Attack Ent T1679 Selective Exclusion

Analyze MITRE ATT&CK T1679 Selective Exclusion in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1679, Selective Exclusion, or enterprise ATT&CK. Adversaries may intentionally exclude certain files, folders, directories, file types, or system components from encryption or tampering during a ransomware or malicious payload execution.

santosomar Updated

File contents

santosomar/mitre-attack-agent-skills/tree/main/enterprise/attack-ent-t1679-selective-exclusion commit b176c604f2

Frequently asked questions

npx skillmds@latest add santosomar/attack-ent-t1679-selective-exclusion