Skip to main content
SIEM-OPERATIONS5 MIN READ

Sort detections by ATT&CK tactic

Map common SIEM detection ideas to ATT&CK tactics so coverage discussions focus on attacker objectives.

Sort each SIEM detection idea by the attacker objective it most directly observes. Execution Persistence Credential Access Lateral Movement Exfiltration WINWORD.EXE launches powershell.exe with encoded command. New scheduled task created by a non-admin user on a workstation. Process opens LSASS memory with suspicious access rights. Admin share connection from a newly suspicious host to three file servers. Large object-read burst from sensitive storage followed by upload to first-seen external domain. New service installed remotely on a peer server after suspicious login. Mailbox forwarding rule created to external address after impossible-travel sign-in. PowerShell script block contains Invoke-Mimikatz function names.

Read the full lesson

Sign up free — one personalized lesson every day, matched to your role and goals.

Already have an account? Sign in

← Back to library
Contact us