Production-grade detection coverage across the full ATT&CK matrix. Sigma rules, SIEM integration patterns, SOC playbooks, and enterprise detection engineering guidance built for analyst teams.
Complete MITRE ATT&CK Enterprise matrix coverage from initial access through exfiltration and impact.
Techniques with the highest adversary usage frequency and broadest applicability across threat actor groups. Detect these first.
Platform-agnostic Sigma rules for high-priority ATT&CK techniques. Convert to Splunk SPL, Elastic EQL, Microsoft Sentinel KQL, or Chronicle using sigmatools.
Sigma rules convert to native query languages for all major platforms. Sentinel APEX Detection Packs include pre-converted, tuned rules for each platform.
Recommended detection coverage targets for enterprise SOC teams. Gaps represent high-priority investments for detection engineering roadmaps.
| Tactic | Technique | T-ID | EDR | SIEM | Network | UEBA | Priority |
|---|---|---|---|---|---|---|---|
| Initial Access | Spearphishing Attachment | T1566.001 | H | H | M | L | P1 |
| Execution | PowerShell | T1059.001 | H | H | L | M | P1 |
| Execution | Windows Management Instrumentation | T1047 | H | M | L | L | P2 |
| Persistence | Boot/Logon Autostart — Registry Run Keys | T1547.001 | H | H | L | L | P2 |
| Privilege Esc. | Process Injection | T1055 | H | M | L | L | P1 |
| Defense Evasion | Signed Binary Proxy Exec (LOLBins) | T1218 | M | H | L | L | P2 |
| Credential Access | OS Credential Dumping — LSASS | T1003.001 | H | H | L | H | P1 |
| Lateral Movement | SMB / Windows Admin Shares | T1021.002 | M | H | H | H | P1 |
| C&C | Encrypted Channel — TLS | T1573.002 | L | M | H | M | P2 |
| Exfiltration | Exfiltration Over Web Service | T1567 | L | M | H | H | P2 |
| Impact | Data Encrypted for Impact (Ransomware) | T1486 | H | H | L | H | P1 |
| Impact | Inhibit System Recovery | T1490 | H | H | L | L | P1 |
Structured response workflows for high-priority ATT&CK technique detections. Designed for L1/L2 analysts with clear triage, escalation, and containment steps.
Sentinel APEX provides pre-tuned, production-certified detection packs for your SIEM platform — built by detection engineers for SOC operations teams.