skip to content

A five-year ATT&CK technique series shows one technique dropping 30% - why is "they stopped" wrong?

level: seniorimportance: should knowfreq 44%

answer

  1. did the catalogue move, or the crew
  2. a cliff dated at a release boundary
  3. parent versus child recording depth
  4. you are counting labels, not actions
  5. ordinary grants sit under the same number

basics

~10 s

Because the catalogue moved underneath the series. Identifiers were revoked, split and re-parented across those releases, and the mappings count labels people wrote, not adversary actions. Normalise every year to one release first.

solid answer

~50 s

Three things can produce that curve before the adversary changes anything. First, **version skew**: identifiers moved across releases, and the July 2020 sub-technique restructure moved many at once - a behaviour recorded as `T1527` in 2019 is `T1550.001` today, so a raw-ID series compares unlike things. Second, **granularity drift**: the same behaviour can be recorded at parent `T1550` or at `T1550.001` depending on how much the writer knew, so a shift toward parent-level mapping deflates the child with no change in behaviour. Third, you are counting **mappings** - labels people wrote - not adversary actions. And an application grant with a mail-read scope is also what a provider's engineer holds for ordinary reasons, so the identifier is not even purely adversarial. Normalise to one release, roll up to the coarsest common level, state the version, then compare.

go deeper

for a junior

Know that ATT&CK identifiers change between releases, so two years of technique numbers cannot simply be lined up and compared without checking which release each was written against.

for a middle

Explain the mechanics of each artefact: a revocation moves a count to a new number, a split scatters it across children, and parent-level recording deflates a child with no behaviour change.

for a senior

Walk the normalisation end to end - pin a release, migrate what resolves, roll up to the coarsest common level, mark the unresolvable - and then say what the surviving number actually measures.

for a principal

Own the expectation-setting with whoever wants the trend. The catalogue is a vocabulary revised twice a year, not a measurement instrument, and saying so is more valuable than producing a defensible-looking curve.

## The obvious reading, and why it fails Someone puts a chart in front of you: one crew, five years, ATT&CK technique identifiers, and `T1550.001` down thirty percent. The obvious reading is that the crew moved away from using application access tokens. Your job is to explain why that is the wrong first conclusion, and to say what would have to be true before it became the right one. ## Confounder 1: the catalogue moved ATT&CK ships roughly twice a year and identifiers move between releases: some are revoked and replaced, some are deprecated, and some parents split into sub-techniques. The July 2020 v7 release did this at scale when sub-techniques were introduced. The behaviour "use an application's access token" was `T1527` before that release and `T1550.001` after it. If the early years of the series were written against the older releases and are counted by raw identifier, then the series is not one time series - it is two, glued together at a release boundary. The tell is distinctive and easy to check: **a cliff in one number, dated at a release boundary, with one or several new numbers being born in the same period.** That signature is a split or a revocation, not adversary behaviour. Adversaries do not change tradecraft simultaneously on the day a catalogue ships. ## Confounder 2: granularity drift Even within one release, a behaviour can be recorded at two levels. Someone who knows only that alternate authentication material was used writes the parent, `T1550`. Someone who knows it was an application token writes `T1550.001`. Both are correct; the second is more specific. Now suppose the material available in later years is thinner, or the people writing the mappings are more cautious about asserting detail. The parent's count rises, the child's falls, and the underlying behaviour is unchanged. A drop in a sub-technique's count is therefore ambiguous between "less of it happened" and "we were less willing to say which kind it was". Rolling both parent and child together removes the ambiguity - and often removes the drop. ## Confounder 3: you are counting the wrong noun The series counts **mappings**, which are labels that people wrote. It does not count adversary actions. The number moves when the volume of published material moves, when the number of people producing it moves, when the depth of their access to the underlying material moves, and when the conventions they follow move. None of those is the crew. ## Confounder 4: the identifier is not purely adversarial This one is specific to the technique and it is the sharpest. `T1550.001` describes using an application's issued access token. In a SaaS tenant, the entirely ordinary case looks the same: a provider's engineer with delegated administration holds a consented application carrying a mail-read scope, and it reads mailboxes exactly as granted, every day, for five years. A technique names a behaviour, not intent or authorisation, so that ordinary activity sits under the same identifier as an adversary's. Any count over that identifier is a count over a mixture, and the mixture's composition can shift on its own - a provider onboarding, a consolidation of apps, a scope tidy-up - producing a movement in the number with no adversary anywhere in it. ## What you actually do 1. **Pin a release.** Choose one ATT&CK version as the frame for the whole comparison and say which one it is. 2. **Migrate what is mechanically resolvable.** Follow the published replacement pointers for revoked identifiers. Keep the original identifier alongside the migrated one; never overwrite the history. 3. **Roll up to the coarsest common level.** If part of the series predates sub-techniques, comparing at parent level is the only honest comparison. Do not push old parent references down into children - the detail was never recorded, and inventing it manufactures precision. 4. **Handle the unresolvable explicitly.** Deprecated identifiers have no successor; mark them rather than letting them fall out silently. 5. **State what the number is.** It is a count of mappings written against a stated release, over a stated body of material, including any ordinary activity that fits the same behaviour. After all that, if the drop persists, you have a real change in **what was mapped**. That is still not a change in behaviour: you must also rule out changes in who was writing, how deeply they could see, and how the mixture of ordinary and adversarial activity under that identifier shifted. Only then does "the crew changed" become the leading explanation - and by then it is a claim you can defend rather than a shape on a chart. ## The one-sentence version An ATT&CK identifier is a shared vocabulary revised twice a year, and it was never built to be the axis of a five-year time series; when the numbers move, ask what the catalogue did before you ask what the adversary did.

  • You normalise every year to one release and the drop survives. Is it real now?
    It is now a real change in what was mapped, which still is not a change in behaviour. Rule out shifts in who wrote the mappings, how deep their view of the underlying material was, and how much ordinary activity sits under the same identifier, before claiming the crew changed.
  • What is the fingerprint of a split, as opposed to a genuine decline?
    A split moves counts out of one number into several. Read raw, the parent looks like it collapsed while several new identifiers appear from nothing, and both events are dated at the same release boundary. A genuine decline is gradual and is not synchronised with a catalogue release.
  • Why does rolling up to parent level often make the drop disappear?
    Because parent and child are not competing behaviours - the child is a narrower way of doing the parent. If writers became less willing to assert which kind it was, volume shifts from child to parent with nothing changing underneath. Summing them removes the artefact.

saying these in an interview costs you the question

  • Reads a raw multi-release identifier series as behaviour change
  • Ignores the July 2020 restructure when comparing years
  • Treats parent and sub-technique counts as independent
  • Assumes every mapping under a technique is adversarial
  • Back-fills old parent references into guessed sub-techniques

context