon) | ファイルメタデータ (WinEventLog:Sysmon) | Windowsレジストリキー変更 (WinEventLog:Security)",
   "tuning": "MonitoredPaths | HashBaseline",
   "detection_logic_en": "Monitor for runtime data manipulations by detecting suspicious modification of application binaries, API hooking, or unexpected behavior from processes responsible for rendering or displaying data. Correlate registry edits, process creation, and unexpected binary hash mismatches."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1565.003",
   "technique_ja": "実行時データの操作",
   "technique_en": "Runtime Data Manipulation",
   "analytic_id": "AN1098",
   "detection_strategy_id": "DET0391",
   "analytic_name": "Analytic 1098",
   "platforms": "Linux",
   "log_sources": "File Modification (auditd:SYSCALL) | OS API Execution (linux:syslog)",
   "log_sources_ja": "ファイル変更 (auditd:SYSCALL) | OS API実行 (linux:syslog)",
   "tuning": "WatchedBinaries | IntegrityCheckFrequency",
   "detection_logic_en": "Detect runtime manipulation by monitoring system calls for modifications to shared libraries, ELF binaries, or environment variables that affect how data is displayed. Look for suspicious writes to application directories and mismatch in binary integrity baselines."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1565.003",
   "technique_ja": "実行時データの操作",
   "technique_en": "Runtime Data Manipulation",
   "analytic_id": "AN1099",
   "detection_strategy_id": "DET0391",
   "analytic_name": "Analytic 1099",
   "platforms": "macOS",
   "log_sources": "File Metadata (macos:unifiedlog) | File Modification (macos:osquery)",
   "log_sources_ja": "ファイルメタデータ (macos:unifiedlog) | ファイル変更 (macos:osquery)",
   "tuning": "AllowedApps | SignatureEnforcement",
   "detection_logic_en": "Monitor for runtime manipulation by observing changes in application bundles, unexpected signing modifications, and runtime API calls that inject or alter how data is displayed. Detect alterations in CFNetwork or CoreFoundation frameworks responsible for rendering data."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1657",
   "technique_ja": "金銭窃盗",
   "technique_en": "Financial Theft",
   "analytic_id": "AN1361",
   "detection_strategy_id": "DET0495",
   "analytic_name": "Analytic 1361",
   "platforms": "Windows",
   "log_sources": "Logon Session Creation (WinEventLog:Security) | Process Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "ログオンセッション作成 (WinEventLog:Security) | プロセス生成 (WinEventLog:Sysmon)",
   "tuning": "FinanceAppList | HighRiskAccounts",
   "detection_logic_en": "Monitor for anomalous access to financial applications, browser-based banking sessions, or enterprise ERP systems from Windows endpoints. Detect mass emailing of payment instructions, sudden rule changes in Outlook for financial staff, or use of clipboard data exfiltration tied to cryptocurrency wallet addresses."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1657",
   "technique_ja": "金銭窃盗",
   "technique_en": "Financial Theft",
   "analytic_id": "AN1362",
   "detection_strategy_id": "DET0495",
   "analytic_name": "Analytic 1362",
   "platforms": "Linux",
   "log_sources": "Command Execution (auditd:SYSCALL) | Application Log Content (linux:syslog)",
   "log_sources_ja": "コマンド実行 (auditd:SYSCALL) | アプリケーションログ内容 (linux:syslog)",
   "tuning": "KnownFinanceIPs",
   "detection_logic_en": "Monitor server and endpoint logs for unusual outbound network connections to cryptocurrency nodes, unauthorized scripts accessing financial systems, or automation targeting payment file formats. Detect curl/wget activity aimed at exfiltrating transaction data or credentials from financial apps."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1657",
   "technique_ja": "金銭窃盗",
   "technique_en": "Financial Theft",
   "analytic_id": "AN1363",
   "detection_strategy_id": "DET0495",
   "analytic_name": "Analytic 1363",
   "platforms": "macOS",
   "log_sources": "Process Creation (macos:unifiedlog) | Application Log Content (macos:unifiedlog)",
   "log_sources_ja": "プロセス生成 (macos:unifiedlog) | アプリケーションログ内容 (macos:unifiedlog)",
   "tuning": "MonitoredApps",
   "detection_logic_en": "Monitor unified logs for access to payment applications, browser plug-ins, or Apple Pay services from non-standard processes. Detect anomalous use of Automator scripts or keychain extraction targeting financial account credentials."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1657",
