skip to content

Your remediation list blocks command lines one by one — how do you state ATT&CK technique risk to the owner?

level: principalimportance: nice to knowfreq 28%

answer

  1. Two lines, not one
  2. Price the interim in adversary time
  3. Name the removal, not the identifier
  4. Owners can refuse; capture the acceptance
  5. Never close a class with values

basics

~20 s

State the claim in the adversary's currency: say which procedures are closed, what respelling costs the operator, and that the technique class remains open. Never let a procedure-shaped item close a technique-shaped one, even under schedule pressure.

solid answer

~50 s

The list is real work, so ship it - but write it at the level it actually delivers. Each blocked command line closes one matchable value; the technique above it stays open until something the class cannot substitute is removed. So I would report two lines, not one: procedures closed, with the operator's respell cost measured in minutes, and technique open, residual accepted until the capability removal lands. The durable option here breaks builds for teams who can refuse it, so take the class-level change to them named by what it removes rather than by a T-number, and put a date on the residual. Where the owner will not accept it, the outcome is an explicitly accepted risk with the class named - not a closed item. What I am guarding against is a plan that reads as technique coverage and is made of strings.

go deeper

for a junior

Understand the shape of the mistake: a list of blocked commands is real work, but it is not the same promise as saying a technique is handled. Do not let the two be written as one line.

for a middle

Be able to explain to a non-specialist why the class remains open after the values are blocked, using what the technique depends on rather than jargon or identifiers.

for a senior

Show you would report both lines and price the interim by the adversary's replacement cost, and that you know which capability removal would let you close the class-level item honestly.

for a principal

Own the negotiation and the residual. Take the durable change to the owner named by what it removes, refuse the trade of a longer value list for the capability change, and put a name and a date on anything accepted rather than closed.

## The situation Work has been done: several observed command lines on the CI runners are now blocked. The list is being read one level up as *that technique is handled*, and the schedule assumes the item is closing. You have to say what is true without discarding real work, and without a durable fix you can ship this quarter. ## Why this is a leadership problem and not a wording problem A procedure-shaped item and a technique-shaped item are different sizes of commitment, and only one of them is checkable. *We blocked these five values* is verifiable and finite. *`T1059.004` is handled* is a claim about an unbounded class. If those two are allowed to occupy the same row in a plan, then the plan's remaining rows are also unreliable — the reader has no way to know which kind of promise each one is. That is why the correction has to be made at the plan level and once, rather than being argued per item forever. ## What to actually say Write the claim in the adversary's currency, because that is the only unit that means the same thing to a technical reader and a risk owner: - **What is closed.** These specific values no longer run. Anything automated that hard-codes them fails, and an operator working from someone else's script is stopped. - **What it cost them.** The operator holds standing privilege on the runner. Respelling — a wrapper script, a different parent, commands from an environment variable — needs no new access, no purchase and a few minutes. Say the number out loud; a control priced at *minutes of an afternoon* is described honestly the moment you say so. - **What remains open.** The class needs a shell reachable in the job context and something able to feed it operator-supplied input. Until one of those is gone, the class is available. - **Who can close it, and what it costs them.** The capability removal breaks builds for teams who own those pipelines. They can refuse. That makes it a negotiation with a named owner, not an engineering task waiting in a queue. ## Negotiating the durable change Take it to the owner named by what it removes, never by its identifier. *We want the job context to have no shell an operator can reach* is a sentence a platform team can argue with, cost and counter-propose against. *We need `T1059.004` coverage* is not — it invites the answer *fine, block more strings*, which is how the estate got here. Expect a counter-offer: a narrower change, a subset of pipelines, a phased date. Those are good outcomes. What is not acceptable is trading the class-level change for a longer list of values, because that trade converts a durable control into more of the thing you already agreed was priced in minutes. ## When the answer is no Sometimes the builds matter more this quarter, and the owner refuses. That is a legitimate outcome and it has a specific written form: the class stays open, the residual is stated in terms of what an adversary with runner privilege can still do, an owner's name is on the acceptance, and it has a review date. It does **not** become a closed item because the sub-items under it are done. A risk accepted with its class named is a manageable position; a risk closed by string-counting is an estate that believes something false. ## The failure this prevents An organisation whose plan is written in procedure-shaped rows accumulates a long list of true statements and one false conclusion. The list grows, every entry is defensible, and the class it was supposed to address is exactly as available as it was on day one — because nothing was ever removed that an operator could not substitute. Being the person who insists on the two-line report is unglamorous and it is the whole job. ## Saying it cleanly *Five procedures closed, respell cost to the operator measured in minutes; technique open. Closing the class means the job context has no reachable shell, which breaks three teams' builds — so it is their call, with a date, and until then this is an accepted residual with my name on it, not a closed row.*

  • How do you price an interim procedure-shaped control so the number means something?
    By the adversary's replacement cost, not by your effort. Ask what the operator needs in order to respell: new access, new tooling, money, time. Here it is none, none, none and a few minutes, so the control is worth stating as friction with a short shelf life. The same block would be worth far more against someone who first has to regain execution.
  • The teams who own the runners will not accept a change that breaks builds. How do you close the item?
    You do not close it. You convert it into an accepted residual: the class stated in terms of what an adversary with runner privilege can still do, the named owner who accepted it, and a review date. Closure requires removal; acceptance requires a name and a date. Recording the second as if it were the first is the actual defect.
  • Why not simply report progress as a percentage of the technique addressed?
    Because the denominator does not exist. A technique is an unbounded class of implementations, so a fraction of it closed is not a measurable quantity, and any percentage is really a percentage of what you happened to observe. Report what was removed and what the adversary must give up — both of those are checkable.

saying these in an interview costs you the question

  • Closes a technique-level item using blocked-string counts
  • Reports a percentage of a technique addressed
  • Takes the durable change to owners named by T-number
  • Accepts a longer value list instead of the capability removal
  • Leaves a refused change with no owner and no date

context