MITRE ATT&CK Coverage
AlphaSOC provides comprehensive detection coverage across the MITRE ATT&CK Enterprise framework through managed detections and support for custom Sigma rules. The coverage map below shows the adversarial techniques detected by the AlphaSOC engine in its default state with our in-built managed detections.
Using the ATT&CK Navigator
You can download the coverage data as an ATT&CK Navigator layer file for detailed analysis and integration with your security workflows:
- Download the layer file using the button in the coverage map below
- Open the ATT&CK Navigator
- Click "Open Existing Layer" → "Upload from local"
- Select the downloaded JSON file
The Navigator layer includes color-coded coverage based on detection count, allowing you to visualize detection depth across the framework.
MITRE ATT&CK Coverage Map
In-built managed detection alignment with the MITRE ATT&CK Enterprise framework.
Download ATT&CK Navigator Layer93%14 of 15Tactics Covered
Reconnaissance
0/12 Covered
T1589
Gather Victim Identity InformationT1590
Gather Victim Network InformationT1591
Gather Victim Org InformationT1592
Gather Victim Host InformationT1593
Search Open Websites/DomainsResource Development
4/9 Covered
T15836
Acquire InfrastructureT15842
Compromise InfrastructureT15862
Compromise AccountsT16081
Stage CapabilitiesT1585
Establish AccountsInitial Access
6/9 Covered
T107879
Valid AccountsT11332
External Remote ServicesT11896
Drive-by CompromiseT11906
Exploit Public-Facing ApplicationT11993
Trusted RelationshipExecution
5/10 Covered
T105910
Command and Scripting InterpreterT12044
User ExecutionT16106
Deploy ContainerT16481
Serverless ExecutionT16516
Cloud Administration CommandPersistence
9/12 Covered
T107814
Valid AccountsT1098107
Account ManipulationT11336
External Remote ServicesT113615
Create AccountT15052
Server Software ComponentPrivilege Escalation
6/9 Covered
T10375
Boot or Logon Initialization ScriptsT107830
Valid AccountsT109847
Account ManipulationT148418
Domain or Tenant Policy ModificationT15431
Create or Modify System ProcessStealth
2/9 Covered
T10704
Indicator RemovalT15351
Unused/Unsupported Cloud RegionsT1078
Valid AccountsT1205
Traffic SignalingT1211
Exploitation for StealthDefense Impairment
1/9 Covered
T14842
Domain or Tenant Policy ModificationT1222
File and Directory Permissions ModificationT1556
Modify Authentication ProcessT1578
Modify Cloud Compute InfrastructureT1599
Network Boundary BridgingCredential Access
9/14 Covered
T10402
Network SniffingT111017
Brute ForceT11871
Forced AuthenticationT15286
Steal Application Access TokenT15391
Steal Web Session CookieDiscovery
8/16 Covered
T10462
Network Service DiscoveryT10694
Permission Groups DiscoveryT10878
Account DiscoveryT152616
Cloud Service DiscoveryT158031
Cloud Infrastructure DiscoveryLateral Movement
3/8 Covered
T10216
Remote ServicesT15501
Use Alternate Authentication MaterialT15701
Lateral Tool TransferT1072
Software Deployment ToolsT1080
Taint Shared ContentCollection
3/5 Covered
T11142
Email CollectionT12136
Data from Information RepositoriesT153012
Data from Cloud StorageT1119
Automated CollectionT1557
Adversary-in-the-MiddleCommand and Control
13/17 Covered
T10013
Data ObfuscationT10081
Fallback ChannelsT107145
Application Layer ProtocolT10902
ProxyT10951
Non-Application Layer ProtocolExfiltration
4/8 Covered
T10412
Exfiltration Over C2 ChannelT104830
Exfiltration Over Alternative ProtocolT153735
Transfer Data to Cloud AccountT156727
Exfiltration Over Web ServiceT1011
Exfiltration Over Other Network MediumImpact
8/12 Covered
T148550
Data DestructionT14863
Data Encrypted for ImpactT14895
Service StopT149018
Inhibit System RecoveryT149620
Resource Hijacking