Atomic Red Team testing cycle
In line with the threat hunting cycle, Red Canary has the Atomic Red Team Testing Cycle. First you choose the technique (or the permutation of a technique) you want to test for and execute the test. Always start for places in which you know you have the strongest visibility. Then, verify if you have detected the technique. In case you didn’t, you have to ask yourself if you are collecting data from the right data sources. In the case you are, you may need to refine the collection process. But if you are not, then you should establish the right collection process and make sure you are gathering the data from the right data sources. Finally, the process starts all over again:

Important note
When carrying out this type of test, do it first in your lab environment. Make sure not to run any test in a production environment without the right permissions and, most of all, make sure that you are not running anything...