MITRE ATT&CK Coverage

Every AlertKick detection rule is mapped to the MITRE ATT&CK framework - the industry-standard catalogue of attacker tactics and techniques. This page is the full matrix, generated from the same rule definitions the agent runs, so you can see exactly what's covered before you install anything.

74

mapped detection rules

45

ATT&CK techniques

12/12

tactics covered

Rules fire on kernel-level eBPF events - process execution, network connections, file changes, logins - so coverage below is runtime detection on the host, not log parsing after the fact. Every event a rule produces is triaged by AI and feeds compliance evidence automatically.

Initial Access

TA0001 · 5 techniques

Technique Detection rules
T1005
  • critical PCI: Off-Hours Cardholder Data Access
  • high SOX: Off-Hours Critical File Access
T1021.004
  • high Off-Hours SSH Activity
  • high Weekend SSH Activity
  • medium SSH Inbound Connection
  • medium SSH Inbound Login
T1078
  • critical PCI: Off-Hours Cardholder Data Access
  • critical SSH Login from Unknown IP
  • high Off-Hours SSH Activity
  • high SOX: Off-Hours Critical File Access
  • high SOX: Weekend Privileged Access
  • high Weekend SSH Activity
  • medium SSH Inbound Login
T1133
  • critical SSH Login from Unknown IP
  • medium SSH Inbound Connection
T1548.003
  • high SOX: Weekend Privileged Access

Execution

TA0002 · 5 techniques

Technique Detection rules
T1053.003
  • medium Cron Configuration Change
T1059
  • high PCI: Terminal Injection (ioctl)
T1059.004
  • critical Reverse Shell
  • high PCI: Shell in Container
  • medium Shell in Container
T1204.002
  • critical YARA Malware Match
T1609
  • high PCI: Shell in Container
  • medium Shell in Container

Persistence

TA0003 · 9 techniques

Technique Detection rules
T1014
  • high ld.so.preload Rootkit Indicator
T1053.003
  • medium Cron Configuration Change
T1098
  • high SOX: Credential Tampering
  • medium Credential Change
T1098.004
  • medium SSH Key Generation
T1547.006
  • critical Kernel Module Operation
T1556
  • high SOX: Credential Tampering
T1556.003
  • high PAM Configuration Change
T1571
  • medium New Listening Port (Privileged)
  • medium New Listening Port (Well-Known Service)
  • medium PCI: Critical Port Access (Bind/Accept)
T1574.006
  • high ld.so.preload Rootkit Indicator

Privilege Escalation

TA0004 · 8 techniques

Technique Detection rules
T1055.008
  • high Process Injection via Ptrace
T1059
  • high PCI: Terminal Injection (ioctl)
T1068
  • high Credential Change - Privilege Escalation
T1078
  • high SOX: Weekend Privileged Access
T1110
  • high Sudo Brute Force
T1548
  • critical Privilege Escalation in Container
  • high Capability Elevation
  • high Privilege Escalation to Root
T1548.003
  • critical Sudo Configuration Change
  • high SOX: Weekend Privileged Access
  • high Sudo Brute Force
  • medium SOX: Privileged Command Execution
T1611
  • critical Container Escape Attempt (chroot/pivot_root)
  • critical PCI: Container Escape Attempt
  • critical Privilege Escalation in Container
  • high Namespace Clone
  • high Namespace Manipulation

Defense Evasion

TA0005 · 11 techniques

Technique Detection rules
T1014
  • critical Hidden Kernel Module
  • critical Hidden Process
  • high ld.so.preload Rootkit Indicator
T1055
  • medium Suspicious Memory Mapping
T1055.008
  • high Process Injection via Ptrace
T1070.002
  • critical SOX: Audit Log Tampering
  • critical SOX: VFS Audit Log Tampering
  • high Audit Log Modification
T1547.006
  • critical Kernel Module Operation
T1554
  • critical File Integrity Violation
T1562.001
  • high Sysctl Parameter Write
  • medium SOX: Audit System Process Execution
T1564
  • critical Hidden Process
T1565.001
  • critical File Integrity Violation
  • critical Sensitive File Modification
  • high VFS Sensitive File Operation
T1574.006
  • high ld.so.preload Rootkit Indicator
T1611
  • high Namespace Clone
  • high Namespace Manipulation

Credential Access

TA0006 · 9 techniques

Technique Detection rules
T1005
  • medium SOX: Critical File Access
  • medium Sensitive File Access
T1098
  • high SOX: Credential Tampering
T1110
  • high Sudo Brute Force
T1110.001
  • high SSH Brute Force
T1548.003
  • high Sudo Brute Force
T1552.001
  • medium SOX: Critical File Access
  • medium Sensitive File Access
T1552.004
  • medium SSH Directory Access
T1556
  • high SOX: Credential Tampering
T1556.003
  • high PAM Configuration Change

