Frameworks / MITRE ATT&CK / MITRE-ATTACK-Detection-Data-Sources-Analytics-Sigma-Splunk-KQL-Yara-Snort-SIEM-Hunt-Engineering MITRE ATT&CK
Detection Engineering and Data Sources - MITRE ATT&CK
MITRE ATT&CK MITRE-ATTACK-Detection-Data-Sources-Analytics-Sigma-Splunk-KQL-Yara-Snort-SIEM-Hunt-Engineering: MITRE ATT&CK Detection + Data Sources + Analytics + Sigma + SPL + KQL + Yara + Snort + SIEM + Hunt Implement detection engineering and threat hunting using ATT&CK Data Sources and detection content. Each technique includes Detection guidance + Data Sources required + analytic queries. Data Sources (DS-IDs) provide categorisation of logs and telemetry: DS0009 Process + DS0017 Command Execution + DS0029 Network Traffic + DS0011 Module + DS0016 Drive + DS0022 File + DS0033 Network Share + others. v16 (October 2024) introduced structured detection content with analytic platforms metadata. Detection content includes vendor-agnostic Sigma rules + platform-specific SIEM query languages (SPL, KQL, YARA-L, Elasticsearch DSL) + Yara malware signatures + Snort/Suricata network rules. Integration with SIEM and EDR platforms. Threat hunt loops using ATT&CK Navigator gap analysis. Detection coverage reporting per technique + per platform + per data source. CALDERA automated adversary emulation. Pyramid of Pain (David Bianco) for detection sophistication.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 158 controls across 50 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASD37-06 Email content filtering (Excellent) ASD37-12 Antivirus software with heuristics (Very Good) ASD37-16 Antivirus software with signatures (Limited) ASD37-20 Multi-factor authentication (Essential) ASD37-22 Network segmentation (Excellent) ASD37-25 Software firewall - inbound (Very Good) ASD37-34 Regular backups (Essential) ASD37-35 Business continuity and disaster recovery plans (Very Good) ASD37-36 System recovery capabilities (Very Good) API1164-12 Incident Response API1164-13 Business Continuity and Recovery API1164-17 Wireless and Field Communications API1164-18 Field Device Security API1164-19 Safety Instrumented Systems Interface IEC62443-12 Malware prevention for operational systems IEC62443-13 Network security monitoring IEC62443-16 Incident response plan for operational disruptions IEC62443-17 Recovery plan for critical systems IEC62443-20 Exercises and drills for OT incidents 27011-6.3 Awareness and Training 27011-8.2 Network security and segregation 27011-8.4 Logging and monitoring 27011-8.5 Vulnerability and malware management 27011-8.6 Data protection and backup ISO27019-12 Malware prevention for operational systems ISO27019-13 Network security monitoring ISO27019-16 Incident response plan for operational disruptions ISO27019-18 Reporting obligations to authorities ISO27019-20 Exercises and drills for OT incidents ISO27043-22 Protection from malware ISO27043-23 Backup and recovery procedures ISO27043-24 Logging and monitoring ISO27043-25 Technical vulnerability management ISO27043-27 Network security management ISO21434-22 Protection from malware ISO21434-23 Backup and recovery procedures ISO21434-24 Logging and monitoring ISO21434-25 Technical vulnerability management ISO21434-27 Network security management ISMSP-AC-04 Network Access Control ISMSP-PI-06 Personal Information Destruction ISMSP-SYS-03 Security Monitoring and Log Management ISMSP-SYS-04 Vulnerability Management ISMSP-SYS-06 Business Continuity and Disaster Recovery BSI-14 Vulnerability scanning and management BSI-28 Audit event logging and storage BSI-29 Audit record review and analysis BSI-31 Audit log protection and retention IM8-RES.2 Disaster Recovery IM8-RES.4 Resilience Testing IM8-SEC.3 Network Security IM8-SEC.4 Vulnerability Management AWWA-3.1 Network Segmentation AWWA-4.1 Malware Protection AWWA-4.4 Audit Logging and Monitoring CPG-1.D Revoking Credentials for Departing Employees CPG-5.A Vulnerability Disclosure Program CPG-8.A Network Segmentation CAT-D3-1 Preventative controls CAT-D3-2 Detective controls CAT-D3-3 Corrective controls 27031-8.1 Exercising and Testing 27031-8.2 Maintaining IRBC 27031-9.3 Management Review 30111-1 Scope 30111-3 Terms and definitions 30111-8.1 Post-release monitoring FFIEC-06 Network security and segmentation FFIEC-12 Disaster recovery procedures FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g)) ISO22316-08 Recovery time and point objectives ISO22316-12 Recovery strategy for critical activities 27010-12.2 Protection from malware 27010-13.1 Communications Security 29147-5.6 Advisory Content and Quality 29147-7.8 Remediation information ISO22317-08 Recovery time and point objectives ISO22317-12 Recovery strategy for critical activities ISO22318-08 Recovery time and point objectives ISO22318-12 Recovery strategy for critical activities MAS-TRM-Project-SDLC-Service-Management-Chapters-4-5-6-IT-Project-Software-Lifecycle-Change-ITIL MAS TRM Project + SDLC + Service Management + Chapters 4-6 + IT Project + Software Lifecycle + ITIL MAS-TRM-Reliability-Data-Centre-Chapters-7-8-RTO-RPO-BCP-DR-System-Availability-4-Hours-12-Months MAS TRM Reliability + Data Centre + Chapters 7-8 + RTO + RPO + BCP + DR + System Availability 4 Hours 12 Months NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities NISTSP34-4 Information System Contingency Plan (ISCP) Development DSOMM-1 Culture, Organization, Education, and Governance DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management 4.4.8 Business Continuity and Recovery DIQ-1 Data Integration and Interoperability CJIS-10 System and Information Integrity FEDRAMP-CP-9 System Backup 62351-14 Cyber security event logging ISO-22320-5.2 Incident management process ISO27799-05 Audit trail for ePHI access ISO28001-PS-01 Facility Security ISO-25012-4.11 Traceability 29134-9.2 Report findings and recommendations NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights CPSC-CS.1 Network Security for Connected Products USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR) CYB-5 Cyber Incident Response Plan Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Query this from an agent The graph holds this control, the 158 it maps to, and the evidence behind each claim, over MCP and REST.