A step in an intrusion write-up has no matching ATT&CK technique — what do you do?
answer
- not every sentence has a T-number
- conditions are not behaviours
- a declared gap is information
- the nearest fit is still a claim
basics
~20 sLeave it unmapped and say so. ATT&CK catalogues adversary behaviour, so much of any account — conditions, motive, business context, the author's speculation — carries no identifier. Forcing the nearest one asserts a behaviour the source never describes.
solid answer
~50 sNot every sentence earns a `T####`, and a mapping that covers every paragraph is a warning sign rather than a thorough one. ATT&CK names things an adversary *does* against systems on covered platforms. An account also contains conditions of the target — the pod ran as root, the bearer token was mounted by default, the service faced the internet — which are properties of the environment, not actions; those belong in a control-class or weakness statement, never in a technique row. It contains motive, attribution and business impact, none of which are behaviours. And it contains speculation the author flagged as such. Leave all of it unmapped, and record that you did: a stated gap is information, whereas the nearest-fit identifier is a claim about behaviour that no sentence supports and that travels onward once somebody copies your list.
go deeper
Remember that ATT&CK names what an adversary did, so parts of any account simply have no identifier. Leaving prose unmapped is normal and expected; inventing a near-fit row is not.
Be ready to sort a passage into behaviour, condition, motive or speculation on the spot, and to say which vocabulary owns each — a weakness class and a control class for conditions, a technique only for actions.
Explain the downstream damage of forced rows: unfalsifiable claims, diffs that measure habits instead of sources, and near-fit identifiers becoming indistinguishable from supported ones once copied. Argue for declared gaps instead.
Own the standard: unmapped passages are recorded with a reason, proportion mapped is never a quality measure, and recurring gaps are raised with the framework's maintainers rather than patched locally with near misses.
## The pull towards full coverage Mapping feels like a completion exercise: read the account, attach identifiers, be thorough. That instinct produces the most common defect in the craft — forcing the nearest available technique onto prose that describes something ATT&CK does not model. Ask what the catalogue is for. ATT&CK enumerates **behaviours an adversary performs** against systems on platforms it covers, grouped by the goal those behaviours serve. That is a narrow target compared with what a write-up contains. ## What routinely has no identifier **Conditions of the target.** "The pod ran as root and the service-account token was mounted by default." Nothing was done here by anybody; this is how the environment stood before the operator arrived. Conditions are the province of weakness and configuration vocabularies — a CWE-style weakness class, a CVE record when a specific product version is at fault, a control-class statement about what should have removed it — and of none of them is a technique identifier a substitute. **Motive, attribution and consequence.** "The crew appears financially motivated." "The company disclosed three weeks later." "Two hundred customers were affected." These are claims about people and outcomes, not behaviours. **The author's own speculation.** If the write-up says the operator *probably* pivoted, the text has offered you a possibility, and a technique row would convert it into a described behaviour. **Behaviour on ground the catalogue does not cover.** Coverage is platform-scoped and evolves; something performed against a system outside the covered platforms may have no home, even though it plainly happened. **Steps too coarse or too specific to name.** "They spent two days poking around" describes duration and effort, not a technique. Conversely a fully idiosyncratic action may simply have no entry. ## Why forcing an identifier is worse than a gap A row is a claim: *this account describes behaviour matching this technique*. Attach one to a sentence that cannot support it and you have manufactured that claim. Three consequences follow. First, it is unfalsifiable to the next reader, who sees an identifier and not the sentence. Second, it contaminates comparison: if you and somebody else both map the same intrusion and one of you forced rows, the diff between your mappings now measures your habits rather than the sources. Third, the claim travels — mappings get copied into summaries and profiles, and the nearest-fit row is indistinguishable from a well-supported one once it moves. A declared gap has none of those properties. "Paragraphs 4–6 describe the target's configuration and carry no technique" is a precise, checkable statement. ## The convention 1. Map behaviour; leave everything else unmapped. 2. Record *why* a passage is unmapped when the reason is interesting — condition, motive, out of scope, speculation. This is cheap and it pre-empts the reviewer who asks whether you simply missed it. 3. If the same behaviour keeps recurring across accounts with no home in the catalogue, that is worth raising with the framework's maintainers as a gap rather than papering over locally with a near-miss. 4. Never treat the proportion of an account that carries identifiers as a quality measure of the mapping. It is a property of the account. ## The distinction that makes it click ATT&CK names **what an adversary did**. CWE names **the kind of weakness that let them**. CVE names **a specific vulnerable product**. A control class names **what would have removed the opportunity**. A sentence about a default-mounted token is a weakness-and-control sentence; giving it a technique number does not make it a behaviour, it only makes your mapping wrong in a way that is hard to see later.
- Give a concrete sentence from a container write-up that has no technique, and say what does describe it."The pod ran as root and the service-account token was mounted by default." No adversary did anything in that sentence — it states how the environment stood. It is a weakness-and-control statement: a CWE-style weakness class describes the kind of flaw, and the control class that removes it is the fix. A technique row there would assert behaviour the source never describes.
- Is a mapping that covers most of an account better than one that covers a third of it?Not by itself. The proportion is a property of the account: a behaviour-dense technical write-up maps heavily, while a narrative piece with business context and motive maps thinly and correctly. Reading a high proportion as quality rewards exactly the forcing habit you want to prevent, and it makes two mappings of different sources look comparable when they are not.
saying these in an interview costs you the question
- Forces the nearest technique so nothing is left unmapped
- Gives the victim's configuration a technique identifier
- Maps motive or attribution as adversary behaviour
- Treats percentage of the account mapped as a quality score
- Converts the author's speculation into a stated behaviour