Discovery

TA0007 · 2 techniques

Technique Detection rules
T1046
  • medium Network Reconnaissance Tool Execution
T1083
  • high SOX: Sensitive Chdir in Container

Lateral Movement

TA0008 · 6 techniques

Technique Detection rules
T1021
  • critical PCI: Insecure Protocol Usage (Network)
  • critical PCI: Insecure Protocol Usage (Process)
  • high Insecure Protocol Usage (Network)
  • high Insecure Protocol Usage (Process)
  • medium PCI: Critical Port Access (Connect)
  • medium PCI: Remote Access Network Connection
  • medium PCI: Remote Access Tool Execution
T1021.004
  • high Off-Hours SSH Activity
  • high Weekend SSH Activity
  • medium SSH Inbound Connection
  • medium SSH Inbound Login
  • medium SSH Outbound Connection
  • medium SSH Process Execution
T1071
  • critical PCI: Insecure Protocol Usage (Network)
  • critical PCI: Insecure Protocol Usage (Process)
  • high Insecure Protocol Usage (Network)
  • high Insecure Protocol Usage (Process)
T1078
  • high Off-Hours SSH Activity
  • high Weekend SSH Activity
  • medium SSH Inbound Login
T1133
  • medium SSH Inbound Connection
T1219
  • medium PCI: Remote Access Tool Execution

Collection

TA0009 · 3 techniques

Technique Detection rules
T1005
  • critical PCI: Off-Hours Cardholder Data Access
  • high PCI: Cardholder Data Access
  • high SOX: Off-Hours Critical File Access
  • medium SOX: Critical File Access
  • medium Sensitive File Access
T1078
  • critical PCI: Off-Hours Cardholder Data Access
  • high SOX: Off-Hours Critical File Access
T1552.001
  • medium SOX: Critical File Access
  • medium Sensitive File Access

Exfiltration

TA0010 · 5 techniques

Technique Detection rules
T1030
  • medium Large Data Transfer
  • medium PCI: Large Data Transfer
T1048
  • high Data Exfiltration from Container
  • high PCI: Data Exfiltration from Container
  • medium Large Data Transfer
  • medium PCI: Large Data Transfer
T1048.003
  • medium DGA / DNS Tunneling Indicator
T1071.004
  • medium DGA / DNS Tunneling Indicator
T1568.002
  • medium DGA / DNS Tunneling Indicator

Command and Control

TA0011 · 10 techniques

Technique Detection rules
T1021
  • critical PCI: Insecure Protocol Usage (Network)
  • critical PCI: Insecure Protocol Usage (Process)
  • high Insecure Protocol Usage (Network)
  • high Insecure Protocol Usage (Process)
  • medium PCI: Remote Access Tool Execution
T1048.003
  • medium DGA / DNS Tunneling Indicator
T1059.004
  • critical Reverse Shell
T1071
  • critical Connection to Known-Bad IP
  • critical PCI: Insecure Protocol Usage (Network)
  • critical PCI: Insecure Protocol Usage (Process)
  • high Insecure Protocol Usage (Network)
  • high Insecure Protocol Usage (Process)
T1071.004
  • critical DNS Query to Known-Bad Domain
  • medium DGA / DNS Tunneling Indicator
T1105
  • critical Connection to Known-Bad IP
T1219
  • medium PCI: Remote Access Tool Execution
T1496
  • high Connection to Mining Pool Port
T1568.002
  • medium DGA / DNS Tunneling Indicator
T1571
  • medium New Listening Port (Privileged)
  • medium New Listening Port (Well-Known Service)
  • medium PCI: Critical Port Access (Bind/Accept)

Impact

TA0040 · 4 techniques

Technique Detection rules
T1489
  • medium Dangerous Signal to Process
  • medium Process Killed (SIGKILL)
T1496
  • critical Cryptocurrency Miner Process
  • critical Miner in Container
  • high Connection to Mining Pool Port
T1554
  • critical File Integrity Violation
T1565.001
  • critical File Integrity Violation
  • critical Sensitive File Modification
  • high VFS Sensitive File Operation

Generated from AlertKick's rule definitions (74 of 77 rules carry ATT&CK mappings; the remainder are operational checks outside the framework's scope). Technique IDs link to the corresponding MITRE ATT&CK entry.

Your servers, watched by tonight.

Install one agent. Get security monitoring, infrastructure alerts, and on-call management - all included with every host.