MITRE ATT&CK
Detection Engineering and Data Sources - MITRE ATT&CK

MITRE ATT&CK MITRE-ATTACK-Detection-Data-Sources-Analytics-Sigma-Splunk-KQL-Yara-Snort-SIEM-Hunt-Engineering: MITRE ATT&CK Detection + Data Sources + Analytics + Sigma + Splunk + KQL + Yara + Snort + SIEM + Hunt

Implement detection engineering and threat hunting using ATT&CK Data Sources and detection content. Each technique includes Detection guidance + Data Sources required + analytic queries. Data Sources (DS-IDs) provide categorisation of logs and telemetry: DS0009 Process + DS0017 Command Execution + DS0029 Network Traffic + DS0011 Module + DS0016 Drive + DS0022 File + DS0033 Network Share + others. v16 (October 2024) introduced structured detection content with analytic platforms metadata. Detection content includes vendor-agnostic Sigma rules + platform-specific Splunk SPL + Microsoft Kusto Query Language (KQL) + Yara malware signatures + Snort/Suricata network rules + ElasticSearch DSL + AWS CloudWatch + Azure Sentinel KQL + Google Chronicle YARA-L. Integration with SIEM platforms (Splunk + Microsoft Sentinel + IBM QRadar + Elastic SIEM + Google Chronicle + Sumo Logic + Devo + Securonix + LogRhythm + Exabeam) + EDR platforms (CrowdStrike Falcon + Microsoft Defender + SentinelOne + Cybereason + Cylance + Carbon Black + Trend Vision One + Sophos Intercept X). Threat hunt loops using ATT&CK Navigator gap analysis. Detection coverage reporting per technique + per platform + per data source. CALDERA automated adversary emulation. Pyramid of Pain (David Bianco) for detection sophistication.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.