Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

54 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

MITRE ATT&CK Coverage Analysis

This document maps the detection rules currently covered by the Sentryfy project and the targeted techniques against the MITRE ATT&CK framework. It is maintained to transparently show the progress of detection engineering work and the scope of the portfolio.


Legend:

  • ✅ Covered — rule written and tested in lab
  • ⏳ Medium priority — on the roadmap, coming later

TA0001 — Initial Access

Status Technique ID Technique Name SPL File
T1566 Phishing (Suspicious File Creation) Phishing SPL
T1190 Exploit Public-Facing Application Exploit Public App SPL
T1200 Hardware Additions (BadUSB / HID) Hardware Additions SPL
T1078 Valid Accounts (login anomaly) Valid Accounts
T1133 External Remote Services (RDP) planned
T1195 Supply Chain Compromise planned
T1199 Trusted Relationship planned

TA0002 — Execution

Status Technique ID Technique Name SPL File
T1059.003 Windows Command Shell (cmd.exe) Windows Command Shell SPL
T1059.005 Visual Basic (wscript / cscript) planned
T1059.007 JavaScript planned
T1047 Windows Management Instrumentation (WMI) planned
T1218.010 Regsvr32 (Squiblydoo) planned
T1218.011 Rundll32 abuse planned
T1203 Exploitation for Client Execution planned

TA0003 — Persistence

Status Technique ID Technique Name SPL File
T1098 Account Manipulation Account Manipulation
T1053.005 Scheduled Task Scheduled Task SPL
T1176 Browser Extensions Browser Extensions
T1547.001 Registry Run Keys / Startup Folder Registry Run Keys SPL
T1543.003 Windows Service planned
T1136 Local Account Creation planned
T1546.003 WMI Event Subscription planned
T1546.008 Accessibility Features (sethc / utilman) planned
T1505.003 Web Shell planned

TA0004 — Privilege Escalation

Status Technique ID Technique Name SPL File
T1055.002 Process Injection: Remote Thread (DLL Injection) DLL Injection
T1055.012 Process Injection: Process Hollowing Process Hollowing SPL
T1055.004 Process Injection: APC (Early Bird) Early Bird SPL
T1068 Exploitation for Privilege Escalation (BYOVD) BYOVD SPL
T1548.002 Bypass User Account Control (fodhelper) Bypass UAC SPL
T1134.001 Access Token Manipulation: Token Impersonation planned
T1055.003 Thread Execution Hijacking planned
T1574.002 DLL Side-Loading planned

TA0005 — Defense Evasion

Status Technique ID Technique Name SPL File
T1562.001 Disable or Modify Tools (Windows Defender) Win-Defender SPL
T1036.003 Process Masquerading (svchost.exe) Process Masquerading SPL
T1036.008 Masquerading: Masquerade File Type Masquerading SPL
T1562.001 Disable or Modify Tools (PPL / LSA Protection) PPL Disabled SPL
T1134.004 Parent PID Spoofing PPID Spoofing SPL
T1218.005 Mshta abuse Mshta Abuse SPL
T1070.001 Clear Windows Event Logs planned
T1027 Obfuscated Files (base64, encoded commands) planned
T1140 Deobfuscate / Decode Files or Information planned
T1112 Modify Registry planned
T1070.004 File Deletion planned
T1497 Virtualization / Sandbox Evasion planned
T1564.001 Hidden Files and Directories planned

TA0006 — Credential Access

Status Technique ID Technique Name SPL File KQL File
T1110 Brute Force Brute Force SPL Brute Force KQL
T1110.003 Password Spraying Password Spraying SPL Password Spraying KQL
T1003.001 OS Credential Dumping: LSASS Memory LSASS Memory SPL
T1555 Credentials from Password Stores (browsers) planned
T1558.003 Kerberoasting planned
T1552.001 Unsecured Credentials in Files planned

TA0007 — Discovery

Status Technique ID Technique Name SPL File
T1087.001 Account Discovery: Local Account planned
T1018 Remote System Discovery planned
T1082 System Information Discovery planned
T1016 System Network Configuration Discovery planned

TA0008 — Lateral Movement

Status Technique ID Technique Name SPL File
T1021.002 Remote Services: SMB/Windows Admin Share Admin Share SPL
T1570 Lateral Tool Transfer Lateral Tool Transfer SPL

TA0011 — Command and Control

Status Technique ID Technique Name SPL File
T1219 Remote Access Tools Remote Access Tools SPL
T1071.004 Application Layer Protocol: DNS Tunneling DNS Tunneling SPL
T1071.004 + T1048.003 DNS Tunneling (Network-Based + Process Correlation) DNS Tunneling Correlation SPL
T1572 Protocol Tunneling planned

🔬 Test Environment

All rules are written and tested in the following environment:

  • OS: Windows 11
  • EDR/Telemetry: Sysmon (config: SwiftOnSecurity baseline + custom additions) + Windows Event Logs
  • SIEM: Splunk Developer License (Free license, lab use) + Microsoft Sentinel (free trial, lab use)

About

Detection engineering lab: MITRE ATT&CK detections built and validated on real telemetry across Splunk (RBA) and Microsoft Sentinel (KQL), with writeups.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages