References
Browse the catalog#
- Detection Rule Catalog: Catalog-relevant rules from Sigma, Elastic, Splunk, Kusto, and Chronicle, grouped by MITRE ATT&CK tactic and technique
- ATT&CK Coverage Graph: Lays out the MITRE ATT&CK matrix as tactic columns with technique cells, each showing event and rule coverage; per-technique pages list contributing events and rules with a cross-vendor event coverage matrix
Lookup tables#
- Logon Type: Values in Security events 4624, 4625, 4648
- Access Mask: Bitmask values for file, registry, AD, and SAM objects in Security events 4656, 4657, 4661, 4662, 4663
- Process Access Rights: Bitmasks in Sysmon event 10 and Security event 4663
- Privilege Constants: Values in Security events 4672, 4673, 4674
- UAC Flags: Bitmask flags in Security events 4738, 4720
- NTSTATUS Codes: Complete table from Windows 11 25H2
Platform coverage matrices#
Non-Windows rules organized by each platform's native action vocabulary, across all vendors:
- AWS Coverage: CloudTrail rules grouped by event source and event name
- Azure AD Coverage: Entra ID rules grouped by audit category and sign-in result
- Entra ID Sign-In Telemetry: Sign-in log tables, ResultType error codes, and key detection fields for interactive, non-interactive, service principal, and managed identity sign-ins
- GCP Coverage: Google Cloud Audit Log rules grouped by service and method
- M365 Coverage: Microsoft 365 audit rules grouped by workload and operation
- Okta Coverage: Okta System Log rules grouped by event type
Vendor coverage reports#
Per-vendor mappings to Windows catalog events; each also links its non-Windows rules out to the platform matrices above.
- Sigma Rule Coverage: Sigma rule mappings to catalog events, by event and provider
- Elastic Rule Coverage: Elastic rule mappings to catalog events, by event and provider
- Elastic Inferred Detection Coverage: Inferred Elastic rule-to-event mappings at medium and low confidence
- Splunk Rule Coverage: Splunk rule mappings to catalog events, by event and provider
- Kusto Rule Coverage: Microsoft Sentinel and Defender XDR rule mappings to catalog events, by event and provider
- Chronicle Rule Coverage: Chronicle/YARA-L rule mappings to catalog events, by event and provider
Field guides#
- Collection Priority: Which events to collect first, ranked from authoritative sources (Microsoft, Australian Signals Directorate, Yamato Security, and more)
Using this site#
- Search and Filter Syntax: Search operators, filter syntax, and keyboard shortcuts