skip to content

Two accounts of the same intrusion map to 6 and 19 ATT&CK techniques — what does the gap measure?

level: seniorimportance: nice to knowfreq 29%

answer

  1. counts measure pages, not adversaries
  2. normalise the source before comparing
  3. shorter account, not smaller intrusion
  4. compare attested behaviours and shape

basics

~20 s

It measures the accounts, not the intrusion: how much each author could see, how much they chose to write, how far each mapper inferred, and how much of each text was behaviour at all. It says nothing about adversary sophistication.

solid answer

~50 s

The obvious reading — the shorter account missed things, or their side of the estate was hit less hard — promotes a document into a description of reality. A technique count is a function of four properties of the source and the mapping: the author's visibility, their word count and disclosure limits, the mapper's inference policy, and the share of the text that describes behaviour rather than conditions or motive. To compare two intrusions at all you must first normalise the source — compare accounts of similar depth, or compare only the behaviours both texts attest to — and state the framework version and inference rule on each side. Then compare which goals appear and in what order, not totals. If somebody asks which adversary is more advanced from the counts, the honest answer is that the diary is longer, not the expedition.

go deeper

for a junior

Know that the number of techniques in a mapping comes from how much was written, not how much the adversary did, so two accounts of one intrusion can produce very different totals with neither being wrong.

for a middle

Be able to name the four inputs to a count — visibility, word count, inference policy and behaviour density — and explain why none of them is a property of the adversary.

for a senior

Show how you would make a comparison defensible: fix source, version and inference rule, compare the behaviours both texts attest to, and read shape and absences rather than totals.

for a principal

Own how these numbers get quoted upward. A scalar detaches from its caveats faster than anything else here, so decide what may be published as a count at all and insist a comparison names its sources whenever it leaves your hands.

## The claim hidden in a number Counting rows feels safe. Two accounts of one intrusion, one carrying six identifiers and the other nineteen, and the temptation is immediate: the second describes a deeper intrusion, or a more capable adversary, or a more thorough author. Only the last of those is even in the right category. A technique count is an output of the mapping process, and the mapping process takes prose as input. So a count measures properties of the prose and of the mapper: - **Visibility.** What could the author observe at all? Somebody writing from inside the affected estate has ground truth an outside commentator does not. - **Word count and constraint.** Long technical write-ups map heavily. Short notices, and anything written under legal or contractual limits, are thin on purpose. - **Inference policy.** A mapper who credits entailed-but-unstated steps produces more rows from the same text than one who refuses them. Neither is wrong; the counts are not comparable. - **Behaviour density.** A narrative account rich in business context, motive and consequence maps thinly and correctly, because those passages carry no identifiers. None of those four is a property of the adversary. ## The sophistication trap The strongest version of the error appears when adversaries rather than intrusions are compared: *this group uses thirty-four techniques and that one twelve, so the first is more advanced.* Profiles assembled from public writing are profiles of the writing. A heavily-covered group accumulates rows because many people published about it; a group that operates quietly, or against victims who never publish, accumulates few. Sophistication is not row count in any case — an operator who reaches their objective with three well-chosen steps is not less capable than one who flails through twenty. ## Making a comparison that survives scrutiny If you must compare, normalise before you count: 1. **Fix the source.** Compare two mappings of *the same* account, or two accounts written from comparable visibility. Comparing an insider write-up with an outside commentary measures the authors. 2. **Fix the framework version.** Identifiers are added, retired and re-parented between releases, so counts drift on their own. 3. **Fix the inference rule.** Either both sides credit entailed steps with marks, or neither does. 4. **Compare shape, not totals.** Which goals appear, in what order, and which are conspicuously absent tells you far more than a scalar. A narrative that reaches an objective with no persistence step is a real, interesting statement; a count of six is not. 5. **Compare only attested behaviours.** The intersection both texts support is a defensible basis; the union is a wish list. ## Answering the person who asked Someone senior will eventually put the two numbers in front of you and ask whether the shorter account means less happened. The answer that holds up is: "Those numbers describe the two write-ups. One author had more to say and more freedom to say it. To say anything about the intrusion itself I need to compare the behaviours both accounts actually attest to, and to know how far each mapping inferred beyond what was written." That answer is not evasive — it is the only one that does not silently convert a document into reality. And it usually leads somewhere better, because the follow-up question, *which behaviours does the longer account describe that the shorter one does not, and is that a difference in what happened or in what was written down*, is answerable. ## The general rule Every number derived from a mapping inherits the mapping's scope. Counts, proportions and overlap percentages are all statements about accounts. Say so out loud whenever one is quoted, because a scalar detaches from its caveats faster than any other artefact in this domain.

  • Someone builds an adversary profile from every public write-up about a group. What is it a profile of?
    Of the public writing about that group. Groups that hit victims who publish, or that draw research attention, accumulate rows; quiet operators against victims who never write accumulate few. The profile is still useful — it tells you what has been described — but it must be quoted as what has been written about, never as the group's full repertoire or its ceiling.
  • What comparison between two accounts of one intrusion is actually defensible?
    The behaviours both texts attest to, plus the shape of each narrative: which goals appear, in what order, and which are absent. Fix the framework version and the inference rule on both sides first. An absence with a reason — an objective reached with no persistence step described — carries real information, where the difference between six and nineteen carries almost none.
  • Two mappers map the same account and produce 11 and 17 rows. Is that the same problem?
    No, and it is the easier one, because the source is fixed. The difference must come from inference policy, from judgment about what counts as behaviour rather than condition, or from framework version. Diff the rows and each divergence sorts into one of those; what is left is a genuine fidelity error. Counts across different sources cannot be reduced that way.

Ranking two expeditions by the page count of their diaries tells you who liked writing, not who climbed higher.

saying these in an interview costs you the question

  • Reads a higher technique count as a more advanced adversary
  • Concludes the shorter account's author missed things
  • Compares counts across accounts of different depth
  • Treats a public-reporting profile as an adversary's full repertoire
  • Quotes an overlap percentage without naming the sources

context