Skip to content

Latest commit

 

History

62 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

MITRE ATT&CK Coverage Analysis

This document maps the detection rules currently covered by the Sentryfy project and the targeted techniques against the MITRE ATT&CK framework. It is maintained to transparently show the progress of detection engineering work and the scope of the portfolio.


Legend:

  • ✅ Covered — rule written and tested in lab
  • ⏳ Planned — on the roadmap, coming later

TA0001 — Initial Access

Status Technique ID Technique Name SPL File KQL File
✅ T1566 Phishing Phishing SPL Phishing KQL
✅ T1190 Exploit Public-Facing Application Exploit Public App SPL
✅ T1200 Hardware Additions (BadUSB / HID) Hardware Additions SPL
✅ T1078 Valid Accounts (login anomaly) Valid Accounts
⏳ T1133 External Remote Services (RDP) planned
⏳ T1195 Supply Chain Compromise planned
⏳ T1199 Trusted Relationship planned

TA0002 — Execution

Status Technique ID Technique Name SPL File KQL File
✅ T1059.003 Windows Command Shell (cmd.exe) Windows Command Shell SPL
✅ T1204.002 User Execution: Malicious File Malicious File SPL
⏳ T1059.005 Visual Basic (wscript / cscript) planned
⏳ T1059.007 JavaScript planned
⏳ T1047 Windows Management Instrumentation (WMI) planned
⏳ T1218.010 Regsvr32 (Squiblydoo) planned
⏳ T1218.011 Rundll32 abuse planned
⏳ T1203 Exploitation for Client Execution planned

TA0003 — Persistence

Status Technique ID Technique Name SPL File KQL File
✅ T1098 Account Manipulation Account Manipulation
✅ T1053.005 Scheduled Task Scheduled Task SPL
✅ T1176 Browser Extensions Browser Extensions
✅ T1547.001 Registry Run Keys / Startup Folder Registry Run Keys SPL
⏳ T1543.003 Windows Service planned
⏳ T1136 Local Account Creation planned
⏳ T1546.003 WMI Event Subscription planned
⏳ T1546.008 Accessibility Features (sethc / utilman) planned
⏳ T1505.003 Web Shell planned

TA0004 — Privilege Escalation

Status Technique ID Technique Name SPL File KQL File
✅ T1055.002 Process Injection: Remote Thread (DLL Injection) DLL Injection SPL DLL Injection KQL
✅ T1055.012 Process Injection: Process Hollowing Process Hollowing SPL Process Hollowing KQL
✅ T1055.004 Process Injection: APC + Thread Hijacking Threadless SPL Threadless KQL
✅ T1068 Exploitation for Privilege Escalation (BYOVD) BYOVD SPL
✅ T1548.002 Bypass User Account Control (fodhelper) Bypass UAC SPL
⏳ T1134.001 Access Token Manipulation: Token Impersonation planned
⏳ T1055.003 Thread Execution Hijacking planned
⏳ T1574.002 DLL Side-Loading planned

TA0005 — Defense Evasion

Status Technique ID Technique Name SPL File KQL File
✅ T1562.001 Disable or Modify Tools (Windows Defender) Defense Tool Termination SPL
✅ T1218.005 Mshta abuse Mshta Abuse SPL
⏳ T1036.008 Masquerading: Masquerade File Type planned
⏳ T1036.003 Process Masquerading planned
⏳ T1134.004 Parent PID Spoofing planned
⏳ T1070.001 Clear Windows Event Logs planned
⏳ T1027 Obfuscated Files (base64, encoded commands) planned
⏳ T1140 Deobfuscate / Decode Files or Information planned
⏳ T1112 Modify Registry planned
⏳ T1070.004 File Deletion planned
⏳ T1497 Virtualization / Sandbox Evasion planned
⏳ T1564.001 Hidden Files and Directories planned

TA0006 — Credential Access

Status Technique ID Technique Name SPL File KQL File
✅ T1110 Brute Force Brute Force SPL Brute Force KQL
✅ T1110.003 Password Spraying Password Spraying SPL Password Spraying KQL
✅ T1003.001 OS Credential Dumping: LSASS Memory LSASS Memory SPL
⏳ T1555 Credentials from Password Stores (browsers) planned
⏳ T1558.003 Kerberoasting planned
⏳ T1552.001 Unsecured Credentials in Files planned

TA0007 — Discovery

Status Technique ID Technique Name SPL File KQL File
⏳ T1087.001 Account Discovery: Local Account planned
⏳ T1018 Remote System Discovery planned
⏳ T1082 System Information Discovery planned
⏳ T1016 System Network Configuration Discovery planned

TA0008 — Lateral Movement

Status Technique ID Technique Name SPL File KQL File
⏳ T1021.002 Remote Services: SMB/Windows Admin Share planned
⏳ T1570 Lateral Tool Transfer planned

TA0011 — Command and Control

Status Technique ID Technique Name SPL File KQL File
⏳ T1219 Remote Access Tools planned
⏳ T1071.004 Application Layer Protocol: DNS Tunneling planned
⏳ T1071.004 + T1048.003 DNS Tunneling planned
⏳ T1572 Protocol Tunneling planned

🔬 Test Environment

All rules are written and tested in the following environment:

  • OS: Windows 11
  • EDR/Telemetry: Sysmon (config: SwiftOnSecurity baseline + custom additions) + Windows Event Logs
  • SIEM: Splunk Developer License (Free license, lab use) + Microsoft Sentinel (free trial, lab use)

About

Detection engineering lab: MITRE ATT&CK detections built and validated on real telemetry across Splunk (RBA) and Microsoft Sentinel (KQL), with writeups.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages