Two ATT&CK mappings of the same intrusion write-up differ — is one of them wrong?
answer
- a claim about a document
- silence belongs to the author
- same intrusion, two accounts
- wrong means no sentence supports it
basics
~10 sNot necessarily. An ATT&CK mapping is a claim about the account you read, not about the intrusion itself. Two people differ mainly because they apply different rules to steps the author never wrote down.
solid answer
~50 sThe instinct is that a disagreement means somebody made a mistake, and that is usually the wrong call. A mapping asserts *this text describes behaviour matching these techniques* — it never asserts *the adversary did these things and nothing else*. So the honest first move is to ask what each mapping was made from. Different sources of the same intrusion produce different technique sets by construction. On one shared source, differences cluster on steps the author only implies, on prose that describes a condition rather than a behaviour, and on the framework version each person used. A mapping is genuinely wrong only when a row cannot be supported by any sentence in the source, when a behaviour is filed under a goal the text contradicts, or when an inferred step is presented as a stated one.
go deeper
Be ready to state the scope rule in one sentence: a mapping describes the account you read, not the intrusion. Then name two innocent reasons two mappings differ — different sources, and different handling of steps the author only implies.
Explain the mechanics behind each cause of divergence, including framework versioning and the difference between a described action and a described condition. Show that you know what a row must cite before it is defensible.
Demonstrate that you can run the diff productively: sort each divergent row into source, inference, behaviour-versus-condition or version, and identify the small residue that is a real fidelity error worth correcting.
Own the consequence: mappings from many hands get merged and compared, so unless source, version and inference marks travel with every mapping, the merged artefact quietly becomes a claim nobody can defend. Argue for what must be recorded and why.
## What a mapping actually is ATT&CK is a published catalogue of adversary behaviour. Tactics name the adversary's goal in a moment (Initial Access, Credential Access, Discovery); techniques carry `T####` identifiers and name a way of reaching that goal. Mapping is the act of reading an account of an intrusion — a vendor write-up, a conference talk, a blog post — and attaching identifiers to what it describes. That input is prose written by a human who chose what to say. So the output is a claim about that prose. This is the scope rule, and almost everything else follows from it: > A mapping asserts that **this account** describes behaviour matching these techniques. It does not assert that the adversary performed exactly these behaviours, nor that it performed no others. ## Why two mappings legitimately differ **1. They were made from different sources.** Two write-ups of one intrusion are written by people with different visibility, different word counts and different legal constraints. Mapping each faithfully must produce different sets. Neither mapper erred. **2. They apply different rules to implied steps.** Suppose an account says an operator got a shell inside a container and that, minutes later, that container's service account was listing every namespace in the cluster. It never says the mounted bearer token was read. One person credits Unsecured Credentials (`T1552`) because the API calls entail that *something* read the token; the other refuses, because the author never wrote it. Both positions are defensible. The disagreement is about a convention, not about a fact. **3. They judge differently what counts as behaviour.** Accounts contain conditions as well as actions: the pod ran as root, the token was mounted by default, the service was exposed to the internet. Conditions are properties of the target, not things the adversary did, and they have no technique. One mapper may reach for the nearest identifier anyway. **4. Framework drift.** ATT&CK is versioned. Techniques are added, renamed, retired and re-parented between releases — the 2020 release that introduced sub-techniques retired a set of older identifiers outright. Two mappings made a few years apart can carry different numbers for the same sentence. Record the version you mapped against; without it the diff is unreadable. ## What does make a mapping wrong The scope rule is not a licence to shrug. A mapping is defective when: - a row rests on no sentence — the mapper pattern-matched the adversary's reputation instead of the text; - a behaviour is filed under a goal the text contradicts (the account states the operator was enumerating hosts, and the row claims an Impact goal); - an identifier is attached to the victim's configuration rather than the adversary's action; - an inferred step is presented as an observed one, so a downstream reader cannot tell which rows the source actually supports. Note the shape of that list: all four are failures of fidelity **to the source**. None of them is "listed fewer techniques than the other person". ## Making a disagreement productive Diff the two mappings row by row and, for each row that appears in only one, ask which of the four causes above produced it. Require every row to cite the sentence it rests on; mark inferred rows explicitly; leave unmappable prose unmapped and say so. Once each mapping carries its source, its version and its inference marks, most disagreements resolve into "these are answers to different questions", and the small residue that remains is a real error worth fixing. ## The interview answer When an interviewer sets two conflicting mappings in front of you, they are testing whether you know what the artefact claims. The candidate who says "the six-technique one missed things" has quietly promoted a document into a description of reality. The candidate who asks "what was each one mapped from, and how did each treat the steps the author only implies?" has understood the model.
- What would you need alongside each mapping before the diff is even readable?Three things: the source each was made from, the ATT&CK version used, and a per-row citation back to the sentence it rests on, with inferred rows marked as inferred. Without the source you cannot tell a different-visibility difference from a different-judgment one; without the version you cannot tell a retired identifier from a missing behaviour; without citations you cannot tell a supported row from a reputational guess.
- Give an example of a difference that is a genuine error rather than a convention.A row asserting a behaviour no sentence in the source describes — for instance crediting a lateral-movement technique because the group is known for it, when the account only ever places the operator on one host. That is the mapper importing prior belief about the adversary into a claim about this text, and it cannot be defended by pointing at any line of the source.
- Both mappings are of the same source and identical except one is a year older. What do you check first?The framework version. Between releases, identifiers are added, renamed, retired and re-parented, so the same sentence can carry a different number in each. Re-express the older mapping against the newer release before concluding anything about judgment; often the whole disagreement disappears and what is left is one or two rows of real inference difference.
Two people summarising the same article will list different facts; a third summarising a different article about the same event will differ more. The summaries disagree; the event never changed.
saying these in an interview costs you the question
- Says the shorter mapping simply missed techniques
- Treats a mapping as a description of what happened
- Assumes disagreement means one mapper is unskilled
- Adds techniques for steps the account never mentions, unmarked
- Compares two mappings without asking what each was made from