References
Browse the catalog#
- Detection Rule Catalog: Rules from Sigma, Elastic, Splunk, Kusto, Chronicle, Panther, and Sublime, grouped by MITRE ATT&CK
- ATT&CK Coverage Graph: the MITRE ATT&CK matrix
Rule coverage by platform#
- M365 Coverage: Microsoft 365 audit rules grouped by workload and operation
- Entra ID Coverage: Entra ID rules grouped by audit category and sign-in result
- Defender XDR Coverage: Advanced Hunting ActionTypes grouped by table, with sample and detection-rule coverage
- AWS Coverage: CloudTrail rules grouped by event source and event name
- GCP Coverage: Google Cloud Audit Log rules grouped by service and method
- Google Workspace Coverage: Google Workspace rules grouped by application and event name
- GitHub Coverage: GitHub audit log rules grouped by category and action
- Kubernetes Coverage: Kubernetes audit log rules grouped by resource and verb
- Linux Coverage: Linux rules mapped to auditd record types and Sysmon for Linux events
- macOS Coverage: macOS rules mapped to Endpoint Security Framework event types
- Okta Coverage: Okta System Log rules grouped by event type
- Sublime Coverage: Sublime MQL rule coverage across the Message Data Model attributes
- Panther Rule Coverage: Panther rules grouped by platform and integration
- Sublime MQL Rule Coverage: Sublime rules grouped by Message Data Model attribute
Windows rule coverage by vendor#
- Sigma Rule Coverage: Sigma rule mappings to catalog events
- Elastic Rule Coverage: Elastic rule mappings to catalog events
- Elastic Inferred Detection Coverage: Inferred Elastic rule-to-event mappings at medium and low confidence
- Splunk Rule Coverage: Splunk rule mappings to catalog events
- Kusto Rule Coverage: Microsoft Sentinel and Defender XDR rule mappings to catalog events
- Chronicle Rule Coverage: Chronicle/YARA-L rule mappings to catalog events
Decode a Windows field value#
- Logon Type: Values in Security events 4624, 4625, 4648
- Access Mask: Bitmask values for file, registry, AD, and SAM objects in Security events 4656, 4657, 4661, 4662, 4663
- Process Access Rights: Bitmasks in Sysmon event 10 and Security event 4663
- Privilege Constants: Values in Security events 4672, 4673, 4674
- UAC Flags: Bitmask flags in Security events 4738, 4720
- NTSTATUS Codes: Complete table from Windows 11 25H2
Miscellaneous references#
- Collection Priority: Which Windows events to collect first according to authoritative sources
- Microsoft Defender for Endpoint Sensor Inventory: MDE sensor providers and registry-configured rule names mapped to Windows event IDs
- Entra ID Sign-In Telemetry: Sign-in log tables, ResultType error codes, and key detection fields
Using this site#
- Search and Filter Syntax: Search operators, filter syntax, and keyboard shortcuts
- Semantic Labels documents the identity, permission, resource, and operation labels behind the search facets, with a rule count and search link for each value