Search papers, labs, and topics across Lattice.
This paper conducts a comprehensive analysis of 1,214 cyber threat records in healthcare from 2017 to 2024, revealing a significant shift in attacker behavior towards stealth-oriented tactics, particularly defense evasion. The study highlights that while persistence and initial access tactics have declined to zero, defense evasion consistently accounted for 15-20% of techniques used, indicating a misalignment in existing detection guidance. By linking 679 exploited vulnerabilities to a dominant behavioral technique, the authors identify 42 high-priority detection opportunities that directly address emerging threats to AI-integrated clinical systems.
Stealth tactics dominate healthcare cyber threats, with defense evasion accounting for 15-20% of techniques, while traditional detection methods fail to keep pace.
Healthcare systems face persistent and evolving cyber threats, yet how adversarial tactics and techniques have shifted over time has not been systematically characterised using empirical, multi-source data. This paper analyses 1,214 threat records drawn from three authoritative sources: the MITRE ATT&CK behavioural framework, the CISA Known Exploited Vulnerabilities catalogue, and the NIST vulnerability database, covering 44 validated healthcare-targeting threat entities from 2017 to 2024. We show that attacker behaviour has shifted measurably toward stealth-oriented tactics: defense evasion remained the dominant tactic throughout the observation period, consistently accounting for 15-20% of observed technique use from 2017 to 2024, while persistence declined from 11.2% to zero and initial access from 9.0% to zero over the same period. We further demonstrate that existing detection guidance is structurally misaligned with where attacker effort is concentrated, with the least-covered techniques receiving the most adversarial attention. A convergence analysis links 679 confirmed exploited vulnerabilities to a single dominant behavioural technique, identifying a common addressable chokepoint across the vulnerability and behavioural surfaces. Finally, we identify 42 high-priority techniques representing immediate detection opportunities and show that this set of techniques maps directly to emerging threats against AI-integrated clinical systems.