MITRE ATT&CK Coverage Analysis
This document maps the detection rules currently covered by the Sentryfy project and the targeted techniques against the MITRE ATT&CK framework. It is maintained to transparently show the progress of detection engineering work and the scope of the portfolio.
Legend:
✅ Covered — rule written and tested in lab
⏳ Medium priority — on the roadmap, coming later
Status
Technique ID
Technique Name
SPL File
✅
T1566
Phishing (Suspicious File Creation)
Phishing SPL
✅
T1190
Exploit Public-Facing Application
Exploit Public App SPL
✅
T1200
Hardware Additions (BadUSB / HID)
Hardware Additions SPL
✅
T1078
Valid Accounts (login anomaly)
Valid Accounts
⏳
T1133
External Remote Services (RDP)
planned
⏳
T1195
Supply Chain Compromise
planned
⏳
T1199
Trusted Relationship
planned
Status
Technique ID
Technique Name
SPL File
✅
T1059.003
Windows Command Shell (cmd.exe)
Windows Command Shell SPL
⏳
T1059.005
Visual Basic (wscript / cscript)
planned
⏳
T1059.007
JavaScript
planned
⏳
T1047
Windows Management Instrumentation (WMI)
planned
⏳
T1218.010
Regsvr32 (Squiblydoo)
planned
⏳
T1218.011
Rundll32 abuse
planned
⏳
T1203
Exploitation for Client Execution
planned
Status
Technique ID
Technique Name
SPL File
✅
T1098
Account Manipulation
Account Manipulation
✅
T1053.005
Scheduled Task
Scheduled Task SPL
✅
T1176
Browser Extensions
Browser Extensions
✅
T1547.001
Registry Run Keys / Startup Folder
Registry Run Keys SPL
⏳
T1543.003
Windows Service
planned
⏳
T1136
Local Account Creation
planned
⏳
T1546.003
WMI Event Subscription
planned
⏳
T1546.008
Accessibility Features (sethc / utilman)
planned
⏳
T1505.003
Web Shell
planned
TA0004 — Privilege Escalation
Status
Technique ID
Technique Name
SPL File
✅
T1055.002
Process Injection: Remote Thread (DLL Injection)
DLL Injection
✅
T1055.012
Process Injection: Process Hollowing
Process Hollowing SPL
✅
T1055.004
Process Injection: APC (Early Bird)
Early Bird SPL
✅
T1068
Exploitation for Privilege Escalation (BYOVD)
BYOVD SPL
✅
T1548.002
Bypass User Account Control (fodhelper)
Bypass UAC SPL
⏳
T1134.001
Access Token Manipulation: Token Impersonation
planned
⏳
T1055.003
Thread Execution Hijacking
planned
⏳
T1574.002
DLL Side-Loading
planned
Status
Technique ID
Technique Name
SPL File
✅
T1562.001
Disable or Modify Tools (Windows Defender)
Win-Defender SPL
✅
T1036.003
Process Masquerading (svchost.exe)
Process Masquerading SPL
✅
T1036.008
Masquerading: Masquerade File Type
Masquerading SPL
✅
T1562.001
Disable or Modify Tools (PPL / LSA Protection)
PPL Disabled SPL
✅
T1134.004
Parent PID Spoofing
PPID Spoofing SPL
✅
T1218.005
Mshta abuse
Mshta Abuse SPL
⏳
T1070.001
Clear Windows Event Logs
planned
⏳
T1027
Obfuscated Files (base64, encoded commands)
planned
⏳
T1140
Deobfuscate / Decode Files or Information
planned
⏳
T1112
Modify Registry
planned
⏳
T1070.004
File Deletion
planned
⏳
T1497
Virtualization / Sandbox Evasion
planned
⏳
T1564.001
Hidden Files and Directories
planned
TA0006 — Credential Access
Status
Technique ID
Technique Name
SPL File
⏳
T1087.001
Account Discovery: Local Account
planned
⏳
T1018
Remote System Discovery
planned
⏳
T1082
System Information Discovery
planned
⏳
T1016
System Network Configuration Discovery
planned
TA0008 — Lateral Movement
TA0011 — Command and Control
All rules are written and tested in the following environment:
OS: Windows 11
EDR/Telemetry: Sysmon (config: SwiftOnSecurity baseline + custom additions) + Windows Event Logs
SIEM: Splunk Developer License (Free license, lab use) + Microsoft Sentinel (free trial, lab use)