MITRE ATT&CK
Detection Engineering and Data Sources - MITRE ATT&CK

MITRE ATT&CK MITRE-ATTACK-Detection-Data-Sources-Analytics-Sigma-Splunk-KQL-Yara-Snort-SIEM-Hunt-Engineering: MITRE ATT&CK Detection + Data Sources + Analytics + Sigma + SPL + KQL + Yara + Snort + SIEM + Hunt

Implement detection engineering and threat hunting using ATT&CK Data Sources and detection content. Each technique includes Detection guidance + Data Sources required + analytic queries. Data Sources (DS-IDs) provide categorisation of logs and telemetry: DS0009 Process + DS0017 Command Execution + DS0029 Network Traffic + DS0011 Module + DS0016 Drive + DS0022 File + DS0033 Network Share + others. v16 (October 2024) introduced structured detection content with analytic platforms metadata. Detection content includes vendor-agnostic Sigma rules + platform-specific SIEM query languages (SPL, KQL, YARA-L, Elasticsearch DSL) + Yara malware signatures + Snort/Suricata network rules. Integration with SIEM and EDR platforms. Threat hunt loops using ATT&CK Navigator gap analysis. Detection coverage reporting per technique + per platform + per data source. CALDERA automated adversary emulation. Pyramid of Pain (David Bianco) for detection sophistication.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 158 controls across 50 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-06 Email content filtering (Excellent)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-25 Software firewall - inbound (Very Good)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

API 1164 · 5 controls

  • API1164-12 Incident Response
  • API1164-13 Business Continuity and Recovery
  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface

IEC 62443 · 5 controls

  • IEC62443-12 Malware prevention for operational systems
  • IEC62443-13 Network security monitoring
  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents

ISO/IEC 27011:2024 · 5 controls

  • 27011-6.3 Awareness and Training
  • 27011-8.2 Network security and segregation
  • 27011-8.4 Logging and monitoring
  • 27011-8.5 Vulnerability and malware management
  • 27011-8.6 Data protection and backup

ISO/IEC 27019:2024 · 5 controls

  • ISO27019-12 Malware prevention for operational systems
  • ISO27019-13 Network security monitoring
  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents

ISO/IEC 27043:2015 · 5 controls

  • ISO27043-22 Protection from malware
  • ISO27043-23 Backup and recovery procedures
  • ISO27043-24 Logging and monitoring
  • ISO27043-25 Technical vulnerability management
  • ISO27043-27 Network security management

ISO/SAE 21434 · 5 controls

  • ISO21434-22 Protection from malware
  • ISO21434-23 Backup and recovery procedures
  • ISO21434-24 Logging and monitoring
  • ISO21434-25 Technical vulnerability management
  • ISO21434-27 Network security management

South Korea ISMS-P · 5 controls

  • ISMSP-AC-04 Network Access Control
  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-03 Security Monitoring and Log Management
  • ISMSP-SYS-04 Vulnerability Management
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery

BSI IT-Grundschutz · 4 controls

  • BSI-14 Vulnerability scanning and management
  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention

MITRE D3FEND · 4 controls

OWASP ASVS · 4 controls

OWASP MASVS · 4 controls

  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing
  • IM8-SEC.3 Network Security
  • IM8-SEC.4 Vulnerability Management
  • AWWA-3.1 Network Segmentation
  • AWWA-4.1 Malware Protection
  • AWWA-4.4 Audit Logging and Monitoring
  • CPG-1.D Revoking Credentials for Departing Employees
  • CPG-5.A Vulnerability Disclosure Program
  • CPG-8.A Network Segmentation
  • CAT-D3-1 Preventative controls
  • CAT-D3-2 Detective controls
  • CAT-D3-3 Corrective controls

ISO/IEC 27031:2011 · 3 controls

  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review

ISO/IEC 30111:2019 · 3 controls

  • 30111-1 Scope
  • 30111-3 Terms and definitions
  • 30111-8.1 Post-release monitoring
  • FFIEC-06 Network security and segmentation
  • FFIEC-12 Disaster recovery procedures
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • FTC-Safeguards-ServiceProvider-Evaluation Service Provider Oversight + Program Evaluation + Personnel Training (16 CFR 314.4(d-g))

ISO 22316 · 2 controls

  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities

ISO/IEC 27010:2015 · 2 controls

  • 27010-12.2 Protection from malware
  • 27010-13.1 Communications Security

ISO/IEC 29147:2018 · 2 controls

  • 29147-5.6 Advisory Content and Quality
  • 29147-7.8 Remediation information

ISO/TS 22317:2021 · 2 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-12 Recovery strategy for critical activities

ISO/TS 22318:2021 · 2 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • MAS-TRM-Project-SDLC-Service-Management-Chapters-4-5-6-IT-Project-Software-Lifecycle-Change-ITIL MAS TRM Project + SDLC + Service Management + Chapters 4-6 + IT Project + Software Lifecycle + ITIL
  • MAS-TRM-Reliability-Data-Centre-Chapters-7-8-RTO-RPO-BCP-DR-System-Availability-4-Hours-12-Months MAS TRM Reliability + Data Centre + Chapters 7-8 + RTO + RPO + BCP + DR + System Availability 4 Hours 12 Months
  • NISTSP34-2 Business Impact Analysis (BIA): Critical Resources, Recovery Priorities
  • NISTSP34-4 Information System Contingency Plan (ISCP) Development
  • DSOMM-1 Culture, Organization, Education, and Governance
  • DSOMM-3 Build, Deployment, Infrastructure Hardening, and Secrets Management
  • 4.4.8 Business Continuity and Recovery
  • DIQ-1 Data Integration and Interoperability
  • CJIS-10 System and Information Integrity

FedRAMP Rev 5 · 1 control

  • FEDRAMP-CP-9 System Backup
  • 62351-14 Cyber security event logging

ISO 22320:2018 · 1 control

  • ISO-22320-5.2 Incident management process

ISO 27799:2025 · 1 control

  • ISO27799-05 Audit trail for ePHI access
  • ISO28001-PS-01 Facility Security
  • ISO-25012-4.11 Traceability

ISO/IEC 29134:2023 · 1 control

  • 29134-9.2 Report findings and recommendations
  • NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation

OWASP Top 10:2025 · 1 control

  • OWASPTOP10-9 A09:2025 Security Logging and Monitoring Failures
  • UNGPBHR-2 Pillar II: Corporate Responsibility to Respect Human Rights
  • CPSC-CS.1 Network Security for Connected Products
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 158 it maps to, and the evidence behind each claim, over MCP and REST.