   "technique_ja": "金銭窃盗",
   "technique_en": "Financial Theft",
   "analytic_id": "AN1364",
   "detection_strategy_id": "DET0495",
   "analytic_name": "Analytic 1364",
   "platforms": "SaaS",
   "log_sources": "Application Log Content (saas:finance)",
   "log_sources_ja": "アプリケーションログ内容 (saas:finance)",
   "tuning": "TransactionThreshold",
   "detection_logic_en": "Monitor SaaS financial systems (e.g., QuickBooks, Workday, SAP S/4HANA cloud) for unauthorized access, rule changes, or mass export of financial data. Detect anomalous transfers initiated via SaaS APIs or new MFA-disabled logins targeting finance apps."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1657",
   "technique_ja": "金銭窃盗",
   "technique_en": "Financial Theft",
   "analytic_id": "AN1365",
   "detection_strategy_id": "DET0495",
   "analytic_name": "Analytic 1365",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:unified) | File Modification (m365:office)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | ファイル変更 (m365:office)",
   "tuning": "FraudTerms",
   "detection_logic_en": "Monitor email and document management systems for fraudulent invoices, impersonation of vendors, or BEC-style payment redirections. Detect abnormal editing of invoice templates, or emails containing known fraud language combined with attachment delivery."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1667",
   "technique_ja": "メール爆撃",
   "technique_en": "Email Bombing",
   "analytic_id": "AN1008",
   "detection_strategy_id": "DET0355",
   "analytic_name": "Analytic 1008",
   "platforms": "Windows",
   "log_sources": "Application Log Content (m365:unified) | File Creation (WinEventLog:Sysmon)",
   "log_sources_ja": "アプリケーションログ内容 (m365:unified) | ファイル作成 (WinEventLog:Sysmon)",
   "tuning": "TimeWindow | RecipientThreshold | AttachmentSizeThreshold",
   "detection_logic_en": "Detect abnormally high volume of inbound email messages or repetitive attachments being delivered to a single mailbox within a short time window. Defenders should look for anomalous spikes in message counts and repetitive attachment file creation events correlated with targeted users."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1667",
   "technique_ja": "メール爆撃",
   "technique_en": "Email Bombing",
   "analytic_id": "AN1009",
   "detection_strategy_id": "DET0355",
   "analytic_name": "Analytic 1009",
   "platforms": "Linux",
   "log_sources": "File Creation (auditd:SYSCALL) | Application Log Content (Application:Mail)",
   "log_sources_ja": "ファイル作成 (auditd:SYSCALL) | アプリケーションログ内容 (Application:Mail)",
   "tuning": "MailVolumeThreshold | AttachmentPatternList",
   "detection_logic_en": "Monitor mail server logs (e.g., Postfix, Sendmail) for excessive connections or inbound message counts targeting a single recipient. Correlate with repetitive attachment storage in /var/mail or /var/spool/mail directories."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1667",
   "technique_ja": "メール爆撃",
   "technique_en": "Email Bombing",
   "analytic_id": "AN1010",
   "detection_strategy_id": "DET0355",
   "analytic_name": "Analytic 1010",
   "platforms": "Office Suite",
   "log_sources": "Application Log Content (m365:exchange)",
   "log_sources_ja": "アプリケーションログ内容 (m365:exchange)",
   "tuning": "UserContext",
   "detection_logic_en": "Detect abnormal use of email clients (e.g., Outlook, Thunderbird) showing mass arrival of messages or repetitive attachments being locally stored. Correlate message volume with file creation activity in mail cache directories."
  },
  {
   "tactic_id": "TA0040",
   "tactic_ja": "影響",
   "technique_id": "T1667",
   "technique_ja": "メール爆撃",
   "technique_en": "Email Bombing",
   "analytic_id": "AN1011",
   "detection_strategy_id": "DET0355",
   "analytic_name": "Analytic 1011",
   "platforms": "macOS",
   "log_sources": "Application Log Content (macos:unifiedlog) | File Creation (fs:fsusage)",
   "log_sources_ja": "アプリケーションログ内容 (macos:unifiedlog) | ファイル作成 (fs:fsusage)",
   "tuning": "FileCountThreshold",
   "detection_logic_en": "Monitor unified logs and Mail.app activity for repetitive incoming messages with attachments. Defenders should look for large volumes of incoming mail stored under ~/Library/Mail with unusual timing or repetitive subjects."
  }
 ]
}