Select a theme from the list.
Insights

From our experts

Latest
MITRE ATT&CK Splits Hiding From Blinding in Major Defensive Model ChangeParaShells Flaw Leaves Intel Mac Users Without a Confirmed Parallels FixWindows 11 Security Update Knocks Some Enterprise PCs Off Their DomainsTelegram-Controlled Windows Spyware Extends Iranian Surveillance Beyond National BordersRansomware Crews Turn VMware vCenter Flaw Into a Virtual Infrastructure CrisisCisco Email Gateways Face Root-Level Takeover Through Weaponized MessagesPhishing Study Finds Click Rates Are Hiding the Metrics That Actually MatterClaude Distillation Campaigns Turn AI Access Into an Industrial Data-Theft MarketCheck Point VPN Flaws Put Enterprise Gateways on an Urgent Patch ClockMicrosoft Maps the Hidden Attack Paths Connecting Serverless Apps to Cloud ControlBrevo Breach Turns Trusted Trezor Emails Into Wallet-Stealing PhishingCisco Firewall Manager Flaws Become Launchpads for Espionage and Qilin RansomwareMITRE ATT&CK Splits Hiding From Blinding in Major Defensive Model ChangeParaShells Flaw Leaves Intel Mac Users Without a Confirmed Parallels FixWindows 11 Security Update Knocks Some Enterprise PCs Off Their DomainsTelegram-Controlled Windows Spyware Extends Iranian Surveillance Beyond National BordersRansomware Crews Turn VMware vCenter Flaw Into a Virtual Infrastructure CrisisCisco Email Gateways Face Root-Level Takeover Through Weaponized MessagesPhishing Study Finds Click Rates Are Hiding the Metrics That Actually MatterClaude Distillation Campaigns Turn AI Access Into an Industrial Data-Theft MarketCheck Point VPN Flaws Put Enterprise Gateways on an Urgent Patch ClockMicrosoft Maps the Hidden Attack Paths Connecting Serverless Apps to Cloud ControlBrevo Breach Turns Trusted Trezor Emails Into Wallet-Stealing PhishingCisco Firewall Manager Flaws Become Launchpads for Espionage and Qilin Ransomware
Security Insight

MITRE ATT&CK Splits Hiding From Blinding in Major Defensive Model Change

MITRE ATT&CK Splits Hiding From Blinding in Major Defensive Model Change
Photo by Ann H on Pexels

The Enterprise MITRE ATT&CK matrix now contains 15 tactics after the former Defense Evasion category was divided into Stealth and Defense Impairment. The change gives defenders a clearer way to separate attackers who quietly conceal activity from those who actively disable logging, security tools or access controls.

News Date: 2026-09-14

The Enterprise MITRE ATT&CK matrix has expanded from 14 to 15 tactics, replacing the broad Defense Evasion category with two more precise concepts: Stealth and Defense Impairment. Sophos has published practical guidance explaining why the distinction matters for detection engineering, incident response and digital forensics.

Two Different Adversary Objectives

The former Defense Evasion category covered a wide range of behavior, from subtle concealment to the deliberate destruction of defensive visibility. Combining those actions under one heading made reporting convenient, but it could hide important differences in attacker intent and required response.

Stealth, identified as TA0005, describes attempts to blend into an environment or make malicious activity harder to recognize. Examples include masquerading as legitimate software, changing file timestamps, using alternate data streams, packing payloads and relying on trusted administrative tools.

Defense Impairment, identified as TA0112, covers actions that weaken the defender directly. Clearing Windows event logs, stopping endpoint protection, modifying firewall policies, tampering with Microsoft Defender settings or disabling cloud alerting rules all fall into this more aggressive category.

This separation is operationally useful. A stealthy attacker may leave faint but recoverable traces in file-system metadata, identity logs or command histories. An attacker impairing defenses may generate obvious configuration changes but quickly destroy the evidence investigators need. Each situation therefore demands different collection priorities and containment decisions.

Cloud and Identity Environments Also Matter

The distinction extends beyond endpoints. In Microsoft 365 or other cloud platforms, stealth may involve valid session tokens, carefully paced downloads or OAuth grants that resemble legitimate activity. Defense impairment may involve weakened conditional-access policies, muted alerts or altered audit configurations.

Actions for Security Teams

  • Reclassify detections previously mapped to Defense Evasion.
  • Update SIEM dashboards, threat-hunting queries and incident templates.
  • Measure coverage for Stealth and Defense Impairment separately.
  • Confirm that forensic collection survives attempts to disable local logging.
  • Protect cloud audit settings and security policies with privileged access controls.

In my view, this is more than a taxonomy adjustment. Security teams frequently measure whether they can detect malware while paying less attention to whether an attacker can disable that detection. Separating quiet concealment from active defensive sabotage should expose those blind spots. Organizations that merely rename their rules will gain little, while those that reassess telemetry, retention and response authority can turn the revised matrix into a meaningful improvement.

Talk to our team →

Latest

MITRE ATT&CK Splits Hiding From Blinding in Major Defensive Model ChangeSep 17, 2026ParaShells Flaw Leaves Intel Mac Users Without a Confirmed Parallels FixSep 17, 2026Windows 11 Security Update Knocks Some Enterprise PCs Off Their DomainsSep 17, 2026Telegram-Controlled Windows Spyware Extends Iranian Surveillance Beyond National BordersSep 16, 2026Ransomware Crews Turn VMware vCenter Flaw Into a Virtual Infrastructure CrisisSep 16, 2026Cisco Email Gateways Face Root-Level Takeover Through Weaponized MessagesSep 16, 2026

Most read

1Microsoft Redraws the Security Boundary for Edge AI2Ted Implant Turns Compromised HAProxy Servers Into Invisible Interception Points3French Hospital Fine Turns Weak Identity Controls Into a GDPR Warning4IDScan Lawsuits Put Mass Identity Collection Under the Microscope5Microsoft Brings Agentic Vulnerability Hunting Into Azure Government6Scattered Spider's Cyberattack on Marks & Spencer Exposes Retail Vulnerabilities