Program



Track A(Hall D)
2026.8.11 16:20 ~ 17:00
mail share facebook share twitter share linkedin share band share kakao
Advancing EDR-NDR Detection Through Behavior Rules and MITRE ATT&CK Evaluation-A Practical Journey

NPCore Dongjin Kim Technical support


To preemptively counter advanced threats, organizations are adopting MITRE ATT&CK-based behavioral analysis and proven detection rules at scale. This session presents an architecture that fuses EDR and NDR telemetry with over 20,000 behavioral detection rules from a global threat detection platform, enabling real-time rule deployment and continuous coverage. We share practical insights gained from preparing for the MITRE ATT&CK Evaluation, including R1 testing, and demonstrate how precisely mapping behavioral rules to EDR/NDR logs eliminates detection blind spots and maximizes reliability.